Public companies: No more dragging your feet when it comes cybersecurity.
As of today, large publicly traded enterprises are beholden to new cybersecurity requirements from the Securities and Exchange Commission (SEC).
Notably, they must disclose “material” incidents within four business days. This means they must file a Form 8-K that outlines a meaningful shareholder update.
Additionally, public companies must outline in their Form 10-K their process for assessing, identifying and managing material risks and describe their board of directors’ oversight and expertise.
“You’ve got to tell a really good story about cybersecurity within a company,” Michael Lucas, a digital security principal at Crowe LLP, a public accounting, consulting and technology firm, told SDxCentral. “You must have a cybersecurity program, strategy, governance, a board with oversight of cyber risk.”
Define your ‘materiality’Many experts agree that the “materiality” phrasing is up for interpretation and urge organizations to come up with their own definition with strict, specific requirements that err on the side of caution.
“It’s difficult to determine materiality,” said Lucas. “There’s not really a prescribed formula or equation or set of criteria. The SEC has by and large left it up to companies to determine.”
If they haven’t already, organizations should establish a structured methodology to determine materiality that goes beyond dollar signs, he advised.
“It should not just be financial; a company should also be considering things like reputational harm,” said Lucas.
They should also take regulatory and compliance issues into account — when does an incident violate privacy laws, HIPAA, GDPR or the California Consumer Protection Act (CCPA)? This could result in regulatory fines.
Employee morale is another important factor, as is safety. For instance, could an outage or incident impact a product or even result in loss of life (such as in healthcare, life science or infrastructure scenarios)?
Organizations should create matrices similar to risk assessment graphs that consider the category or probability of an attack against consequence and severity and applies weighting and value, Lucas advised.
Yelena Barychev, partner at law firm Blank Rome LLP agreed that “materiality is going to be on a case-by-case basis,” depending on both the company and the particular attack.
“There is no litmus test,” she said. Organizations must “assess the impact of the incident, not only from a quantitative point of view but also from a qualitative point of view.”
Organizations should report “early and often,” advised Gary Barlet, federal field CTO at network security company Illumio, but always with a caveat that they are still investigating and will continue to report as new exposures are discovered.
“In military conflicts, first reports are almost always wrong and the same goes for cyber conflicts,” he said. “Transparency and consistent communication go a long way in rebuilding trust after a breach.”
Update your incident response processGoing forward, Lucas pointed out, when organizations experience a cyber incident, they will face the challenge of not just responding as quickly as possible, but performing a parallel process to determine materiality and get the wheels moving to report to the SEC disclosure within four days.
They must update their incident process to reflect this new reality, he said and “throw different scenarios at it to evaluate how that plan holds up.”
For instance, perform tabletop exercises to test what-ifs during a ransomware incident, a website or system attack, insider leaks or a breach of a third-party data center.
“Put the process to test, in motion,” said Lucas. “You don’t want to wait to figure this out until you have an incident. Then you’re going to be behind the curve.”
A tip-off for cyberattackers?At the same time, other experts warn that the broadened 8-K requirement could ratchet up cybersecurity activity.
“The 8-K is a public filing, so both right and wrong parties will be aware if a breach occurs,” said Sean Deuby, principal technologist at active directory protection company Semperis.
It effectively creates a “target list” of companies that can (and have been) breached, said Deuby.
“Threat actors will definitely take advantage of this; why would they not?” he posited. “If you were a bad guy, what easier way? It could likely increase multiple attacks.”
Furthermore, new regulation inadvertently provides cybercriminals with a new tool to further advance their psychological warfare tactics.
He pointed to MeridianLink, whose recent attack was ratted to the SEC by perpetrators Alphv/BlackCat.
“To predict what cybercriminals will come up with next, just follow the recipe of maximizing profit while minimizing time and effort, removing all morality, with a dash of ‘avoiding undue government scrutiny,’” said Deuby. “Expect this tactic to become the norm in ransomware attacks. The SEC will have an army of not-so-altruistic helpers.”
Getting your board on boardThe second prong of the new cybersecurity provisions, meanwhile, requires public enterprises to specifically outline their cybersecurity risk management processes, strategy, chain of command and governance, as well as board involvement.
This must be included on their Form 10-K beginning with annual reports for fiscal years ending on or after today.
Barychev of Blank Rome pointed out that, “cybersecurity has always been on the board’s agenda; this is not a new item for them.”
What’s different now is that the SEC wants detailed disclosures about the process that the board goes through in overseeing risk.
“They want to see interconnections about how management is getting info, how that info travels up the chain to the board, how the board evaluates it,” she said.
Still, experts agree that getting board buy-in — and understanding of — cybersecurity can be a challenge for Chief Information Security Officer (CISO).
“Historically boards have not been extremely cybersecurity competent,” said Lucas. “That’s always been a challenge. They hear the word ‘cyber incident’ and just get alarmed, they really don’t understand what it means.”
Typically, getting their buy-in and comprehension means translating incidents into monetary terms. Security leaders should quantify how mature a program is and how well it is performing and problems still facing the company based on performance.
For example, explicitly laying out, ‘we are one incident away from having $100 million of exposure to the business.’
“It’s being much more thoughtful and meaningful and putting it into financial terms,” said Lucas.
Why private companies should take note of SEC rulesStill, while the new SEC rules apply to public companies, private enterprises should be taking note, experts caution.
Barychev pointed out that many private companies are in the supply chain of public companies, and those larger enterprises now beholden to disclosure requirements will soon double down on those relationships and require higher standards and transparency.
“There will be a lot of focus on shifting risk to vendors and making sure they have robust Enterprise risk management,” she said.
Lucas agreed, saying that private companies should study the requirements and implement similar measures, even if they are watered down.
“As a private company, I would sure hope they are seeing the writing on the wall, they should follow suit,” he said. “What we should be taking away is that we must have cybersecurity involvement within management. If there is a board, there should be some cyber knowledge. A bit more tactically, private companies must absolutely have an incident response process.”
Comments