Current:Home > MarketsCyber breaches cost investors money. How SEC's new rules for companies could benefit all. -DataFinance
Cyber breaches cost investors money. How SEC's new rules for companies could benefit all.
View
Date:2025-04-24 00:07:06
The U.S. Securities and Exchange Commission announced new rules yesterday requiring public companies to disclose cybersecurity incidents as soon as four business days.
SEC Chair Gary Gensler said the disclosure "may be material to investors" and could benefit them, the companies and markets connecting them.
“Currently, many public companies provide cybersecurity disclosure to investors. I think companies and investors alike, however, would benefit if this disclosure were made in a more consistent, comparable, and decision-useful way," he said.
The new rules were proposed in March 2022 after the SEC noted the increase in cybersecurity risks following the way companies pivoted toward remote work, moving more operations online, use of digital payments, increased reliance on third-party service providers for services like cloud computing technology, and how cyber criminals are able to monetize cybersecurity incidents.
What is the SEC cyber disclosure rule?
Under the new rules, companies are required to fill out the brand new 8-K form, which will have Item 1.05 added to disclose cybersecurity incidents. It will require disclosing and describing the nature, scope, and timing of the incident, material impact or reasonably likely material impact, including the financial condition and results of operations.
If the incident will have a significant effect, then the company has to report it in four days. But if the U.S. Attorney General deems the immediate disclosure a risk to national security or public safety, disclosure could be delayed.
The new regulation requires companies to describe their process assessing cybersecurity threats, how their board of directors oversee cybersecurity threats, and how management assesses the threat.
Foreign companies will use the amended 6-K form to disclose cybersecurity incidents and the amended 20-F form for periodic disclosure.
How much does a data breach cost a business?
In this year's "Cost of a Data Breach Report" by IBM Security, the average cost of a data breach in 2023 was $4.45 million, a 2.3% increase from 2022 when it was $4.35 million. The United States has lead the way for 13 consecutive years in highest data breach costs. This year, the Middle East, Canada, Germany and Japan also made up the top five countries with the most expensive data breaches.
During ransomware attacks, companies that excluded law enforcement paid 9.6% more and experienced a longer breach at 33 days.
Only one-third of the companies found data breaches themselves, while the rest were reported by the attackers themselves or by a third party. Among industries, health care had the highest data breach costs in the U.S. this year, followed by the financial, pharmaceutical, energy, and industrial sectors in order.
veryGood! (5662)
Related
- Federal court filings allege official committed perjury in lawsuit tied to Louisiana grain terminal
- Turkey’s President Erdogan and Elon Musk discuss establishing a Tesla car factory in Turkey
- Hearings in $1 billion lawsuit filed by auto tycoon Carlos Ghosn against Nissan starts in Beirut
- In a state used to hurricanes and flooding, Louisiana is battling an unprecedented wildfire season
- The White House is cracking down on overdraft fees
- 'Back to the Future,' 'Goonies' and classic Disney VHS tapes are being sold for thousands on eBay
- UK Labour leader Keir Starmer says he’ll seek closer ties with the EU if he wins the next election
- Republican legislatures flex muscles to maintain power in two closely divided states
- Jamie Foxx gets stitches after a glass is thrown at him during dinner in Beverly Hills
- The Red Cross: Badly needed food, medicine shipped to Azerbaijan’s breakaway Nagorno-Karabakh region
Ranking
- Who are the most valuable sports franchises? Forbes releases new list of top 50 teams
- Tacoma police investigate death of Washington teen doused in accelerant and set on fire
- Mike Babcock resigns as Columbus Blue Jackets coach after NHLPA investigation
- German ambassador’s attendance at Israeli court hearing ignites diplomatic spat
- Taylor Swift makes surprise visit to Kansas City children’s hospital
- In a state used to hurricanes and flooding, Louisiana is battling an unprecedented wildfire season
- Fantasy football sizzlers, fizzlers: Return of Raheem Must-start
- Trial in Cyprus for 5 Israelis accused of gang raping a British woman is to start Oct. 5
Recommendation
Meet the volunteers risking their lives to deliver Christmas gifts to children in Haiti
5 people shot, including 2 juveniles, in Boston's Dorchester neighborhood
Trial of 3 Washington officers over 2020 death of Black man who said 'I can't breathe' starts
A Florida man bought a lottery ticket with his Publix sub. He won $5 million.
This was the average Social Security benefit in 2004, and here's what it is now
702 Singer Irish Grinstead Dead at 43
Missing Maine man found alive after being trapped in his truck in a mud pit for two days
All 9 juveniles recaptured after escape from Pennsylvania detention center, police say