LONDON WALLET
  • Home
  • Investing
  • Business Finance
  • Markets
  • Industries
  • Opinion
  • UK
  • Real Estate
  • Crypto
No Result
View All Result
LONDON WALLET
  • Home
  • Investing
  • Business Finance
  • Markets
  • Industries
  • Opinion
  • UK
  • Real Estate
  • Crypto
No Result
View All Result
LondonWallet
No Result
View All Result

The SEC wants corporate America to tell investors more about cybersecurity breaches and what’s being done to fight them

Garry Wills by Garry Wills
July 26, 2023
in Business Finance
The SEC wants corporate America to tell investors more about cybersecurity breaches and what’s being done to fight them
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter


You might also like

Stocks making the biggest moves after hours: Costco, Marvell Technology, Gap & more

Mortgages in 47 seconds: Better’s new ChatGPT app targets lenders Rocket and UWM

Oaktree’s Howard Marks says there’s no systemic problem with private credit

The Securities and Exchange Commission wants corporate America to tell investors more about cybersecurity breaches and what’s being done to fight them. Much more. 

The SEC is scheduled to vote today on rules that would require public companies to disclose “material” cybesecurity breaches within four days after a determination that an incident was material. 

related investing news

CNBC Pro

The SEC says it is necessary to collect the data to protect investors. Corporate America is pushing back, claiming that the short announcement period is unreasonable, and that it would require public disclosure that could harm corporations and be exploited by cybercriminals. 

If adopted, the final rules will become effective 30 days following publication of the release in the Federal Register. 

Current cybersecurity rules are fuzzy 

Current rules on when a company needs to report a cybersecurity event are fuzzy. Companies have to file an 8-K report to announce major events to shareholders, but the SEC believes that the reporting requirements for reporting a cybersecurity event are “inconsistent.” 

In addition to requiring public companies to disclose cybersecurity breaches within four days, the SEC wants additional details to be disclosed, such as the timing of the incident and the material impact on the company. It will also require disclosure of management expertise on cybersecurity. 

The pushback from corporate America sounds strikingly similar to the pushback from many of the other rulemaking proposals SEC Chair Gary Gensler has made or proposed: too much. 

“The SEC is calling for public disclosure of considerably too much, too sensitive, highly subjective information, at premature points in time, without requisite deference to the prudential regulators of public companies or relevant cybersecurity specialist agencies,” the Securities Industry and Financial Markets Association (SIFMA), an industry trade group, said in a letter to the SEC. 

Industry objections

The most prominent industry concerns are: 

  • Four days is too short a period. SIFMA and others claim that four days denies companies time to first focus on remediating and mitigating the impacts of any incident. 
  • Premature public disclosure could harm companies. The NYSE, on behalf of its listed companies, has written to the SEC saying that corporations should be allowed to delay public disclosures in two circumstances: 1) pending remediation of the incident, and 2) if law enforcement determines that a disclosure will interfere with a civil or criminal investigation. 

The proposed rule allows the Attorney General to delay reporting if the AG determines that immediate disclosure would pose a substantial risk to national security. 

“Premature public disclosure of an incident without certainty that the threat has been extinguished could provide bad actors with useful information to expand an attack,” Hope Jarkowski, NYSE Group general counsel, said in the letter. 

Nasdaq, in a separate letter to the SEC, agrees, noting that “the obligation to disclose may reveal additional information to an unauthorized intruder who may still have access to the company’s information systems at the time the disclosure is made and potentially further harm the company.” 

Concerns about duplicate reporting 

Another concern is overlapping regulations. Many public companies already have procedures in place to share critical information about cyber incidents with other federal agencies, including the FBI. 

The lead agency that deals with cybersecurity is the Cybersecurity and Infrastructure Security Agency (CISA) in the Department of Homeland Security. Under legislation passed last year, CISA is adopting cybersecurity rules that require “critical infrastructure entities,” which would include financial institutions, to report cyberbreaches within three days to CISA. 

This would conflict with the SEC’s four-day rule, and would also create duplicate reporting requirements. 

All this goes to the central issue of who should be regulating cybersecurity. “The Commission is not a prudential cybersecurity regulator for all registrants,” SIFMA said. 

What is the SEC trying to accomplish? 

Cybersecurity is only a small part of the more than 50 proposed rules Gensler has out for consideration, nearly 40 of which are in the Final Rule stage. 

If there is an underlying theme behind much of Gensler’s extensive rulemaking agenda, it is “disclosure.”  More disclosure about cybersecurity, board diversity, climate change and dozens of other issues. 

“Gensler is claiming he wants more transparency and thinks that will protect investors,” Mahlet Makonnen, a principal at Williams & Jensen, told me. 

“The fear the industry has is that the data collected will put unnessary burdens on industry, does not actually protect investors, and that the data can be used to grow the aggressive enforcement tactics under Gensler,” she said. 

“The more information they have, the more the SEC can determine if there are any violations of rules and regulations. It allows them to expand enforcement actions. The SEC will say they have broad authority to protect investors, and the disclosures can be used to expand the enforcement actions.” 

Another long-time observer of the SEC, who asked to remain anonymous, agreed that the ultimate goal of stepped up disclosure is to expand the SEC’s enforcement power. 

“It will enable the SEC to claim they are protecting investors, and it will enable them to ask Congress for more money,” the observer told me. 

“You don’t get more money from Congress by asking for money for market structure. You get more money by claiming you are protecting grandma.”



Source link

Share30Tweet19
Previous Post

Bank of Italy innovation hub supports research into security tokens on secondary markets

Next Post

Government’s £24m boost to clear planning backlog ‘not enough’

Garry Wills

Garry Wills

Recommended For You

Stocks making the biggest moves after hours: Costco, Marvell Technology, Gap & more
Business Finance

Stocks making the biggest moves after hours: Costco, Marvell Technology, Gap & more

March 5, 2026
Mortgages in 47 seconds: Better’s new ChatGPT app targets lenders Rocket and UWM
Business Finance

Mortgages in 47 seconds: Better’s new ChatGPT app targets lenders Rocket and UWM

March 5, 2026
Oaktree’s Howard Marks says there’s no systemic problem with private credit
Business Finance

Oaktree’s Howard Marks says there’s no systemic problem with private credit

March 5, 2026
States led by New York sue to block Trump’s latest tariffs, calling them an illegal end-run around Supreme Court
Business Finance

States led by New York sue to block Trump’s latest tariffs, calling them an illegal end-run around Supreme Court

March 5, 2026
Next Post
Government’s £24m boost to clear planning backlog ‘not enough’

Government’s £24m boost to clear planning backlog ‘not enough’

Related News

Coinbase’s entry into S&P 500 is a watershed moment for crypto industry, analysts say

Coinbase’s entry into S&P 500 is a watershed moment for crypto industry, analysts say

May 13, 2025
Nvidia’s Jensen Huang says AI robotics is a ‘once-in-a-generation’ opportunity for Europe

Nvidia’s Jensen Huang says AI robotics is a ‘once-in-a-generation’ opportunity for Europe

January 21, 2026
Canadian University Dubai backtracks on accepting crypto via Binance Pay

Canadian University Dubai backtracks on accepting crypto via Binance Pay

February 12, 2023

Browse by Category

  • Business Finance
  • Crypto
  • Industries
  • Investing
  • Markets
  • Opinion
  • Real Estate
  • UK

London Wallet

Read latest news about finance, business and investing

  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2025 London Wallet - All Rights Reserved!

No Result
View All Result
  • Checkout
  • Contact
  • Home
  • Login/Register
  • My account
  • Privacy Policy
  • Terms and Conditions

© 2025 London Wallet - All Rights Reserved!

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?