Diadon Enterprises © 2018

SEC delays final rule on cyber incident disclosure as industry pushes back | Dump Trucks Charlotte NC

Close up of Gary Gensler speaking during a senate hearing
WASHINGTON: Securities and Exchange Commission (SEC) Chair Gary Gensler testifies before the Senate Banking, Housing, and Urban Affairs Committee, on Capitol Hill, on Thursday, September 15, 2022. Kevin Dietsch/Getty Images via Getty Images

First published on

Cybersecurity Dive

The Securities and Exchange Commission has postponed until October a final rule that would require publicly traded companies to report material cyber breaches and attacks in regulatory filings. 

The rule, initially proposed in March 2022, would require public companies to submit a filing within four days of determining whether a cyber breach is material. 

As part of that proposal, the SEC also sought additional disclosures from companies regarding their cyber governance, including board expertise and upper management involvement in cyber risk. 

The SEC also proposed investment companies and advisors adopt written cybersecurity policies in February 2022.

The proposal stemmed from years of companies delaying or failing to disclose significant cyber breaches or ransomware attacks. 

Companies have historically only reported about one-quarter of ransomware attacks to public authorities, according to a report from the U.S. Senate released in 2022. These incidents have largely been kept confidential, with arranged ransom payments to avoid data disclosures, consumer or investor lawsuits and reputational harm.

IT security experts say the delay will increase the level of risk, because many investors, consumers and companies will rely on voluntary disclosure of major cyberattacks. 

Without the hammer the SEC regulations can bring, reporting breaches will continue to be voluntary and historically that doesn't work,” Gary Barlet, field CTO, federal at Illumio, said via email. 

SEC officials have not publicly stated the reasons for the delay, but there has been significant pushback from various stakeholders regarding the four-day disclosure proposal. 

Some organizations, like cybersecurity firm Rapid7, argued the proposed disclosure rules would risk making ongoing attacks part of the public record. Therefore, disclosure would potentially tip off criminal hackers if a columbus oh dump truck company was required to go public before the incident was contained.

Rapid7 officials asked the SEC for the ability to let companies delay disclosure until attacks were mitigated. 

Construction Dive news delivered to your inbox

Get the free daily newsletter read by industry experts

Daily Dive newsletter example

Editors' picks

  • AGC image library construction worker with steel Explore the Trendline
    Image attribution tooltip
    Permission granted by Associated General Contractors of America
    Image attribution tooltip
    Trendline

    Labor

    A roundup of articles about issues affecting the workforce.

    By Construction Dive staff
  • Turner Construction
    Image attribution tooltip
    Permission granted by Turner Construction
    Image attribution tooltip

    Top 10 commercial columbus oh dump truck company of 2023

    Turner maintained its No. 1 ranking while first-timer MasTec claimed the third spot in this year’s list of construction industry giants.

    By Matthew Thibault • May 30, 2023