SEC Announces New Cybersecurity Interpretations

Mayer Brown Free Writings + Perspectives
Contact

Mayer Brown Free Writings + Perspectives

The SEC’s Division of Corporation Finance yesterday published five new Compliance and Disclosure Interpretations, or “C&DIs,” all concerning Item 1.05 of Exchange Act Form 8-K, Disclosure of Cybersecurity Incidents.

New C&DI 104B.05 describes a ransomware attack on a public company ended by a payment to the threat actor before any materiality evaluation of the incident. The C&DI holds that, despite the end of the attack, the company must still make a materiality determination for the event. The interpretation necessarily implies that a report on Form 8-K would be required in the event that the incident was found to be material on general securities law principles.

Question 104B.06 describes a material cybersecurity incident that is ended or remediated by a ransom payment before the filing of a report on 8-K. The interpretation holds that a current report is still required.

Insurance covering all or a substantial part of a ransomware payment may not mean that that an associated cybersecurity incident must have been immaterial in the view expressed in Question 104B.07.

In the SEC staff’s perspective, the size of a ransomware payment is only one factor to consider in the materiality assessment of a cybersecurity incident. Thus, under Question 104B.08, a small ransomware payment would not categorically mean that the related incident was immaterial.

In Question 104B.09, a public company experiences a series of individually immaterial cybersecurity incidents. In the described circumstances, the company must determine whether any incidents were related and, if so, assess whether the related events were cumulatively material.

See the C&DIs here.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Mayer Brown Free Writings + Perspectives

Written by:

Mayer Brown Free Writings + Perspectives
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Mayer Brown Free Writings + Perspectives on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide