Current:Home > NewsCyber breaches cost investors money. How SEC's new rules for companies could benefit all. -Legacy Profit Partners
Cyber breaches cost investors money. How SEC's new rules for companies could benefit all.
View
Date:2025-04-16 01:31:30
The U.S. Securities and Exchange Commission announced new rules yesterday requiring public companies to disclose cybersecurity incidents as soon as four business days.
SEC Chair Gary Gensler said the disclosure "may be material to investors" and could benefit them, the companies and markets connecting them.
“Currently, many public companies provide cybersecurity disclosure to investors. I think companies and investors alike, however, would benefit if this disclosure were made in a more consistent, comparable, and decision-useful way," he said.
The new rules were proposed in March 2022 after the SEC noted the increase in cybersecurity risks following the way companies pivoted toward remote work, moving more operations online, use of digital payments, increased reliance on third-party service providers for services like cloud computing technology, and how cyber criminals are able to monetize cybersecurity incidents.
What is the SEC cyber disclosure rule?
Under the new rules, companies are required to fill out the brand new 8-K form, which will have Item 1.05 added to disclose cybersecurity incidents. It will require disclosing and describing the nature, scope, and timing of the incident, material impact or reasonably likely material impact, including the financial condition and results of operations.
If the incident will have a significant effect, then the company has to report it in four days. But if the U.S. Attorney General deems the immediate disclosure a risk to national security or public safety, disclosure could be delayed.
The new regulation requires companies to describe their process assessing cybersecurity threats, how their board of directors oversee cybersecurity threats, and how management assesses the threat.
Foreign companies will use the amended 6-K form to disclose cybersecurity incidents and the amended 20-F form for periodic disclosure.
How much does a data breach cost a business?
In this year's "Cost of a Data Breach Report" by IBM Security, the average cost of a data breach in 2023 was $4.45 million, a 2.3% increase from 2022 when it was $4.35 million. The United States has lead the way for 13 consecutive years in highest data breach costs. This year, the Middle East, Canada, Germany and Japan also made up the top five countries with the most expensive data breaches.
During ransomware attacks, companies that excluded law enforcement paid 9.6% more and experienced a longer breach at 33 days.
Only one-third of the companies found data breaches themselves, while the rest were reported by the attackers themselves or by a third party. Among industries, health care had the highest data breach costs in the U.S. this year, followed by the financial, pharmaceutical, energy, and industrial sectors in order.
veryGood! (89312)
Related
- Apple iOS 18.2: What to know about top features, including Genmoji, AI updates
- Lululemon, Disney partner for 34-piece collection and campaign: 'A dream collaboration'
- Kraft Heinz stops serving school-designed Lunchables because of low demand
- Why Game of Thrones' Maisie Williams May Be Rejoining the George R.R. Martin Universe
- The Best Stocking Stuffers Under $25
- November 2024 full moon this week is a super moon and the beaver moon
- Kentucky gets early signature win at Champions Classic against Duke | Opinion
- Man found dead in tanning bed at Indianapolis Planet Fitness; family wants stricter policies
- Google unveils a quantum chip. Could it help unlock the universe's deepest secrets?
- Kansas basketball vs Michigan State live score updates, highlights, how to watch Champions Classic
Ranking
- Off the Grid: Sally breaks down USA TODAY's daily crossword puzzle, Triathlon
- Spirit Airlines cancels release of Q3 financial results as debt restructuring talks heat up
- Why Outer Banks Fans Think Costars Rudy Pankow and Madison Bailey Used Stunt Doubles Amid Rumored Rift
- Bev Priestman fired as Canada women’s soccer coach after review of Olympic drone scandal
- Paula Abdul settles lawsuit with former 'So You Think You Can Dance' co
- Song Jae-lim, Moon Embracing the Sun Actor, Dead at 39
- Groups seek a new hearing on a Mississippi mail-in ballot lawsuit
- Why Outer Banks Fans Think Costars Rudy Pankow and Madison Bailey Used Stunt Doubles Amid Rumored Rift
Recommendation
House passes bill to add 66 new federal judgeships, but prospects murky after Biden veto threat
Missing Ole Miss student declared legally dead as trial for man accused in his death looms
Minnesota man is free after 16 years in prison for murder that prosecutors say he didn’t commit
What happens to Donald Trump’s criminal conviction? Here are a few ways it could go
The Daily Money: Spending more on holiday travel?
'I heard it and felt it': Chemical facility explosion leaves 11 hospitalized in Louisville
Oprah Winfrey Addresses Claim She Was Paid $1 Million by Kamala Harris' Campaign
Watch as dust storm that caused 20-car pileup whips through central California