Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity NewsGovernment: Federal, State and Local

Security leaders discuss new SEC disclosure rule as deadline nears

By Rachelle Blair-Frasier, Editor in Chief
Cybersecurity hand graphic

Image via Pixabay

December 14, 2023

In a ruling this summer, the U.S. Securities and Exchange Commission (SEC) voted to adopt final rules on cybersecurity disclosure.

In a 3-to-2 vote, the SEC adopted rules that requires disclosure of material cybersecurity incidents on Form 8-K and periodic disclosure of a registrant’s cybersecurity risk management, strategy and governance in annual reports. Among the rules, the ruling requires reporting material cybersecurity incidents to the SEC within four days of determining the incident is material. Effective December 15, companies will need to disclose on their risk management, strategy and governance procedures, and material cyber incidents by December 18.

Security leaders weigh in

With those dates fast approaching, security leaders are sharing their thoughts on the ruling and its effect on the industry.

John Pirc, Vice President at Netenrich:

The new SEC cybersecurity disclosure rules represent a significant advancement in corporate transparency and investor protection. By mandating timely disclosure of material cybersecurity incidents and the requirement for detailed annual reporting on risk management strategies, these rules bring much-needed clarity and standardization to how public companies report cybersecurity issues.

This move is particularly commendable as it aligns with the growing importance of digital security in today’s interconnected business landscape. However, while the rules offer flexibility in the timing of disclosures, the four-day window for reporting material incidents may pose challenges for companies in accurately assessing and disclosing complex cybersecurity events.

Additionally, the rules’ emphasis on both internal and third-party cybersecurity incidents underscores the increasing complexity of managing digital risk in a cloud-centric world. Overall, these regulations are a positive step towards greater corporate accountability and enhanced investor confidence in the face of escalating cyber threats.

Joseph Carson, Chief Security Scientist and Advisory CISO at Delinea:

With the implementation of the new SEC cybersecurity disclosure rules, organizations must further invest and improve their incident response plan and process to meet the new SEC rules, such as identifying cybersecurity incidents that have a material impact to the business and also report those incidents within four business days of discovery. Incident response tends to focus on identifying the impact of a cybersecurity incident and getting the business back to operations. However, the incident response team must now also identity the business risks and material impact to determine if they need to report and disclose the incident. The new rules are focused on ensuring that incident reporting is more consistent and safeguard that investors have transparency into cybersecurity incidents. In the past, the average dwell time for an incident was more than 200 days. These new rules will have a significant impact on how organizations report incidents going forward and will likely see large investments into an organizations risk assessment and incident response strategy.

Michael Mumcuoglu, CEO and Co-Founder at CardinalOps:

One of the key changes with the SEC rule that is different from the previous guidance in 2018 is that, in 10-K reports, organizations will now be required to describe their processes for "assessing, identifying and managing material risks from cybersecurity threats” as well as to “describe the board of directors’ oversight of risks from cybersecurity threats and management’s role and expertise in assessing and managing material risks from cybersecurity threats.” This puts a greater emphasis on the necessity for companies to assess and validate their existing security controls and to have increased visibility into their overall ability to effectively detect potential threats. We've seen growing interest in this area for a while now, so much so that Gartner research has introduced a new category, automated security control assessment (ASCA), that covers solutions that improve an organization's security posture by verifying the proper, consistent configuration of security controls in order to better manage and reduce risk.

Nakul Goenka, Risk Officer at ColorTokens:

The SEC has approved new cybersecurity rules, which is a significant step in the right direction. These breach disclosure rules will help give CISOs a seat at the table. Companies should start preparing and thinking about their policies, procedures, organizational structure and tool sets immediately.

While the rules do offer flexibility to determine what is considered a “material” incident and hence reportable, we might also see some litigation based on decisions taken by the management teams. It will be interesting to see how these rules are actually implemented and whether the benefits will outweigh the costs and burden.

Claude Mandy, Chief Evangelist, Data Security at Symmetry Systems:

The SEC Cyber Disclosure Rule transforms transparency into cybersecurity risk management and incidents from good practice to regulatory necessity. The challenge for CISO’s at public companies will be how they can balance promptness with thoroughness in assessing whether an incident is material.

The SEC’s definition of material cybersecurity incidents are nuanced and broad, including incidents that jeopardize (not only impact) the confidentiality, integrity and availability of systems and data.

This requires CISO’s (even with the comfort of self-determining materiality) to be able to substantiate their decision that jeopardy from the incident was not material. In the light of attackers weaponizing the SEC whistleblowing mechanisms, CISO’s must be able to methodically prove quickly that systems and data were not jeopardized - with the threat that attackers will prove them wrong.

KEYWORDS: cyber incident response Cyber response cybersecurity compliance regulatory compliance SEC regulations security leaders

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Rachelle blairfrasier headshot white

Rachelle Blair-Frasier is Security magazine’s Editor in Chief. Blair-Frasier handles eMagazine features, as well as writes and publishes online news and web exclusives on topics including physical security, risk management, cybersecurity and emerging industry trends. She helps coordinate multimedia content and manages Security magazine's social media presence, in addition to working with security leaders to publish industry insights. Blair-Frasier brings more than 15 years of journalism and B2B writing and editorial experience to the role.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • Mac

    Security leaders discuss new phishing campaign targeting Mac users

    See More
  • Circuitboard- red

    Security leaders chime in on new SEC disclosure rules

    See More
  • Broken glass

    Security leaders discuss the new vulnerability added to CISA’s catalog

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing