Publication
SEC Adopts Final Cybersecurity Disclosure Rules
On July 26, 2023, the U.S Securities and Exchange Commission (SEC) adopted long-awaited amendments to its rules requiring public companies to disclose material cybersecurity incidents on Form 8-K and provide disclosures regarding cybersecurity risk management, strategy, and governance in their annual reports on Form 10-K. Ice Miller anticipates that the SEC will take an aggressive approach toward investigating reports of cybersecurity incidents and ensuring that companies comply with these newly required cybersecurity disclosure obligations in their filings.
What is required?
The final rules will require domestic issuers to disclose, on new Item 1.05 of Form 8-K, any cybersecurity incident [1] that the issuer determines to be material, and “describe the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely impact on the registrant, including its financial condition and results of operations.” These disclosures must generally be made within four business days of the issuer’s determination that the incident is material. [2] The filing trigger is based upon the issuer’s materiality determination, without unreasonable delay, and not upon the occurrence or the discovery of the incident. To the extent any required information is not determined or is unavailable at the time of the initial Form 8-K filing, the issuer must include a statement to that effect. The issuer must then amend the prior Item 1.05 Form 8-K to disclose such information within four business days after it, without unreasonable delay, determines such information or such information becomes available. The untimely filing of an Item 1.05 Form 8-K will not result in the loss of Form S-3 eligibility. Item 1.05 is also included in the list of Form 8-K items eligible for the limited safe harbor from liability under Section 10(b) or Rule 10b-5 under the Securities Exchange Act of 1934.
Issuers will need to provide new annual disclosures relating to cybersecurity risks in their Forms 10-K. New Regulation S-K Item 106(b) will require issuers to describe their “processes, if any, for assessing, identifying, and managing material risks from cybersecurity threats [3] in sufficient detail for a reasonable investor to understand those processes.” The rules include a non-exclusive list of disclosures that should be addressed:
- Whether and how such processes have been integrated into the issuer’s overall risk management system or processes;
- Whether the issuer engages any assessors, consultants, auditors, or other third parties in connection with any such processes; and
- Whether the issuer has processes to oversee and identify such risks from cybersecurity threats associated with its use of any third-party service provider.
Item 106(b) also requires a description of whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the issuer, including its business strategy, results of operations, or financial condition.
Under new Item 106(c), issuers must describe the board of directors’ oversight of risks from cybersecurity threats, including identifying any board committees or subcommittees responsible for such oversight and the processes by which the board or such committee is informed about such risks. Issuers must also describe management’s role in assessing and managing material risks from cybersecurity threats. The rules include a non-exclusive list of disclosures that issuers should consider addressing:
- Whether and which management positions or committees are responsible for assessing and managing such risks, and a description of any relevant expertise of such persons or members;
- The processes by which such persons or committees are informed about and monitor the prevention, detection, mitigation and remediation of such risks; and
- Whether such persons or committees report information to the board of directors.
Foreign private issuers (FPIs) are subject to similar disclosure requirements. FPIs must furnish on Form 6-K information regarding material cybersecurity incidents that they disclose or otherwise publicize in a foreign jurisdiction to any stock exchange or to security holders. FPIs will also be required to describe the board of directors’ oversight of risks from cybersecurity threats, as well as management’s role in assessing and managing material risks from cybersecurity threats in their annual Form 20-F filings.
When are the rules effective?
The final rules will be effective 30 days following publication of the adopting release in the Federal Register. All issuers, other than smaller reporting companies (SRCs), must comply with the disclosure requirements of Item 1.05 of Form 8-K or in Form 6-K, as applicable, by 90 days after the date of publication in the Federal Register or December 18, 2023. SRCs must comply with Item 1.05 of Form 8-K on the later of 270 days from the effective date of the rules or June 15, 2024. All issuers must provide the required disclosures in Form 10-K or Form 20-F, as applicable, beginning with annual reports for fiscal years ending on or after December 15, 2023.
What’s next?
Companies should begin taking steps to comply with the new rules in advance of the upcoming deadlines, including:
- Review and update their incident response plan and develop specific policies and procedures to promptly identity, mitigate and respond to cybersecurity incidents.
- Ensure their cybersecurity risk program includes a comprehensive risk assessment program to assess prevalent risks, as well as the likely impact on the company, and develop a plan to mitigate against such risks.
- Create oversight programs and procedures for the board of directors and ensure management has adequate programs and procedures in place for assessment, management, and information-sharing with the board of directors for the occurrence of incidents. This will include educating members of management and the board about cybersecurity and relevant risks.
- Evaluate specific board member and management roles and identify any relevant expertise related to cybersecurity.
- Train the workforce on areas of cybersecurity compliance to meet the SEC reporting requirements.
- Develop a program to manage third-party vendors and supply chain risks. This will include requiring adequate cybersecurity controls and maintaining oversight over a company’s third party vendors and suppliers.
For more information relating to this topic, please reach out to Siddharth Bose, Pierce Haesung Han, Steve Hackman, Jim Watson, or any other Ice Miller attorney.
[1] The final rules define a “cybersecurity incident” as “an unauthorized occurrence, or a series of related unauthorized occurrences, on or conducted through a registrant’s information systems that jeopardizes the confidentiality, integrity, or availability of a registrant’s information systems or any information residing therein”, and “information systems” as “electronic information resources, owned or used by the registrant, including physical or virtual infrastructure controlled by such information resources, or components thereof, organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of the registrant’s information to maintain or support the registrant’s operations.”
[2] Issuers may delay disclosure up to seven business days following notification of the cybersecurity incident to the United States Secret Service and the Federal Bureau of Investigation pursuant to the Federal Communication Commission’s notification rule for breaches of customer proprietary network information, with written notification to the SEC. Disclosure may also be delayed if the United States Attorney General determines immediate disclosure would pose a substantial risk to national security or public safety and notifies the SEC of such determination in writing.
[3] The final rules define a “cybersecurity threat” as “any potential unauthorized occurrence on or conducted through a registrant’s information systems that may result in adverse effects on the confidentiality, integrity or availability of a registrant’s information systems or any information residing therein.”
This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader's specific circumstances.