New SEC rule requires public companies to disclose cybersecurity breaches in 4 days

Advertisement

Advertise with us

WASHINGTON (AP) — The Securities and Exchange Commission adopted rules Wednesday to require public companies to disclose within four days all cybersecurity breaches that could affect their bottom lines. Delays will be permitted if immediate disclosure poses serious national security or public safety risks.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 26/07/2023 (1173 days ago), so information in it may no longer be current.

WASHINGTON (AP) — The Securities and Exchange Commission adopted rules Wednesday to require public companies to disclose within four days all cybersecurity breaches that could affect their bottom lines. Delays will be permitted if immediate disclosure poses serious national security or public safety risks.

The new rules, passed by a 3-2 vote along party lines, also require publicly traded companies to annually disclose information on their cybersecurity risk management and executive expertise in the field. The idea is to protect investors.

Breach disclosures can be delayed if the U.S. Attorney General determines they would “pose a substantial risk to national security or public safety” and notifies the SEC in writing. Only under extraordinary circumstances could that delay be extended beyond 60 days.

FILE - The seal of the U.S. Securities and Exchange Commission at SEC headquarters, June 19, 2015, in Washington. The SEC adopted rules Wednesday, July 26, 2023, to require public companies to disclose within four days all cybersecurity breaches that could affect their bottom lines. Delays will be permitted if immediate disclosure poses serious national security or public safety risks. (AP Photo/Andrew Harnik, File)
FILE - The seal of the U.S. Securities and Exchange Commission at SEC headquarters, June 19, 2015, in Washington. The SEC adopted rules Wednesday, July 26, 2023, to require public companies to disclose within four days all cybersecurity breaches that could affect their bottom lines. Delays will be permitted if immediate disclosure poses serious national security or public safety risks. (AP Photo/Andrew Harnik, File)

“Whether a company loses a factory in a fire — or millions of files in a cybersecurity incident — it may be material to investors,” SEC Chair Gary Gensler said in a statement, noting the current inconsistency in disclosures.

The rules will put “more transparency into an otherwise opaque but growing risk” and may spur improvements in cyber defenses — though potentially posing a bigger challenge for smaller companies with limited resources, Lesley Ritter, senior VP at Moody’s Investors Service, said in a statement.

Technically, the clock doesn’t start ticking on the four-day window for reporting until companies have determined a breach is material.

One of the dissenting Republican commissioners, Hester Peirce, complained that the new requirements overstep the SEC’s authority and “seem designed to better meet the needs of would-be hackers” – who could benefit from detailed info on how companies manage cyberrisk.

As well, Peirce said in a statement, the temptation for the SEC to “micromanage” company operations will only grow.

A leading figure in cybersecurity, Tenable CEO Amit Yoran, heartily welcomed the new rule.

“For a long time, the largest and most powerful U.S. companies have treated cybersecurity as a nice-to-have, not a must have. Now, it’s abundantly clear that corporate leaders must elevate cybersecurity within their organizations,” he said in a statement.

The rules were first proposed in March 2022, when the SEC determined that breaches of corporate networks posed an escalating risk as their digitization of operations and remote work increased — and the cost to investors from cybersecurity incidents rose.

While some critical infrastructure operators and all health care providers must by law report breaches, no federal breach disclosure law exists.

In a new report published by IBM, researchers found organizations now pay an average of $4.5 million to deal with breaches — a 15% increase over the past three years. The Ponemon Institute researchers also found that impacted businesses typically pass the costs on to consumers, who may themselves also be victims with personal information stolen in a breach.

The rule’s passage also comes amid slow-moving, often cryptic disclosures — some through SEC filings — from a major data breach affecting hundreds of organizations caused by the so-called supply chain hack by Russian cybercriminals of a widely used file transfer program, MOVEit. The breach has impacted multiple universities, major pensions funds, U.S. government agencies, more than 9 million motorists in Oregon and Louisiana and companies including the BBC, British Airways, Ernst & Young and PricewaterhouseCoopers.

Many victims of the MOVEit breach were quick to point out that they were failed by a third-party application. The new SEC rule encompasses third-party apps and notes how companies have increasingly relied on outside cloud services for data management and storage.

Report Error Submit a Tip

More Stories

Phoneless concert a beautiful chance to bask in moment

Jen Zoratti 5 minute read Preview

Phoneless concert a beautiful chance to bask in moment

Jen Zoratti 5 minute read 2:01 AM CDT

Outside the Scotiabank Arena in Toronto, digital billboards flashed fans their singular photo op for the night: “I took this photo before I saw Phoebe Bridgers: The Lost Tour 2026.”

It is, as it is for so many other people, my only documentation of a concert by one of my favourite artists. The American singer-songwriter — who I discovered at the Winnipeg Folk Festival in 2018 — has had a meteoric rise in the past few years, winning three Grammys in 2024 as one third of Boygenius, the indie-rock supergroup rounded out by Lucy Dacus and Julien Baker, and opening for Taylor Swift on select dates of her titanic Eras Tour.

Now, Bridgers is touring in support of Lost Weekend, her third album and first since 2020’s Punisher. It’s a feat of a record, a richly textured meditation on loss and grief, written in the aftermath of the death of her dad, with whom she had a complicated relationship.

So she is in a position to not only play multiple sold-out arena shows, but also insist that those shows be phone-free.

Read
2:01 AM CDT

Jets’ game flies south against Ducks

Mike McIntyre 7 minute read Preview

Jets’ game flies south against Ducks

Mike McIntyre 7 minute read Yesterday at 10:38 PM CDT

The Winnipeg Jets sure looked like a team that was running on fumes Friday night.

Playing for the fifth time in eight days, the club suffered its first regulation loss of the young season — a lacklustre 5-1 showing against the Anaheim Ducks at Canada Life Centre.

While we won’t question the effort, the execution was a different story. Sloppy plays, missed passes, porous defensive-zone coverage and iffy goaltending made this a tough watch for the 13,693 fans in attendance.

“Just some mental things that happened. Obviously some physical things as well,” said head coach Scott Arniel.

Read
Yesterday at 10:38 PM CDT

A Life's Story: Writer built bridges with genuine curiosity, compassion for diversity of religious practices

Janine LeGal 6 minute read Preview

A Life's Story: Writer built bridges with genuine curiosity, compassion for diversity of religious practices

Janine LeGal 6 minute read 6:00 AM CDT

Brenda Suderman knew how to make people feel comfortable. For a journalist, that character trait is a real strength, and it made people trust and appreciate her.

Whether covering musicals, worship spaces, the effects of pandemic shutdowns, death rituals and practices of different traditions, the discovery of the burial of 2,284 infants in unmarked graves, or any other of the countless topics she wrote about in her four- decade career, Suderman did it with genuine interest and care.

Born and raised in Winkler, Suderman grew up on a farm. Much of her childhood was spent in gardens and sugar beet fields.

Baptized at 16, she became a member of the Winkler Bergthaler Mennonite Church. The restrictions against women at the time contributed to planting the seeds of Suderman’s feminist perspective.

Read
6:00 AM CDT

Today’s horoscope

Georgia Nicols 4 minute read Preview

Today’s horoscope

Georgia Nicols 4 minute read Yesterday at 2:00 AM CDT

MOON ALERT: After 3:30 a.m. there are no restrictions to shopping or important decisions. The moon is in Libra.

ARIES (March 21-April 19)

You will have to go more than halfway when dealing with others, which is no biggie. This simply requires you to be present, accommodating and willing to go along to get along. Be aware that a partner, spouse or close friend might surprise you.

TAURUS (April 20-May 20)

Read
Yesterday at 2:00 AM CDT

Puzzles Palace

1 minute read Monday, Jul. 27, 2026

To solve our puzzles, please subscribe with this special offer: |

Piece of magic history disappears

Kelly-Anne Riess 5 minute read Preview

Piece of magic history disappears

Kelly-Anne Riess 5 minute read 6:49 PM CDT

A piece of Winnipeg’s magic history has vanished, and internationally renowned escape artist Dean Gunnarson is offering a $500 reward to anyone who can make it reappear.

The plaque marked the birthplace of what has become the world’s largest organization of professional and amateur magicians, the International Brotherhood of Magicians, which was founded in Winnipeg more than a century ago.

Gunnarson said fellow magician and local magic historian Bruce Thompson discovered the disappearance Tuesday while on his way to work.

Thompson returned to inspect the site and found what appeared to be evidence it had been forcibly removed.

Read
6:49 PM CDT