Security News

Cybersecurity news aggregator

INFO News SC Media

SEC cybersecurity disclosure rules: What security leaders must know

  • What: New SEC cybersecurity disclosure rules for companies
  • Impact: Organizations must improve transparency in cybersecurity reporting
Read Full Article →

Governance, Risk and Compliance , Government Regulations SEC cybersecurity disclosure rules: What security leaders must know April 22, 2026 Share By Christen Wojciechowski (Adobe Stock) COMMENTARY: Organizations may have been tackling cyberthreats for decades, but cyberattacks continue to grow in complexity and sophistication. Companies that rely on outdated methods of threat detection and risk management may increase exposure and weaken protection for themselves and their investors. To increase transparency and promote development of businesses’ cybersecurity strategies, the Securities and Exchange Commission issued new rules for reporting of cybersecurity risk management and incident reporting. With an understanding of the SEC’s reporting requirements, cybersecurity and compliance specialists can better ensure their companies’ compliance. [ SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here . ] Incidental disclosures The SEC rules specify instances in which public companies must report cybersecurity concerns in incidental and periodic disclosures. Incidental disclosures are reports that businesses must make to shareholders in the event that something significant happens that is of interest to shareholders, such as Form 8-K. Companies must use the appropriate incidental disclosure to report material cybersecurity incidents. Businesses must generally complete and submit the report to the SEC within four business days of the organization deciding that the cybersecurity incident is material, with limited exceptions. Determining materiality of cybersecurity incidents The materiality of the cybersecurity incident is the major trigger of the incidental reporting. Generally, the SEC defines materiality as any incident that shareholders would consider important to make an investment decision. Related reading: What the dismissal of SolarWinds really means for CISOs The SolarWinds dismissal: a reprieve, not a pardon 2020 SolarWinds case dismissed by SEC; industry offers mixed reaction Periodic disclosures Public companies are required to disclose details about their cybersecurity risk management strategies, as well as management’s role and oversight from the board of directors for those strategies. These disclosures must be made on the business’s annual report, such as Form 10-K. Risk assessment On annual SEC reporting, companies must provide discussion of their risk assessments and risk management strategies. The SEC recommends consideration of operational risks, intellectual property theft, fraud, extortion, harm to employees or customers, violation of privacy laws, and reputational risk. Management’s role in risk management Disclosures should describe which positions or teams are tasked with assessment and management of cybersecurity risk, whether a chief information security officer exists, and the processes for monitoring, detecting, mitigating, and remediating cybersecurity incidents. Structured data requirements Cybersecurity disclosures are required to be filed using EDGAR and tagged with Inline XBRL. This structured data requirement makes cybersecurity disclosures more accessible and comparable for investors and regulators. For public companies, SEC compliance involves increased investment in cybersecurity risk assessment and governance disclosures. Staying current on SEC requirements helps organizations maintain compliance in an evolving risk landscape. Christen Wojciechowski Christen Wojciechowski is Digital Marketing Manager for Donnelley Financial Solutions™ (DFIN), a global financial solutions company headquartered in Chicago. She focuses on the company’s marketing operations through brand awareness, lead generation, and engagement across channels. Her work covers both overall strategy and hands-on execution within the tools. Related Government Regulations House OKs short-term renewal for surveillance program SC Staff April 21, 2026 Legislation that would provide a 10-day extension for Section 702 of the Foreign Intelligence Surveillance Act has been approved by the House, representing a setback for President Donald Trump and House GOP leaders, who had sought an 18-month renewal, according to The Record, a news site by cybersecurity firm Recorded Future. AI/ML Why predictive resilience based on Agentic AI must anchor the National Cyber Strategy Jonathan Trull April 21, 2026 Here’s how a risk operations center model promises to help teams stay one step ahead of the attackers. Government Regulations Executive order spurs push for stronger identity proofing SC Staff April 20, 2026 Industry leaders are seizing upon the Trump administration's Executive Order 14390 to argue that the federal government's aggressive posture toward cyber-enabled fraud prosecutions must be matched by an equally robust investment in digital identity infrastructure, which they contend remains the primary, underutilized lever for disrupting the economics of large-scale impersonation, reports Biometric Update. Related Events Cybercast Mainframe Security in a Changing Regulatory Landscape: Aligning with NYDFS, DORA, and Beyond On-Demand Event Cybercast From checklists to intelligence: Integrating AI into your GRC strategy On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Business Impact Analysis (BIA) British Standard 7799 Chain of Custody Competitive Intelligence Data Custodian Due Care Due Diligence You can skip this ad in 5 seconds

Share this article