SEC Issues New Guidance on Cybersecurity Incident Reporting

SEC Issues New Guidance on Cybersecurity Incident Reporting

BY  
AnhNguyen  
- June 27, 2024

On June 24, 2024, the SEC’s Division of Corporation Finance issued five new Compliance and Disclosure Interpretations (C&DIs) to clarify cybersecurity incident reporting under Item 1.05 of Form 8-K, specifically addressing situations involving ransomware payments. These updates follow recent guidance from Corporation Finance Director Erik Gerding on cybersecurity disclosures. Item 1.05 of Form 8-K, adopted on July 26, 2023, requires public companies to disclose material cybersecurity incidents within four days of determining the incident’s materiality, detailing the nature, scope, timing, and impact on the company’s financial condition and operations. Companies must promptly assess the materiality of incidents and amend disclosures if new material information arises. 

The new C&DIs emphasize that companies must assess the materiality of a ransomware attack even if a payment resolves the incident before making this determination. The cessation of the incident due to a payment does not exempt companies from this obligation. If a ransomware attack is deemed material, companies must report it under Item 1.05 of Form 8-K, regardless of whether a payment ends the incident before the filing deadline. Additionally, the existence of cyber insurance covering the ransomware payment does not automatically render the incident immaterial. The size of the ransomware payment alone is not determinative of materiality; companies should consider all relevant quantitative and qualitative factors, including the broader impact on operations, finances, and reputation. Furthermore, if a company experiences multiple related cybersecurity incidents that are individually immaterial, it should evaluate whether these incidents collectively amount to a material event. 

Director Gerding’s guidance highlights that only material cybersecurity incidents should be disclosed under Item 1.05. For voluntary disclosures of non-material incidents, companies should use a different Form 8-K item, such as Item 8.01, to avoid investor confusion. Companies should consider both quantitative impacts, such as financial losses, and qualitative impacts, such as reputational damage and customer trust, in their materiality assessments. This comprehensive approach ensures that investors receive clear and accurate information, aligning with the SEC’s emphasis on robust cybersecurity risk management and transparency in ESG-related disclosures. 

Sources: 

https://www.mofo.com/resources/insights/240625-u-s-sec-issues-updated-guidance-on-cybersecurity-disclosure 

https://www.securitiesdocket.com/2024/06/26/u-s-sec-issues-updated-guidance-on-cybersecurity-disclosure-under-item-1-05-of-form-8-k-morrison-foerster/

지금 바로 Seneca ESG 툴킷 사용 시작하기

포트폴리오의 ESG 성과를 모니터링하고, 나만의 ESG 프레임워크를 만들며, 더 나은 비즈니스 의사결정을 내리세요.

Toolkit

Seneca ESG

관심 있으신가요? 지금 문의하세요

문의하려면 오른쪽 폼을 작성하시거나 아래 이메일 주소로 연락 주십시오.

sales@senecaesg.com

싱가포르 지사

7 Straits View, Marina One East Tower, #05-01, Singapore 018936

+(65) 6223 8888

바르셀로나 지사

Carrer de la Tapineria, 10

Ciutat Vella, 08002, Barcelona, Spain

+34 612 22 79 06

타이베이 지사

77 Dunhua South Road, 7F Section 2, Da'an District Taipei City, Taiwan 106414

(+886) 02 2706 2108

리마 지사

Av. Santo Toribio 143,

San Isidro, Lima, Peru, 15073

(+51) 951 722 377