Just In! More Guidance on Material Cybersecurity Incidents (Item 1.05 of Form 8-K)

Bass, Berry & Sims PLC
Contact

Bass, Berry & Sims PLC

On June 24, the Securities and Exchange Commission (SEC) released five additional Compliance and Disclosure Interpretations for Item 1.05 of Form 8-K (Material Cybersecurity Incidents).  These interpretations provide additional guidance as to whether and when materiality determinations should be made and when related reporting obligations arise. 

In particular, the interpretations are intended to provide additional guidance in the following scenarios:

  1. When a registrant makes a ransomware payment, the threat actor returns data and stops disruption all before the registrant makes a materiality determination.
  2. When a registrant makes a ransomware payment, the threat actor returns data and stops disruption, after the registrant makes a materiality determination and before it reports such an incident.
  3. When ransomware payment is fully covered by insurance.
  4. Whether the small size of ransomware payment determines lack of materiality in itself.
  5. Whether a series of immaterial cybersecurity incidents is reportable.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Bass, Berry & Sims PLC | Attorney Advertising

Written by:

Bass, Berry & Sims PLC
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Bass, Berry & Sims PLC on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide