Skip to Primary Navigation

SEC adopts cybersecurity, strategy, governance, and incident disclosure rules

ecurities and Exchange Commission Chairmain Gary Gensler talks in a senate hearing
Photo: Win McNamee/Getty Images

The rules will require registrants to describe processes for identifying and managing material risks from cybersecurity threats.

Rules that require registrants to disclose experienced material cybersecurity incidents, including annual material information on cybersecurity risk management, strategy, and governance have just been adopted by the SEC. Foreign private issuers will also be required to make comparable disclosures.

With the adopted rules, registrants will, on the new Item 1.05

  • nature;

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience