The U.S. [1] [2] [4] [8] Securities and Exchange Commission (SEC) has implemented rules to enhance cybersecurity disclosures for public companies [3] [7]. These rules require public companies to disclose information in three categories: cybersecurity risk management [1], cybersecurity governance [1] [5] [7], and cybersecurity incident reporting [1] [2] [4] [5] [6] [7].


Public companies are now obligated to disclose how they assess, identify [1] [4] [5], and manage material cybersecurity risks [1] [4]. They must also describe the board’s oversight of cybersecurity risks [2]. Additionally, public companies are required to disclose any material cybersecurity incidents within four days of determining their materiality [1].

These new rules increase public company exposure and may lead to an increase in lawsuits related to cybersecurity incidents [1]. Directors and officers (D&Os) may face claims alleging breach of duty or oversight [1], and it is important to review D&O insurance policies for coverage. Cyber insurance policies may also be affected [1], with insurers adopting more stringent underwriting practices [1].

