News & Analysis as of

Publicly-Traded Companies Cyber Attacks Securities Regulation

Skadden, Arps, Slate, Meagher & Flom LLP

Recent SEC Cyber-Related Enforcement Actions Emphasize the Importance of Robust Disclosure Controls

On October 22, 2024, the Securities and Exchange Commission (SEC) announced enforcement actions against several technology companies for making materially misleading disclosures regarding cybersecurity risks and intrusions....more

White & Case LLP

SEC Enforcement Heats up on Key Public Company Topics: Cyber Disclosure, Director Independence and Regulation FD

White & Case LLP on

The U.S. Securities and Exchange Commission's ("SEC") Division of Enforcement has recently brought a spate of enforcement actions relating to key topics for public companies. These include enforcement actions related to...more

Troutman Pepper

SEC Cybersecurity Incidents Disclosures: Materiality, Decryptors, and Ransom Payments - Dear Mary – Incidents + Investigations...

Troutman Pepper on

I work for a public company that recently experienced a ransomware attack. Fortunately, we were able to restore our business operations quickly by obtaining a decryption key from the threat actor. Given that we managed to get...more

Alston & Bird

SEC Corporation Finance Provides Additional Guidance on the Disclosure of Material Cybersecurity Incidents in Form 8-K

Alston & Bird on

On June 24, 2024, the Division of Corporation Finance (“Corp Fin”) of the Securities and Exchange Commission (“SEC”) issued five new Compliance and Disclosure Interpretations (“C&DIs”) related to the disclosure of “material”...more

Fenwick & West LLP

SEC Releases New 8-K CDIs for Item 1.05 - Cybersecurity Incidents

Fenwick & West LLP on

On June 24, 2024, the SEC released five new CDIs on Material Cybersecurity Incidents. Please see a high-level summary below...more

Mayer Brown Free Writings + Perspectives

SEC Announces New Cybersecurity Interpretations

The SEC’s Division of Corporation Finance yesterday published five new Compliance and Disclosure Interpretations, or “C&DIs,” all concerning Item 1.05 of Exchange Act Form 8-K, Disclosure of Cybersecurity Incidents....more

Wyrick Robbins Yates & Ponton LLP

Living in a Material World: SEC Clarifies Expectations Regarding Form 8-K Disclosure of Material Cybersecurity Incidents

Last month, the Director of the Division of Corporation Finance (“Director”) of the Securities and Exchange Commission (“SEC”) issued new guidance regarding disclosures of material cybersecurity incidents via Form 8-K under...more

Goodwin

SEC Staff Makes Clear That Cybersecurity Incident Disclosures Under Item 1.05 of Form 8-K Should Be Limited to Material...

Goodwin on

On May 21, 2024, Erik Gerding, director of the Division of Corporation Finance of the U.S. Securities and Exchange Commission (SEC), issued a statement with clarifying guidance on cybersecurity incident disclosure under Item...more

Mayer Brown Free Writings + Perspectives

Avoiding Cybersecurity Incident Overdisclosure:  Helpful Guidance

In a statement yesterday, the Director of the SEC’s Division of Corporation Finance commented on the relatively new Form 8-K Item 1.05 requirement.  Last summer when the SEC adopted the final rules relating to cybersecurity...more

Stinson - Corporate & Securities Law Blog

SEC Director of Corporation Finance Speaks to Cybersecurity Disclosures

Erik Gerding, Director, Division of Corporation Finance, released a statement on the preferred methods to disclose certain cybersecurity incidents.  Mr. Gerding noted “The cybersecurity rules that the Commission adopted on...more

Burr & Forman

Cyber Incident Reporting Obligations for Public Companies under the SEC’s New Cybersecurity Rules

Burr & Forman on

The U.S. Securities Exchange Commission (SEC) recently adopted a final rule regarding cybersecurity risk management, governance, and incident reporting. The final rule went into effect on September 5, 2023, and disclosure...more

Polsinelli

The SEC Raises the Stakes: New Cybersecurity Rules for Publicly Traded Companies Hit the Books in 2023

Polsinelli on

In 2023, the U.S. Securities and Exchange Commission (“SEC”) issued its now-fully implemented Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Rule. The Rule reflects the reality that cybersecurity...more

Saul Ewing LLP

Public Companies Quarterly Update (Q4 2023)

Saul Ewing LLP on

Welcome to Saul Ewing’s Public Companies Quarterly Update series. Our intent is to, on a quarterly basis, highlight important legal developments of which we think public companies should be aware. This edition is related to...more

Mayer Brown Free Writings + Perspectives

Cybersecurity Disclosure and Compliance & Disclosure Interpretations

Recently, in advance of the effective date (December 18, 2023), the Director of the SEC’s Division of Corporation Finance provided additional guidance regarding the final rules relating to cybersecurity incident disclosure...more

Brownstein Hyatt Farber Schreck

Cyber Criminals Weaponize SEC’s Future Cyber Disclosure Rules

In a first for both cybersecurity and securities law, a ransomware company filed a complaint with the U.S. Securities and Exchange Commission (“SEC”) against its own hacking victim for failure to disclose the hack itself. The...more

Thomas Fox - Compliance Evangelist

SEC, Solar Winds and Compliance

The recent SEC lawsuit against SolarWinds Corp and its CISO, Tim Brown, following the 2020 data breach, has brought the issue of executive liability in cybersecurity disclosures to the forefront. This case sheds light on the...more

Robinson+Cole Data Privacy + Security Insider

SEC Hits SolarWinds and CISO with Investor Fraud Suit Over Cybersecurity

In a first, bold move by the Securities and Exchange Commission (SEC) following its new Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies, issued on July 26, 2023, this...more

Woods Rogers

Examining Materiality and Cybersecurity Incidents: Practical Tips for Implementing the New SEC Rules

Woods Rogers on

Publicly traded companies have tangled with the question of when a cybersecurity incident should be disclosed to the public and investors. In a bid to add clarity to the topic, the U.S. Securities and Exchange Commission...more

Nelson Mullins Riley & Scarborough LLP

SEC Adopts New Cybersecurity Disclosure Requirements

The Securities and Exchange Commission (“SEC”) adopted the final rules (the “Final Rules”) on July 26, 2023 that will require disclosure of material cybersecurity incidents, cybersecurity risk management, strategy, and...more

Holland & Knight LLP

SEC Cybersecurity Rules: Considerations for Incident Response Planning

Holland & Knight LLP on

The new Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure rules (Final Rules) adopted by the U.S. Securities and Exchange Commission (SEC) were published in the Federal Register on Aug. 4, 2023, and...more

Epiq

Breaking Down the New SEC Cybersecurity Rules

Epiq on

On July 26, the Securities and Exchange Commission (SEC) adopted new cybersecurity rules. Organizations will need to disclose material cyber incidents pursuant to a prescribed timeline and information regarding risk...more

Wyrick Robbins Yates & Ponton LLP

SEC Adopts Final Cybersecurity Rules

Following up on our previous report from almost a year ago, the U.S. Securities and Exchange Commission (the “SEC” or “Commission”) has adopted final rules intended to enhance and standardize disclosures regarding...more

The Volkov Law Group

SEC Adopts Robust New Cybersecurity Disclosure Rules

The Volkov Law Group on

In late July 2023, the Securities and Exchange Commission (“SEC”) adopted new rules requiring public companies to disclose cybersecurity incidents and cybersecurity governance policies and practice.  The SEC largely adopted...more

A&O Shearman

SEC Mandates New Cybersecurity Disclosures

A&O Shearman on

On July 26, 2023, the SEC adopted final rules that require public companies to promptly disclose material cybersecurity incidents on Form 8-K and detailed information regarding their cybersecurity risk management and...more

Polsinelli

SEC Adopts Cybersecurity Incident and Risk Management Disclosure Rules

Polsinelli on

On July 26, 2023, the Securities and Exchange Commission (the “SEC”) adopted new rules requiring public companies to disclose within four business days material cybersecurity incidents they experience and to disclose annually...more

42 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide