With the enforcement of the new Securities and Exchange Commission (SEC) rules on cyber risk management and incident reporting looming, a recent Deloitte poll showed more than half of surveyed public companies have been strengthening their cybersecurity measures and planning to comply with the requirements, while many of them still have concerns and queries about the rules.
The new SEC rules demand that public companies disclose “material” cybersecurity incidents within four business days, and elaborate on their processes for assessing, identifying, and managing material risks from cybersecurity threats and their boards’ roles in the oversight, among other requirements.
[ Don't miss Deloitte on Tech each month on SDxCentral]“A lot of our clients have come to us to provide ... support in terms of the new rules that were just published,” Naj Adib, advisory principal of cyber and strategic risk services at Deloitte, told SDxCentral.
Adib revealed the most frequently asked questions their clients have had regarding the new SEC rules:
- Materiality definition: The most relevant question from Deloitte clients was often seeking clarification on the definition of "materiality" due to its vagueness and wanting to know how to determine if an incident is considered "material." Adib noted organizations find it challenging to decide when and how to disclose related cyber incidents as incidents and information evolve over time, implying a need for resources and automation to connect related occurrences.
- Third-party management: Deloitte clients also asked about the management of third-party service providers, specifically on the concept of describing the process to oversee and identify material risks associated with third-party service providers in the rules.
- Information disclosure level: Many questions arise regarding the amount of information to disclose in the 8-K and 10-K forms, specifically focusing on the level of detail necessary related to risk management strategy, governance and other related areas.
- Board involvement: Deloitte clients were concerned about the involvement of the board in overseeing and managing cyber risks, including questions such as at what level should the board be involved, how can we get them engaged and how do we make sure that we have a sufficient environment for the right oversight?
In light of these concerns and queries, Deloitte conducted a debrief to provide information about the new rules, while polling more than 1,300 C-suite and other executives from publicly traded organizations who attended the webcast about their thoughts on the rules.
Public companies continue to invest in cybersecurityDeloitte‘s survey showed 64.8% of the polled executives say their organizations will bolster their cybersecurity programs in response to the new rules, while 54.1% are pressing their third parties to do the same.
Adib noted companies continue to invest in cybersecurity regardless of the SEC rules. “The trends that we're seeing and what we know from our client discussion is that cyber is table stakes, right? And most organizations, regardless of the final rules, are investing to strengthen their cyber programs.”
Additionally, while 53% of the respondents say their organizations have been planning for the newly issued SEC cyber rules, 26.1% have not but will be compliant by the mandated deadlines.
For the companies that haven’t started to prepare, Adib suggested conducting an SEC readiness assessment to make sure they have the foundational capabilities and comprehend where companies stand in relation to the requirements, evaluating their incident response capabilities, setting up the coordination and orchestration process and combining legal guidance and cybersecurity expertise to ensure timely and appropriate material incident disclosures.
Deloitte’s recommendations on third-party risk managementThe Deloitte poll results also showed that only 33.9% of executives’ organizations have evaluated communications with third-party service providers.
Adib called the third-party providers “extended enterprise," in which vendors, partners and clients (or customers) are also part of the ecosystem.
To comply with the new SEC rules, he recommended organizations start to look at their ecosystems and conduct comprehensive assessments of third parties to understand their security measures, data control and incident processes.
This involves evaluating third-party service providers' capabilities continually throughout the lifecycle of the relationship, from initial assessment, vendor selection and onboarding, to continuous monitoring and management
Adib also suggested during contracting, putting in the terms and conditions that would require a third party to disclose if they have had a cyber incident, and for existing third parties to assess if “they adhere to the security controls that are required for them to engage with you as an organization.”
Future implications of the new SEC cyber rulesDespite mixed reactions to the rules, Adib noted that the regulations will help organizations strengthen their cybersecurity posture.
“The rules themselves put down some pretty fundamental capabilities that will require you, regardless, to strengthen your cybersecurity posture … and your disclosure controls and procedures,” he said.
Additionally, the rules are expected to lead to more publicly available information, fostering informed decision-making. “But other than that, honestly, it's like any regulations, it's yet to be seen. I mean, maybe the SEC will provide further guidance, depending on the data they have,” he added.
Comments