UPDATED 12:02 EDT / SEPTEMBER 21 2023

Marshall Heilman, Amy Geiger and Edgard Capdevielle, mWISE Conference, 2023 POLICY

Adapting to new rule changes in cyber risk management: How the SEC changed the game

Security and Exchange Commission’s July 2023 rule changes in cyber risk management require companies to disclose governance processes and cyber risk in 10-K filings, define materiality thresholds and publicly disclose material cyber incidents within four days in an 8-K filing.

Companies should now establish a framework for determining materiality, considering various factors, as the SEC rule change may impact how materiality is defined, according to Amy Geiger (pictured, second from right), managing director at Accenture PLC. These developments put additional pressure on companies when it comes to its business filings.

“It’s very clear that the clock starts when you determine materiality,” Geiger said. “I think the first task companies have right now is: What’s my framework for establishing materiality? Once you determine that you’ve got a material incident, now all the operational impacts start. Not only am I trying to contain my incident, but now I’ve got to start making sure I’m getting the right data to be able to make those calls around materiality.”

Geiger; Marshall Heilman (left), global chief technology officer at Mandiant, a Google LLC company; and Edgard Capdevielle (right), chief executive officer at Nozomi Networks Inc., spoke with theCUBE industry analyst John Furrier (second from left) at the mWISE Conference, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed the need to adapt to new rule changes in cyber risk management and prioritizing centralization. (* Disclosure below.)

Getting ready for incidents

The structure of teams and workflows should be based on an organization’s governance and preparedness for incidents, according to Heilman. Instead of just the structure itself, it is important to handle breaches properly to maintain public confidence and comply with regulations.

Companies must ensure that if a major breach occurs, it can demonstrate breach management, Heilman added. This will help instill confidence by showing that appropriate measures have been taken and that they have complied with regulations set by bodies, such as the SEC, aimed at protecting investors.

“The SEC jumped the gun … to protect investors, [which is] the right thing to do. But it’s only the first step,” Capdevielle said. “I think we’re about eight months from having CISA do its move and it’s going to be very similar. It’s also going to continue to have some teeth. The CISOs and management teams, and specifically boards, need to start preparing for the new world.”

Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of the mWISE Conference:

(* Disclosure: Accenture PLC sponsored this segment of theCUBE. Neither Accenture nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)

Photo: SiliconANGLE

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.