{"id":6219,"date":"2023-12-04T09:15:39","date_gmt":"2023-12-04T15:15:39","guid":{"rendered":"https:\/\/www.bbrown.com\/?post_type=insight&#038;p=6219"},"modified":"2023-12-07T15:10:39","modified_gmt":"2023-12-07T21:10:39","slug":"sec-cybersecurity-rule-a-closer-look","status":"publish","type":"insight","link":"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/","title":{"rendered":"SEC Cybersecurity Rule: A Closer Look"},"content":{"rendered":"<div class=\"wpb-content-wrapper\"><p>[vc_row row_style=&#8221;page-hero&#8221; full_width=&#8221;stretch_row_content&#8221;][vc_column]\n\t<div class=\"hero hero--wrap    \">\n\n\t\t<div class=\"hero--background-image hero--background-image-blur\">\n\t\t\t<div class=\"hero--overlay\"><\/div>\n\t\t\t\t\t\t\t<div class=\"hero-background\" style=\"background: url(https:\/\/www.bbrown.com\/wp-content\/uploads\/2023\/12\/SEC-CYBERSECURITY-RULE-A-CLOSER-LOOK-Brown-Brown-External_web-image.png) center center no-repeat; background-size: cover;\"><\/div>\n\t\t\t\t\t<\/div>\n\n\t\t<div class=\"hero--container\">\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"hero--inner width-100\">\n\n\t\t\t\t\t\n  <div class='content-heading  100%  '>\n    <p class='text-white subheading'>Property &amp; Casualty<\/p>\n    <h1 class='text-white    '>\n      SEC Cybersecurity Rule: A Closer Look\n    <\/h1>\n\t\n  <\/div>\t\t\t\t\t\n\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\n\t<\/div>\n\n\t\n[\/vc_column][\/vc_row][vc_row][vc_column width=&#8221;2\/3&#8243;]\n  <div class='content-heading  100% content-heading--ruled '>\n    \n    <h1 class='text-brand-dark-blue    h2'>\n      SEC Cybersecurity Rule: A Closer Look\n    <\/h1>\n\t\n  <\/div>[vc_column_text]New SEC rules released on July 26, 2023, require publicly listed companies to disclose material cybersecurity incidents they experience, and the material information regarding their cybersecurity risk management, strategy and governance annually. The new disclosure requirements take effect starting on or after December 15, 2023. The SEC\u2019s objective is to standardize cybersecurity risk reporting to enable investor confidence and enhance executive\/board level oversight of the cyber risk management function.<\/p>\n<h3>Cybersecurity Incident Disclosures<\/h3>\n<p>Material cybersecurity incidents should be disclosed within a period of four business days from the date materiality\u00a0 was determined.<\/p>\n<h3>Cybersecurity Risk Management, Strategy &amp; Governance Disclosures<\/h3>\n<p>These periodic disclosures outline methodologies for evaluation, identifying and mitigating cybersecurity risks.<\/p>\n<h3>Included in Disclosure(s)<\/h3>\n<ul>\n<li>Description of incident\u2019s material financial, operational or other impact<\/li>\n<li>Description of incident\u2019s nature, scope and timing<\/li>\n<li>Description of any missing requirements in the event that information is not yet available for disclosure<\/li>\n<li>Description of processes for evaluating, recognizing and mitigating significant risks<\/li>\n<li>Description of how these processes have been integrated into a risk management framework<\/li>\n<li>Details of realized risks arising from prior material cybersecurity incidents, including impacts<\/li>\n<li>Description of processes for the cybersecurity program\u2019s engagement with third-party consultants and auditors<\/li>\n<li>Description of processes for management\/board<\/li>\n<\/ul>\n<h3>Key Challenges<\/h3>\n<ul>\n<li>Understanding the definitions of cybersecurity incident and materiality<\/li>\n<li>Timely filing of SEC 8-K Cyber Incident Disclosures<\/li>\n<\/ul>\n<h3>Actions to Prepare and Comply<\/h3>\n<ul>\n<li>Establish cyber risk quantification capability to support materiality assessments<\/li>\n<li>Conduct sample materiality assessments for mock incidents (i.e., tabletop exercise)<\/li>\n<li>Review disclosure controls and procedures<\/li>\n<li>Conduct an internal SEC readiness assessment<\/li>\n<\/ul>\n<h3>Overview<\/h3>\n<p>New SEC rules released on July 26, 2023, require publicly listed companies to disclose material cybersecurity incidents they experience, and provide material information regarding their cybersecurity risk management, strategy and governance annually.<\/p>\n<p>All publicly listed companies are required to disclose details regarding a significant cybersecurity incident through the submission of Form 8-K within four business days from the moment they ascertain its materiality. This disclosure timeline may be extended up to 30-60 days, but only in cases where the U.S. attorney general determines that such disclosure could pose a significant threat to national security or public safety.<\/p>\n<p>Entities must outline their methodologies for evaluating, identifying and mitigating cybersecurity risks, including insights into the board\u2019s supervision and the involvement of management. The new disclosure requirements take effect starting on or after December 15, 2023. Smaller Reporting Companies (SRCs) must comply by June 15, 2024. The SEC\u2019s objective is to standardize cybersecurity risk reporting to enable investor confidence and enhance executive\/board level oversight of the cyber risk management function.[\/vc_column_text]\t<div class='wpb_content_element text-left btn-container'>\n\t\t\t\t\t<a class='btn btn-brand-green  '\n\t\t\t\thref='https:\/\/www.bbrown.com\/wp-content\/uploads\/2023\/12\/SEC-CYBERSECURITY-RULE-A-CLOSER-LOOK-Brown-Brown-External_web.pdf' target='_blank' data-toggle=''>\n\t\t\t\t<span class=\"btn-text-color--default\">Continue Reading<\/span>\n\t\t\t<\/a>\n\t\t\t<\/div>\n[\/vc_column][vc_column width=&#8221;1\/3&#8243;][vc_single_image image=&#8221;6248&#8243; alignment=&#8221;center&#8221; style=&#8221;vc_box_circle_2&#8243;][vc_separator border_width=&#8221;2&#8243; el_width=&#8221;60&#8243;][vc_column_text]<\/p>\n<h6 style=\"text-align: center;\">Sal Ansari<\/h6>\n<p style=\"text-align: center;\">Managing Director, Cyber Risk Advisory<\/p>\n<p>[\/vc_column_text][vc_single_image image=&#8221;6245&#8243; alignment=&#8221;center&#8221; style=&#8221;vc_box_circle_2&#8243;][vc_separator border_width=&#8221;2&#8243; el_width=&#8221;60&#8243;][vc_column_text]<\/p>\n<h6 style=\"text-align: center;\">Coles Cotter<\/h6>\n<p style=\"text-align: center;\">Legal Intern<\/p>\n<p>[\/vc_column_text]\t<div class='wpb_content_element text-center btn-container'>\n\t\t\t\t\t<a class='btn btn-brand-dark-blue  '\n\t\t\t\thref='\/us\/contact\/contact-general\/' target='' data-toggle=''>\n\t\t\t\t<span class=\"btn-text-color--default\">Connect Now<\/span>\n\t\t\t<\/a>\n\t\t\t<\/div>\n[\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>[vc_row row_style=&#8221;page-hero&#8221; full_width=&#8221;stretch_row_content&#8221;][vc_column][\/vc_column][\/vc_row][vc_row][vc_column width=&#8221;2\/3&#8243;][vc_column_text]New SEC rules released on July 26, 2023, require publicly listed companies to disclose material cybersecurity incidents they experience, and the material information regarding their cybersecurity risk [&hellip;]<\/p>\n","protected":false},"author":66,"featured_media":6220,"template":"","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"insight_category":[34],"class_list":["post-6219","insight","type-insight","status-publish","has-post-thumbnail","hentry","insight_category-property-casualty"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SEC Cybersecurity Rule: A Closer Look - Brown &amp; Brown<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SEC Cybersecurity Rule: A Closer Look\" \/>\n<meta property=\"og:description\" content=\"[vc_row row_style=&#8221;page-hero&#8221; full_width=&#8221;stretch_row_content&#8221;][vc_column][\/vc_column][\/vc_row][vc_row][vc_column width=&#8221;2\/3&#8243;][vc_column_text]New SEC rules released on July 26, 2023, require publicly listed companies to disclose material cybersecurity incidents they experience, and the material information regarding their cybersecurity risk [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/\" \/>\n<meta property=\"og:site_name\" content=\"Brown &amp; Brown\" \/>\n<meta property=\"article:modified_time\" content=\"2023-12-07T21:10:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.bbrown.com\/wp-content\/uploads\/2023\/12\/SEC-CYBERSECURITY-RULE-A-CLOSER-LOOK-Brown-Brown-External_web-image.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"563\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/\",\"url\":\"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/\",\"name\":\"SEC Cybersecurity Rule: A Closer Look - Brown &amp; Brown\",\"isPartOf\":{\"@id\":\"https:\/\/www.bbrown.com\/us\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.bbrown.com\/wp-content\/uploads\/2023\/12\/SEC-CYBERSECURITY-RULE-A-CLOSER-LOOK-Brown-Brown-External_web-image.png\",\"datePublished\":\"2023-12-04T15:15:39+00:00\",\"dateModified\":\"2023-12-07T21:10:39+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/#breadcrumb\"},\"inLanguage\":\"us\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"us\",\"@id\":\"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/#primaryimage\",\"url\":\"https:\/\/www.bbrown.com\/wp-content\/uploads\/2023\/12\/SEC-CYBERSECURITY-RULE-A-CLOSER-LOOK-Brown-Brown-External_web-image.png\",\"contentUrl\":\"https:\/\/www.bbrown.com\/wp-content\/uploads\/2023\/12\/SEC-CYBERSECURITY-RULE-A-CLOSER-LOOK-Brown-Brown-External_web-image.png\",\"width\":1000,\"height\":563},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.bbrown.com\/us\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Insights\",\"item\":\"https:\/\/www.bbrown.com\/us\/news-events\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"SEC Cybersecurity Rule: A Closer Look\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.bbrown.com\/us\/#website\",\"url\":\"https:\/\/www.bbrown.com\/us\/\",\"name\":\"Brown &amp; Brown\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.bbrown.com\/us\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.bbrown.com\/us\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"us\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.bbrown.com\/us\/#organization\",\"name\":\"Brown &amp; Brown\",\"url\":\"https:\/\/www.bbrown.com\/us\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"us\",\"@id\":\"https:\/\/www.bbrown.com\/us\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.bbrown.com\/wp-content\/uploads\/2021\/12\/cropped-BBRetail002-RGBrevs.png\",\"contentUrl\":\"https:\/\/www.bbrown.com\/wp-content\/uploads\/2021\/12\/cropped-BBRetail002-RGBrevs.png\",\"width\":1000,\"height\":136,\"caption\":\"Brown &amp; Brown\"},\"image\":{\"@id\":\"https:\/\/www.bbrown.com\/us\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SEC Cybersecurity Rule: A Closer Look - Brown &amp; Brown","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/","og_locale":"en_US","og_type":"article","og_title":"SEC Cybersecurity Rule: A Closer Look","og_description":"[vc_row row_style=&#8221;page-hero&#8221; full_width=&#8221;stretch_row_content&#8221;][vc_column][\/vc_column][\/vc_row][vc_row][vc_column width=&#8221;2\/3&#8243;][vc_column_text]New SEC rules released on July 26, 2023, require publicly listed companies to disclose material cybersecurity incidents they experience, and the material information regarding their cybersecurity risk [&hellip;]","og_url":"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/","og_site_name":"Brown &amp; Brown","article_modified_time":"2023-12-07T21:10:39+00:00","og_image":[{"width":1000,"height":563,"url":"https:\/\/www.bbrown.com\/wp-content\/uploads\/2023\/12\/SEC-CYBERSECURITY-RULE-A-CLOSER-LOOK-Brown-Brown-External_web-image.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/","url":"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/","name":"SEC Cybersecurity Rule: A Closer Look - Brown &amp; Brown","isPartOf":{"@id":"https:\/\/www.bbrown.com\/us\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/#primaryimage"},"image":{"@id":"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/#primaryimage"},"thumbnailUrl":"https:\/\/www.bbrown.com\/wp-content\/uploads\/2023\/12\/SEC-CYBERSECURITY-RULE-A-CLOSER-LOOK-Brown-Brown-External_web-image.png","datePublished":"2023-12-04T15:15:39+00:00","dateModified":"2023-12-07T21:10:39+00:00","breadcrumb":{"@id":"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/#breadcrumb"},"inLanguage":"us","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/"]}]},{"@type":"ImageObject","inLanguage":"us","@id":"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/#primaryimage","url":"https:\/\/www.bbrown.com\/wp-content\/uploads\/2023\/12\/SEC-CYBERSECURITY-RULE-A-CLOSER-LOOK-Brown-Brown-External_web-image.png","contentUrl":"https:\/\/www.bbrown.com\/wp-content\/uploads\/2023\/12\/SEC-CYBERSECURITY-RULE-A-CLOSER-LOOK-Brown-Brown-External_web-image.png","width":1000,"height":563},{"@type":"BreadcrumbList","@id":"https:\/\/www.bbrown.com\/us\/insight\/sec-cybersecurity-rule-a-closer-look\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.bbrown.com\/us\/"},{"@type":"ListItem","position":2,"name":"Insights","item":"https:\/\/www.bbrown.com\/us\/news-events\/"},{"@type":"ListItem","position":3,"name":"SEC Cybersecurity Rule: A Closer Look"}]},{"@type":"WebSite","@id":"https:\/\/www.bbrown.com\/us\/#website","url":"https:\/\/www.bbrown.com\/us\/","name":"Brown &amp; Brown","description":"","publisher":{"@id":"https:\/\/www.bbrown.com\/us\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.bbrown.com\/us\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"us"},{"@type":"Organization","@id":"https:\/\/www.bbrown.com\/us\/#organization","name":"Brown &amp; Brown","url":"https:\/\/www.bbrown.com\/us\/","logo":{"@type":"ImageObject","inLanguage":"us","@id":"https:\/\/www.bbrown.com\/us\/#\/schema\/logo\/image\/","url":"https:\/\/www.bbrown.com\/wp-content\/uploads\/2021\/12\/cropped-BBRetail002-RGBrevs.png","contentUrl":"https:\/\/www.bbrown.com\/wp-content\/uploads\/2021\/12\/cropped-BBRetail002-RGBrevs.png","width":1000,"height":136,"caption":"Brown &amp; Brown"},"image":{"@id":"https:\/\/www.bbrown.com\/us\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.bbrown.com\/us\/wp-json\/wp\/v2\/insight\/6219","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bbrown.com\/us\/wp-json\/wp\/v2\/insight"}],"about":[{"href":"https:\/\/www.bbrown.com\/us\/wp-json\/wp\/v2\/types\/insight"}],"author":[{"embeddable":true,"href":"https:\/\/www.bbrown.com\/us\/wp-json\/wp\/v2\/users\/66"}],"version-history":[{"count":0,"href":"https:\/\/www.bbrown.com\/us\/wp-json\/wp\/v2\/insight\/6219\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bbrown.com\/us\/wp-json\/wp\/v2\/media\/6220"}],"wp:attachment":[{"href":"https:\/\/www.bbrown.com\/us\/wp-json\/wp\/v2\/media?parent=6219"}],"wp:term":[{"taxonomy":"insight_category","embeddable":true,"href":"https:\/\/www.bbrown.com\/us\/wp-json\/wp\/v2\/insight_category?post=6219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}