Subscribe

Ukraine Crisis Resource Center

SEC Proposes New Cybersecurity Risk and Incident Disclosure Obligations

March 15, 2022

On March 9, 2022, the Securities and Exchange Commission (SEC) issued proposed rules and amendments to enhance and standardize disclosures regarding cybersecurity risk management, strategy, governance, and incident reporting by public companies (registrants) that are subject to the reporting requirements of the Securities Exchange Act of 1934.

The stated intent of the proposed amendments is to better inform investors regarding registrant’s risk management, strategy, and governance and to provide timely notification of material cybersecurity incidents. SEC’s position is that “consistent, comparable, and decision-useful disclosures” would allow investors to assess exposure to cybersecurity risks and incidents, including a registrant’s ability to manage and mitigate those risks and incidents.

As further summarized below, the requirements added by the SEC’s proposal include obligations to disclose information related to a material cybersecurity incident within four business days, as well as heightened requirements for disclosing information relating to cyber-related risk management, strategy, and governance.  Importantly, the reporting obligations contained in the SEC’s proposal underscore corporate executive leadership’s role in and responsibility for overseeing the cybersecurity of their respective companies.

The proposal is consistent with prior signaling from SEC Chair Gary Gensler that changes were coming, as he highlighted, for example, during his January 2022 remarks at Northwestern School of Law’s Annual Securities Regulation Institute.  The proposal’s direction is also consistent with the significant uptick in the SEC’s activity concerning cybersecurity-related matters following the SolarWinds supply chain attack, after which the SEC reportedly opened a probe into the attack’s effects and companies’ disclosures.

In the immediate term, the SEC’s proposal shows that this area is still evolving, but it also clearly signals that there is likely to be continuing increased SEC activity in this area.  While the evolving nature of the area may for the moment create challenges for the SEC to bring enforcement cases, it also puts public company executives on notice that they are responsible for their companies’ cyber-related actions to prepare for and in response to cyber-attacks.

The following is a summary of updates from the SEC’s proposal and Fact Sheet, which provides additional context related to the proposed cybersecurity amendments:

Reporting cybersecurity incidents on Forms 8-K

    • Requiring current reporting about material cybersecurity incidents on Form 8-K within four business days;
    • Amending Form 6-K to add “cybersecurity incidents” as a reporting topic;

Disclosure about cybersecurity incidents in periodic reports

    • A registrant’s policies and procedures to identify and manage cybersecurity risks;
    • Management’s role in implementing cybersecurity policies and procedures;
    • Updates about previously reported material cybersecurity incidents;
    • Requiring updated disclosures relating to previously disclosed cybersecurity incidents and to require disclosure, to the extent known to management, when a series of previously undisclosed individually immaterial cybersecurity incidents has become material in the aggregate;

Disclosure of a registrant’s risk management, strategy and governance regarding cybersecurity risks

    • Requiring registrants to provide more consistent and informative disclosure regarding their cybersecurity risk management and strategy;
    • Requiring disclosure of whether cybersecurity related risk and previous incidents have affected or are reasonably likely to affect the registrant’s results of operations or financial condition;
    • Requiring a description of management’s role in assessing and managing cybersecurity-related risks and in implementing the registrant’s cybersecurity policies, procedures, and strategies;
Disclosure regarding the board of directors’ cybersecurity expertise
    • Requiring disclosure about the cybersecurity expertise of members of the board of directors of the registrant, if any;
Periodic disclosure by foreign private issuers (FPI)
    • Requiring an FPI to include in its annual report on Form 20-F the same type of disclosure that would be required in periodic reports filed by domestic registrants:

- Item 106 of Regulation S-K. (1) provide updated disclosure in periodic reports about previously reported cybersecurity incidents; (2) describe its policies and procedures, if any, for the identification and management of risks from cybersecurity threats, including whether the registrant considers cybersecurity risks as part of its business strategy, financial planning and capital allocation; and (3) require disclosure about the board’s oversight of cybersecurity risk, management’s role in assessing and managing such risk, management’s cybersecurity expertise, and management’s role in implementing the registrant’s cybersecurity policies, procedures, and strategies; and

- Item 407 of Regulation S-K. Requiring disclosure of whether any member of the registrant’s board has expertise in cybersecurity, and if so, the nature of such expertise.

The amendments also require the cybersecurity disclosures to be presented in Inline eXtensible Business Reporting Language (Inline XBRL).

***

Crowell & Moring LLP is highly experienced at advising companies that are navigating cybersecurity and SEC compliance issues such as these.  We can provide guidance regarding this Alert and assist with privileged investigations, compliance efforts and other related activities.

For more information, please contact the professional(s) listed below, or your regular Crowell & Moring contact.

Evan D. Wolff
Partner – Washington, D.C.
Phone: +1.202.624.2615
Email: ewolff@crowell.com
Matthew B. Welling
Partner – Washington, D.C.
Phone: +1.202.624.2588
Email: mwelling@crowell.com
Daniel L. Zelenko
Partner – New York
Phone: +1.212.895.4266
Email: dzelenko@crowell.com
Garylene (Gage) Javier, CIPP/US
Associate – Washington, D.C.
Phone: +1.202.654.6743
Email: gjavier@crowell.com

Ukraine Crisis Contacts

Antitrust

Shawn R. Johnson
Partner – Washington, D.C.
Phone: +1.202.624.2624
Email: srjohnson@crowell.com

Learn more about our Antitrust & Competition practice.

Aviation

Eileen M. Gleimer
Partner – Washington, D.C.
Phone: +1.202.624.2840
Email: egleimer@crowell.com

Learn more about our Aviation practice.

Corporate

Bryan Brewer
Partner – Washington, D.C.
Phone: +1.202.624.2605
Email: bbrewer@crowell.com
Jennifer K. Grady
Partner – New York
Phone: +1.212.530.1893
Email: jgrady@crowell.com
Frederick (Rick) Hyman
Partner – New York
Phone: +1.212.803.4028
Email: fhyman@crowell.com
Richard J. Lee
Partner – New York
Phone: +1.212.530.1937
Email: rlee@crowell.com
Scott Lessne
Senior Counsel – Washington, D.C.
Phone: +1.202.624.2597
Email: slessne@crowell.com
Timothy E. Lin
Partner – New York
Phone: +1.212.530.1921
Email: tlin@crowell.com
Kevin Rubinstein
Partner – New York
Phone: +1.212.530.1818
Email: krubinstein@crowell.com
Cathryn Williams
Partner – London
Phone: +44.20.7413.1345, +44.07775.900050
Email: cewilliams@crowell.com

Learn more about our Corporate & Transactional practice.

Cybersecurity

Evan D. Wolff
Partner – Washington, D.C.
Phone: +1.202.624.2615
Email: ewolff@crowell.com
Alexander Urbelis
Senior Counsel – New York
Phone: +1.212.895.4254
Email: aurbelis@crowell.com

Learn more about our Privacy & Cybersecurity practice.

Financial Services

Carlton Greene
Partner – Washington, D.C.
Phone: +1.202.624.2818
Email: cgreene@crowell.com
Andrew J. Knight
Partner – London
Phone: +44.20.7413.1366
Email: aknight@crowell.com
Richard J. Lee
Partner – New York
Phone: +1.212.530.1937
Email: rlee@crowell.com
Michael D. Mann
Partner – Washington, D.C.
Phone: +1.202.261.2990
Email: mmann@crowell.com
Andrew M. Martin
Partner – London
Phone: +44.20.7382.4890
Email: amartin@crowell.com
William Q. Orbe
Partner – New York
Phone: +1.212.530.1850
Email: worbe@crowell.com
Gregory Gennady Plotko
Partner – New York
Phone: +1.212.530.1924
Email: gplotko@crowell.com

Learn more about our Financial Services practice.

Government Affairs

James G. Flood
Partner – Washington, D.C.
Phone: +1.202.624.2716
Email: jflood@crowell.com
Kate Beale
Senior Policy Director – Washington, D.C.(CMI)
Phone: +1.202.508.8997
Email: KBeale@crowell.com

Learn more about our Government Affairs practice.

Government Contracts

Robert J. Sneckenberg
Partner – Washington, D.C.
Phone: +1.202.624.2874
Email: rsneckenberg@crowell.com
Peter Eyre
Partner – Washington, D.C.
Phone: +1.202.624.2807
Email: peyre@crowell.com
Laura J. Mitchell Baker
Counsel – Washington, D.C.
Phone: +1.202.624.2581
Email: lbaker@crowell.com
Christopher D. Garcia
Counsel – Washington, D.C.
Phone: +1.202.688.3450
Email: cgarcia@crowell.com
Rina M. Gashaw
Associate – Washington, D.C.
Phone: +1.202.624.2827
Email: rgashaw@crowell.com
Allison Skager
Associate – Los Angeles
Phone: +1.213.310.7957
Email: askager@crowell.com

Learn more about our Government Contracts practice.

Global Mobility

Nicole Janigian Simonian
Partner – Los Angeles, Shanghai
Phone: +1.213.310.7998
Email: nsimonian@crowell.com

Learn more about our Global Mobility practice.

Insurance

Laura Foggan
Partner – Washington, D.C.
Phone: +1.202.624.2774
Email: lfoggan@crowell.com

Learn more about our Insurance / Reinsurance practice.

International Trade/Sanctions/Export Control

John B. Brew
Partner – Washington, D.C.
Phone: +1.202.624.2720
Email: jbrew@crowell.com
Caroline E. Brown
Partner – Washington, D.C.
Phone: +1.202.624.2509
Email: cbrown@crowell.com
Carlton Greene
Partner – Washington, D.C.
Phone: +1.202.624.2818
Email: cgreene@crowell.com
Robert Holleyman
Partner and C&M International President & CEO – Washington, D.C.
Phone: +1.202.624.2505
Email: rholleyman@crowell.com
Michelle J. Linderman
Partner – London
Phone: +44.20.7413.1353
Email: mlinderman@crowell.com
Jeffrey L. Snyder
Partner – Washington, D.C.
Phone: +1.202.624.2790
Email: jsnyder@crowell.com
David (Dj) Wolff
Partner; Attorney at Law – Washington, D.C., London
Phone: +1.202.624.2548, +44.20.7413.1368
Email: djwolff@crowell.com
Robert Clifton Burns
Senior Counsel – Washington, D.C.
Phone: +1.202.688.3448
Email: cburns@crowell.com

Learn more about our International Trade practice.

International Dispute Resolution

Meagan T. Bachman
Partner – Washington, D.C.
Phone: +1.202.624.2722
Email: mbachman@crowell.com
Ian A. Laird
Partner – Washington, D.C.
Phone: +1.202.624.2879
Email: ilaird@crowell.com
John L. Murino
Partner – Washington, D.C.
Phone: +1.202.624.2663
Email: jmurino@crowell.com
Laurence Winston
Partner – London
Phone: +44.20.7413.1333
Email: lwinston@crowell.com

Learn more about our International Dispute Resolution practice.

Labor & Employment

Sadina Montani
Partner – Washington, D.C.
Phone: +1.202.508.8875
Email: smontani@crowell.com

Learn more about our Labor & Employment practice.

Technology & Brand Protection

Andrew J. Avsec
Partner – Chicago
Phone: +1.312.840.3260
Email: aavsec@crowell.com
Virginia Wolk Marino
Partner – Chicago
Phone: +1.312.840.3228
Email: vmarino@crowell.com

Learn more about our Technology & Brand Protection practice.

Tax

S. Starling Marshall
Partner – New York
Phone: +1.212.895.4263
Email: smarshall@crowell.com
Irina Pisareva
Partner – New York
Phone: +1.212.803.4067
Email: ipisareva@crowell.com

Learn more about our Tax practice.

Force Majeure

Bryan Brewer
Partner – Washington, D.C.
Phone: +1.202.624.2605
Email: bbrewer@crowell.com
Allyson McKinstry
Partner – New York
Phone: +1.212.803.4061
Email: amckinstry@crowell.com
Scott L. Winkelman
Partner – Washington, D.C.
Phone: +1.202.624.2972
Email: swinkelman@crowell.com
Laurence Winston
Partner – London
Phone: +44.20.7413.1333
Email: lwinston@crowell.com

White Collar

Michael K. Atkinson
Partner – Washington, D.C.
Phone: +1.202.624.2540
Email: matkinson@crowell.com
Michael J. Gunnison
Senior Counsel – Doha
Email: mgunnison@crowell.com

Learn more about our White Collar & Regulatory Enforcement practice.