What Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure requires
The Securities and Exchange Commission is adopting new rules to enhance and standardize disclosures regarding cybersecurity risk management, strategy, governance, and incidents by public companies subject to the reporting requirements of the Securities Exchange Act of 1934. These amendments require current disclosure about material cybersecurity incidents via Form 8-K within four business days of determining an incident was material. The rules also mandate periodic disclosures in annual reports (Form 10-K) detailing a registrant’s processes to assess, identify, and manage material cybersecurity risks. This includes describing the board of directors’ oversight of cybersecurity risks and management’s role in assessing and managing such risks. The final rules aim to address varied and inconsistent disclosure practices observed after prior Commission guidance. As the economic dependence on electronic systems grows, along with a substantial rise in the prevalence and costs of cybersecurity incidents, investors need more timely and reliable information. The rules are designed to ensure that investors receive consistent, comparable, and decision-useful information to assess the potential effects of a material cybersecurity incident on a registrant, including financial, operational, and reputational impacts. Disclosures are required to be presented in Inline eXtensible Business Reporting Language (Inline XBRL) to improve accessibility and analysis.
Pillar: Operations & CX · Authority: Securities and Exchange Commission · Version: 1.0.0 · Last updated:
Primary source: https://www.sec.gov/files/rules/final/2023/33-11216.pdf
SHA-256 integrity: 275030b1fb7b79c3e15002a528c674479b16e6b91547253e20a2ff1911c9616b
Primary Citations — 7 traced to source
- {"citation":"Form 8-K Item 1.05","text":"Registrants must disclose any cybersecurity incident they experience that is determined to be material, and describe the material aspects of its: - Nature, scope, and timing; and - Impact or reasonably likely impact."}
- {"citation":"Form 8-K Item 1.05 Filing Deadline","text":"An Item 1.05 Form 8-K must be filed within four business days of determining an incident was material."}
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/sec-cybersecurity-risk-incident-disclosure.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/sec-cybersecurity-risk-incident-disclosure.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/sec-cybersecurity-risk-incident-disclosure
- Back to registry: Browse all 10,090 compliance nodes