Skip to Primary Navigation

New SEC cyber disclosure rules take effect

Image of the silhouette of a man on a computer against a digital background.
Photo: Bill Hinton/Getty Images

Companies now need to disclose on risk management, strategy and governance procedures – and on material cyber incidents by December 18.

This July, the SEC voted to adopt final rules on cybersecurity disclosure. As of December 15, companies need to disclose their cyber-risk management, strategy and governance procedures – and then disclose any material cyber incidents by December 18 – under those rules. (Smaller reporting companies have a 180-day deferral.)

Rules recap

In