New SEC Rules Mandate Cybersecurity Transparency and Oversight

Matthew.Rosenquist
4 min readJul 28, 2023
SEC Announces New Cybersecurity Rules

The new SEC Rules establish a framework that requires rapid disclosure of material cybersecurity incidents (4 days), companies will need to be able to explain their cybersecurity posture to manage risks, and for boards to describe their oversight and expertise for cybersecurity.

This is a major leap forward for securing US public companies! The new regulation drives transparency of incidents, risk management processes, and board accountability. It may be the most impactful cybersecurity event this year that shifts the trajectory of how cyber risks are managed!

The new SEC Rules establish a framework that requires:

  1. Rapid disclosure of material cybersecurity incidents (4 days)
  2. Companies will need to be able to explain their cybersecurity posture to manage risks
  3. Boards of Directors must describe their oversight and expertise in cybersecurity

These three simple rules will shake the current inconsistent foundations across every sector, which are often flimsy, and force companies to build strong programs, integrated with board support, to protect customers’ and shareholders’ interests!

Overall, I very much like this requirement! Historically I have despised tech regulations, except when…

--

--

Matthew.Rosenquist
Matthew.Rosenquist

Written by Matthew.Rosenquist

CISO and cybersecurity Strategist specializing in the evolution of threats, opportunities, and risks in pursuit of optimal security

Responses (2)