Effective today, public companies are beholden to new cybersecurity disclosure rules that will fundamentally alter the way they manage, remediate and disclose incidents.

Notably, these fresh requirements from the Securities and Exchange Commission (SEC) require enterprises to disclose “material” incidents within four business days.

Not surprisingly, organizations of all sizes have many questions — from whether they have the right protocols and reporting channels in place, to whether they have the basics of cybersecurity down — while they also point to the vagary of the term “material” and express trepidation about the four-day turnaround.

“There is room for judgment and discretion in this [‘material’] interpretation,” said Jordan Rae Kelly, senior managing director and head of cybersecurity for the Americas at FTI Consulting.

Four days is “a small window and organizations are questioning if they have the programs and policies in place to meet this requirement,” she added, noting that complying with the deadline during an ongoing incident can be “very challenging.”

New cybersecurity disclosure rules with broad implications

Per the new SEC rules, public companies must now follow these cybersecurity disclosure guidelines:

  • Disclose cybersecurity incidents within four business days and describe its nature, scope, timing and material or likely material impact.
  • Detail processes for assessing, identifying and managing material risks from cybersecurity threats.
  • Describe the board of directors’ oversight of risks from cybersecurity threats and management’s role and expertise in assessing and managing material risks.

The new rules were adopted July 26 and regulators will begin enforcing them in December.

Still, they have much broader implications beyond public companies, experts caution — and they extend beyond U.S. jurisdiction, as well.

Companies that otherwise are not required to prioritize cybersecurity — due to a lack of existing regulation where they are headquartered, for instance — now must comply with SEC rules, Kelly explained. U.S.-based companies with international operations in less cyber mature markets will also be required to disclose incidents with the potential for a material impact, whether in the U.S. or not.

Furthermore, smaller private companies in the supply chain should be taking note, Kelly and others advised, as they could come under scrutiny even if the new rules do not directly apply to them. Public companies, after all, will be monitoring their supply chains and are now obligated to report any significant findings.

Simply put, “these rules have global reach,” Kelly noted.

What does material mean?

According to the Final Rule, “materiality” refers to any incident where “there is a substantial likelihood that a reasonable shareholder would consider it important” when it comes to making an investment decision.

However, “determining if a breach is material isn’t black and white; the exact intricacies are subject to debate, even among cyber professionals,” said Rafal Los, head of services go-to-market at cloud native application protection (CNAPP) company ExtraHop.

For instance, a crypto-locker incident that grinds business to a complete standstill is easy to identify; on the other hand, tracking down whether nation-state sponsored threat actors that have been in a system for months have done long-lasting damage that is substantive to report can take “an extremely long time,” Los said.

Also, something as seemingly simple as a compromised CEO admin could be material because a threat actor could access their mailbox and unpublished reports. In other cases, an attack may not be considered material until it has caused degradation or disruption over time. It can take breach victims months to understand the entire scope and initial assessment is rarely enough to make a determination, Los noted — it simply provides reference points and a base from which to start an investigation.

“The unfortunate part is that there is no easy rule to follow,” he said.

Key questions, consensus critical

Rulebooks (or lack thereof) aside, there are some key questions enterprises should ask themselves in determining materiality, according to Kelly: Would a reasonable person consider an incident important when making an investment decision? And would it dramatically alter existing publicly available information?

Organizations will also need to consider if critical operations were disrupted or if information was accessed by unauthorized users, she said.

Businesses should identify the type of data involved — first and foremost, its sensitivity, emphasized Chiara Portner, attorney with Silicon Valley law firm Hopkins and Carley. Additionally, organizations will need to identify the type and scope of the incident and potential business impact, reputational damage, costs and insurance coverage.

To bring transparency and validity to the process, public entities should establish policies on how materiality is determined, said Aaron Tantleff, partner at international law firm Foley and Lardner. This policy should describe the types of information and inquiries to be included in such determination, he said.

He added that “the process for determining materiality includes senior leadership, the CIO/CISO and legal.”

Ultimately, according to Los, it comes down to having cybersecurity talent that understands the businesses and implementing “small, flexible, rapid response teams” that can quickly assess an incident from a technical and business perspective and come to a consensus.

“Consensus is critical,” said Los, adding that if all relevant areas don’t agree, the business will have to err on the side of caution and declare a breach material.

Is four days enough time?

Regarding the four-day reporting window, meanwhile, it’s worth noting that the obligation does not start at the time or discovery, but once a materiality determination has been made, Tantleff said.

At the same time, that reporting is independent of any state data breach notification law — so even if a particular statute provides for delays in notification, those do not apply to SEC rules, Tantleff said. Therefore, companies must note the impact and obligation of all laws requiring notification.

In all cases, enterprises should be able to provide a timeline to show that a decision was made in a timely manner, he said. They should take care when documenting the dates of information received and evaluated; when the information was initially provided and updated; and when a determination was made as to materiality.

Existing incident response plans should be updated to address who is responsible for disclosures and whether an incident becomes material itself or along with other incidents, Tantleff said.

Enterprises should also review communication methods and channels to ensure timely notification to leadership, their board and others, he advised. Another consideration is to benchmark a cybersecurity program against that of a peer company, as an investor may very well do just that to determine whether their cybersecurity program is sufficient. An additional good practice is to review (and perhaps revise) contracts with third parties to ensure they are quickly and effectively reporting cyber incidents.

But ultimately, Tantleff  said, there’s a delicate balance to be struck, as organizations don’t want to over-report and create additional, undue risk (as has been a common criticism of the new rules).

Implementing new rules while prioritizing incident response

But before implementing any new standards, an organization must have a thorough understanding of its cybersecurity platform (or platforms) and stance, Kelly said. For instance, are security policies up-to-date? How are they managed, implemented and enforced?

Organizations should select and implement controls based on the results of a risk assessment, she said. And, even after those controls are in place, “residual risk” remains and requires an early detection system.

Security teams should also perform tabletop exercises to practice and perfect response procedures and have the ability to communicate relevant details within required timeframes, she said.

Simply put, “prioritize incident response,” Kelly said. “Being ready for cyber threats is fundamental to the success of an incident response program.”