Current:Home > reviewsCyber breaches cost investors money. How SEC's new rules for companies could benefit all. -ProfitLogic
Cyber breaches cost investors money. How SEC's new rules for companies could benefit all.
View
Date:2025-04-23 00:04:51
The U.S. Securities and Exchange Commission announced new rules yesterday requiring public companies to disclose cybersecurity incidents as soon as four business days.
SEC Chair Gary Gensler said the disclosure "may be material to investors" and could benefit them, the companies and markets connecting them.
“Currently, many public companies provide cybersecurity disclosure to investors. I think companies and investors alike, however, would benefit if this disclosure were made in a more consistent, comparable, and decision-useful way," he said.
The new rules were proposed in March 2022 after the SEC noted the increase in cybersecurity risks following the way companies pivoted toward remote work, moving more operations online, use of digital payments, increased reliance on third-party service providers for services like cloud computing technology, and how cyber criminals are able to monetize cybersecurity incidents.
What is the SEC cyber disclosure rule?
Under the new rules, companies are required to fill out the brand new 8-K form, which will have Item 1.05 added to disclose cybersecurity incidents. It will require disclosing and describing the nature, scope, and timing of the incident, material impact or reasonably likely material impact, including the financial condition and results of operations.
If the incident will have a significant effect, then the company has to report it in four days. But if the U.S. Attorney General deems the immediate disclosure a risk to national security or public safety, disclosure could be delayed.
The new regulation requires companies to describe their process assessing cybersecurity threats, how their board of directors oversee cybersecurity threats, and how management assesses the threat.
Foreign companies will use the amended 6-K form to disclose cybersecurity incidents and the amended 20-F form for periodic disclosure.
How much does a data breach cost a business?
In this year's "Cost of a Data Breach Report" by IBM Security, the average cost of a data breach in 2023 was $4.45 million, a 2.3% increase from 2022 when it was $4.35 million. The United States has lead the way for 13 consecutive years in highest data breach costs. This year, the Middle East, Canada, Germany and Japan also made up the top five countries with the most expensive data breaches.
During ransomware attacks, companies that excluded law enforcement paid 9.6% more and experienced a longer breach at 33 days.
Only one-third of the companies found data breaches themselves, while the rest were reported by the attackers themselves or by a third party. Among industries, health care had the highest data breach costs in the U.S. this year, followed by the financial, pharmaceutical, energy, and industrial sectors in order.
veryGood! (8)
Related
- North Carolina trustees approve Bill Belichick’s deal ahead of introductory news conference
- Global Warming Is Pushing Arctic Toward ‘Unprecedented State,’ Research Shows
- The first wiring map of an insect's brain hints at incredible complexity
- Solyndra Shakeout Seen as a Sign of Success for Wider Solar Market
- The White House is cracking down on overdraft fees
- 3 children among 6 found dead in shooting at Tennessee house; suspect believed to be among the dead
- Tennessee becomes the first state to pass a ban on public drag shows
- Ireland Baldwin Gives Birth, Welcomes First Baby With Musician RAC
- Gen. Mark Milley's security detail and security clearance revoked, Pentagon says
- New American Medical Association president says we have a health care system in crisis
Ranking
- The Louvre will be renovated and the 'Mona Lisa' will have her own room
- North Carolina’s Goal of Slashing Greenhouse Gases Faces Political Reality Test
- Vanderpump Rules Finale: Tom Sandoval and Raquel Leviss Declare Their Love Amid Cheating Scandal
- Michael Jordan plans to sell NBA team Charlotte Hornets
- Louvre will undergo expansion and restoration project, Macron says
- New details emerge about American couple found dead in Mexico resort hotel as family shares woman's final text
- A doctor near East Palestine, Ohio, details the main thing he's watching for now
- Solyndra Shakeout Seen as a Sign of Success for Wider Solar Market
Recommendation
Where will Elmo go? HBO moves away from 'Sesame Street'
Australian airline rolls out communal lounge for long-haul flights
Jill Duggar Is Ready to Tell Her Story in Bombshell Duggar Family Secrets Trailer
Ja Morant suspended for 25 games without pay, NBA announces
DoorDash steps up driver ID checks after traffic safety complaints
Natural Gas Leak in Cook Inlet Stopped, Effects on Marine Life Not Yet Known
Tori Spelling Says Mold Infection Has Been Slowly Killing Her Family for Years
North Carolina’s Goal of Slashing Greenhouse Gases Faces Political Reality Test