UPDATED 22:40 EDT / MARCH 10 2022

SECURITY

SEC cybersecurity incident disclosure proposal supported by industry professionals

A proposal from the U.S. Securities and Exchange Commission to compel companies to disclose cybersecurity incidents has received strong support from cybersecurity professionals.

There are two components to the proposal. The first is mandatory cybersecurity incident reporting of “material” incidents. The disclosure of incidents would be via an 8-K form and must be reported within four business days of the incident.

The second component would require companies to disclose their policies to manage cybersecurity risk, including providing updates on previously reported material cybersecurity incidents.

“Over the years, our disclosure regime has evolved to reflect evolving risks and investor needs,” SEC Chair Gary Gensler said in a March 9 statement.”Today, cybersecurity is an emerging risk with which public issuers increasingly must contend. Investors want to know more about how issuers are managing those growing risks.”

So far, the SEC has only put forward the mandatory reporting requirement as a proposal. There is now a 60-day comment period.

The reaction from those in the cybersecurity business was positive, with many praising the proposal as a step in the right direction.

“This is a good move on the SEC’s part to standardize breach reporting and procedures for publicly traded companies and hold them accountable,” Ray Kelly, a fellow at application security company NTT Security AppSec Solutions Inc., told SiliconANGLE. “The current policies — which do not specify a timeframe to report cybersecurity incidents to the public — have essentially allowed companies to disclose this critical information on their own merit, which could affect stock price or mergers and acquisitions.”

Jasmine Henry, field security director at cyber asset management and government solutions provider JupiterOne Inc., said the SEC’s proposed rule amendments are a positive step toward transparency and accountability.

“It’s a public recognition that security is a basic right and that organizations have an ethical responsibility to their shareholders to proactively manage cyber risk,” Henry said. “I am particularly encouraged by the SEC’s attention toward cyber incident recovery in the proposed rule amendments, since applying meaningful change is the most important part of learning from a cybersecurity incident.”

Davis McCarthy, principal security researcher at cloud-native network security services company Valtix Inc., said that as investors gain visibility into how companies secure data, it’s possible the SEC’s amendments will improve the cybersecurity standards of the private sector.

“Security posture, risk management and incident handling could become a competitive advantage — who wants to invest in a company that leaves their front door unlocked?” McCarthy said. “As they scramble to validate their posture, many companies will realize that their security solutions are underperforming and that their attack surface has grown in a new direction.”

Image: Needpix

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.