SEC cybersecurity incident disclosure requirements
2026 SEC rule
From Wikipedia, the free encyclopedia
The SEC cybersecurity incident disclosure requirements are rules adopted in 2023 by the U.S. Securities and Exchange Commission (SEC) requiring publicly traded companies to disclose material cybersecurity incidents and to provide periodic information about cybersecurity risk management, governance, and oversight.[1][2][3]
The rules amend reporting requirements under U.S. federal securities laws, including new disclosure obligations in Form 8-K and periodic reporting forms.[4]
Background
The SEC proposed cybersecurity disclosure rules in 2022 amid increasing concerns about cyberattacks affecting public companies and the lack of consistent disclosure of cybersecurity risks to investors. The SEC adopted the rules on 26 July 2023.[5] The rule became effective on 5 September 2023.[6] Regulators argued that standardised reporting would improve transparency regarding how companies manage cybersecurity threats and incidents.[7]