SEC Adopts Robust Cybersecurity Disclosure Rules for Public Companies: What You Need to Know
In late July 2023, the Securities and Exchange Commission (SEC) adopted novel rules, necessitating public companies to disclose cybersecurity incidents and their policies and practices regarding cybersecurity governance. Borrowing mostly from their original proposal issued in March 2022, the SEC has made some modifications to the requirements of cybersecurity disclosure. These changes were adopted by…