SEC Continues to Emphasize Importance of Cybersecurity and Cyber Risk Governance

“While this is an oversimplification of all of the requirements and nuances of the forthcoming SEC rules, the SEC’s objectives are to require companies to provide meaningful and actionable information to shareholders to better understand companies’ cyber risks and how companies are managing and responding to them. From a very high level, this can be broken down into two categories of what they are wanting to see companies disclose information about: proactive cyber risk governance and risk management, and reactive incident response and reporting.”

The quote above is one I provided to SecureWorld for its article SEC to Put More Onus on Corporate Boards for Cybersecurity as it is my view of what the SEC is really trying to do with all of this — they want to make sure that investors have the best information possible about companies’ risks to better inform their investing decisions. This is a good thing. The by-product of this is that by forcing companies to do many of these things, those companies’ cybersecurity will be improved. This is a good thing.

Will there be some negatives? Of course — there will be — but we will have to work through those and hopefully the positive will outweigh the negative.

Read more of my thoughts, as well as others, on this issue in the full SecureWorld article: SEC to Put More Onus on Corporate Boards for Cybersecurity

Also check out this article I wrote for Ethical Boardroom that emphasizes the need for CISOs to have a seat at the grown ups table — that is — a direct line of communication to the Board: A Lesson in Humility from the FireEye and SolarWinds Cyber Attack

Finally, check out my post from back in 2022 about this issue with the SEC: Is This the Next Evolution of Cyber Risk Governance? The SEC Is About To Force CISOs Into America’s Boardrooms

Published by Shawn E. Tuma

Shawn Tuma is an attorney who is internationally recognized in cybersecurity, computer fraud and data privacy law, areas in which he has practiced for nearly two decades. He is a Partner at Spencer Fane, LLP where he regularly serves as outside cybersecurity and privacy counsel to a wide range of companies from small to midsized businesses to Fortune 100 enterprises. You can reach Shawn by telephone at 972.324.0317 or email him at stuma@spencerfane.com.

Leave a comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from Business Cyber Risk

Subscribe now to keep reading and get access to the full archive.

Continue reading