With the July 26, 2023 U.S. Securities and Exchange Commission (SEC) adoption of new rules to enhance disclosure of cybersecurity risk management, we took a look at current reporting practices to see where things stand and to help provide guidance on where companies need to go once the new rule becomes effective.

The new rules, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure have five areas of disclosure focus:

  • Incident Disclosure
  • Timeliness of Incident Disclosure
  • Board Oversight
  • Board Expertise
  • Management Policies & Procedures.

This report looks at disclosure practices for the first four of these areas.

Access the Full Report

Some articles require a paid subscription.