By
Kyle Brasseur2023-07-26T16:30:00
The Securities and Exchange Commission (SEC) on Wednesday finalized its controversial rule requiring public companies to disclose the nature, scope, timing, and impact of cybersecurity incidents deemed to be material within four business days.
The rule, proposed in March 2022, has received significant attention in the past year for the relatively short timeline it provides businesses to grasp the extent of a cybersecurity incident such as a data breach. Also short will be its compliance date, as large companies as soon as December could be required to begin making the new disclosures.
Smaller reporting companies will receive an additional 180 days to comply.
You are not logged in and do not have access to members-only content.
If you are already a registered user or a member, SIGN IN now.
2023-12-13T18:04:00Z By Kyle Brasseur
Companies won’t have an easy path toward earning additional time from the Department of Justice regarding the disclosure of a material cybersecurity incident to the Securities and Exchange Commission as required under a new rule.
2023-10-16T21:16:00Z By Jeff Dale
Software company Blackbaud agreed to pay $49.5 million in a multistate settlement addressing charges related to a 2020 cyberattack that exposed the personal data of approximately 13,000 consumers.
2023-08-04T18:01:00Z By Adrianne Appel
Covington & Burling is leaving open the possibility of appealing a recent federal court order requiring the law firm to provide the names of hacked clients to the Securities and Exchange Commission.
2026-02-27T21:15:00Z By Ruth Prickett
Sustainability reporting rules for U.K. listed companies are set to change. The U.K. financial regulator has launched a consultation laying out its proposals, which aim to align the reporting regime with the international ISSB standards.
2026-02-26T21:47:00Z By Ruth Prickett
Firms offering “buy now, pay later” financing will become part of the regulated financial services sector in the U.K. from July 15. Compliance teams must act now to ensure they are ready to introduce rules and establish creditworthiness assessment processes, adapt systems, and change data processes before the deadline.
2026-02-25T20:18:00Z By Neil Hodge
New rules that will be introduced this June will require companies based in the European Union (EU) to explain why some workers are paid more money for the same job and remedy any “unjustified” discrepancies.
Site powered by Webvision Cloud