New SEC Cybersecurity Disclosure Rules

New SEC Cybersecurity Disclosure Rules

Blog WilmerHale Privacy and Cybersecurity Law
On July 26, 2023, the Securities and Exchange Commission (the “SEC”), voted to adopt new rules for public companies that will require disclosures regarding “material” cybersecurity incidents, as well as cybersecurity risk management, strategy, and governance. The new rules include both current and periodic reporting requirements, and marks a significant expansion in the way that public companies make disclosures relating to cybersecurity. The new rules will become effective 30 days from publication in the Federal Register and will apply broadly to all public companies, including foreign private issuers, emerging growth companies and smaller reporting companies. 

For additional discussion of some key rule highlights, see this post on our Focus on Audit Committees, Accounting and the Law blog. Given the interdisciplinary nature of cybersecurity issues, we are working closely with our corporate disclosure colleagues to develop recommendations on steps companies should take in response to the new requirements and look forward to sharing our collective thoughts in a forthcoming client alert.

Authors

More from this series

Notice

We appreciate your interest in WilmerHale. While we are pleased to have you contact us, please keep in mind that merely contacting WilmerHale does not create an attorney-client relationship. Such a relationship will not arise until the Firm agrees in writing to represent you in connection with a particular matter. Importantly, unless and until this has occurred, you should not provide us with any confidential information, and we have no duty to keep confidential any information that we may receive from you. Thank you for your understanding.