News: 1716395413

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Confused by the SEC's IT security breach reporting rules? Read this

(2024/05/22)


The US Securities and Exchange Commission (SEC) wants to clarify guidelines for public companies regarding the disclosure of ransomware and other cybersecurity incidents.

According to the [1]breach reporting rules the federal agency adopted in July, public companies must disclose material events under Item 1.05 of Form 8-K. This is the form the SEC requires public companies to submit when they announce big changes that may be material to shareholders.

It means that should a publicly traded company experience a "material" cybersecurity intrusion – one that has a financial impact on the company's operations, or that an investor would want to know before making an investment decision – they need to publicly report it under Item 1.05. In fact, Item 1.05 is titled "Material Cybersecurity Incidents."

[2]

The fuzziness comes into play when companies disclose a breach for which they [3]haven't made a materiality determination , or security snafus that the company flat-out says were not material.

[4]

[5]

For these, fill out Item 8.01 of Form 8-K, we're told.

"It could be confusing for investors if companies disclose either immaterial cybersecurity incidents or incidents for which a materiality determination has not yet been made under Item 1.05," [6]said Erik Gerding, director of the SEC's Division of Corporation Finance.

[7]Biden will veto attempts to kill off SEC's security breach reporting rules

[8]Crooks pwned your servers? You've got four days to tell us, SEC tells public companies

[9]SolarWinds says SEC sucks: Watchdog 'lacks competence' to regulate cybersecurity

[10]Finance orgs have 30 days to confess cyber sins under incoming FTC rules

He added that this "is not intended to discourage companies from voluntarily disclosing cybersecurity incidents for which they have not yet made a materiality determination, or from disclosing incidents that companies determine to be immaterial."

These voluntary disclosures do have value, he opined, but they can also "result in investor confusion" and "dilute the value" of disclosing material cybersecurity incidents in the first place.

[11]

"Given the prevalence of cybersecurity incidents, this distinction between a Form 8-K filed under Item 1.05 for a cybersecurity incident determined by a company to be material and a Form 8-K voluntarily filed under Item 8.01 for other cybersecurity incidents will allow investors to more easily distinguish between the two and make better investment and voting decisions with respect to material cybersecurity incidents," Gerding said.

So, to be crystal clear, if it's material, file a Form 8-K, Item 1.05. If it's voluntary, or you've yet to determine whether it was material, go with Form 8-K, Item 8.01 instead. ®

Get our [12]Tech Resources



[1] https://www.theregister.com/2023/07/26/sec_reporting_security/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zk5q-6jzz7xYKXEm3JnR8AAAAAo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2024/03/08/microsoft_confirms_russian_spies_stole/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zk5q-6jzz7xYKXEm3JnR8AAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zk5q-6jzz7xYKXEm3JnR8AAAAAo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.sec.gov/news/statement/gerding-cybersecurity-incidents-05212024

[7] https://www.theregister.com/2024/02/01/senate_resolution_to_undo_sec/

[8] https://www.theregister.com/2023/07/26/sec_reporting_security/

[9] https://www.theregister.com/2023/11/09/solarwinds_sec_filing/

[10] https://www.theregister.com/2023/10/31/ftc_30_day_breach_disclosure/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zk5q-6jzz7xYKXEm3JnR8AAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



<Deek> That reminds me, we'll need to buy a chainsaw for the office. "In
case of emergency, break glass"