SEC Cybersecurity Incident Disclosure Requirements Begin
As we previously discussed in greater detail, earlier this year the U.S. Securities and Exchange Commission adopted cybersecurity disclosure rules that require a U.S. public company to disclose (1) on Form 8-K (Item 1.05) the occurrence of a material cybersecurity incident within four business days after determining that such incident is material and (2) in the Annual Report on Form 10-K (Item 1C), the company’s risk management, strategy and governance of cybersecurity. Foreign private issuers (FPIs) are subject to similar requirements.
Contributor(s)
Co-Head of Public Company Advisory Group
More from the Governance & Securities Watch
Copyright © 2024 Weil, Gotshal & Manges LLP, All Rights Reserved. The contents of this website may contain attorney advertising under the laws of various states. Prior results do not guarantee a similar outcome. Weil, Gotshal & Manges LLP is headquartered in New York and has office locations in Boston, Brussels, Dallas, Frankfurt, Hong Kong, Houston, London, Los Angeles, Miami, Munich, New York, Paris, San Francisco, Silicon Valley and Washington, D.C.