SEC Delays Finalized Cybersecurity Rules until Fall 2023

Paul Hastings LLP
Contact

Paul Hastings LLP

Based on recent changes to its rulemaking agenda, the Securities Exchange Commission has postponed the much anticipated release of its final rules for Cybersecurity Risk Management, Strategy, Governance and Incident Disclosure for public companies, until at least October 2023.

The new proposed rules were first released in March 2022 for public comments. They largely focus on enhancing cybersecurity requirements for public companies including:

  • Four-day disclosure timeframe for “material” cybersecurity incidents;
  • Requirements around Board governance of cybersecurity;
  • Increased disclosures on Board cybersecurity expertise;
  • Enhanced disclosures on risk management, oversight, and cybersecurity; and;
  • Aggregation requirements for incidents that are non-material individually.

The SEC first released these proposed rules for comment in March 2022 and closed the comment period in May 2022. It temporarily re-opened the comment period between October 7, 2022 and November 1, 2022 due to a technical issue with the SEC’s website. Before this delay, it was widely expected that the final rules would be released this past spring.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Paul Hastings LLP | Attorney Advertising

Written by:

Paul Hastings LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Paul Hastings LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide