SEC

“Everything You Must Know About the Implementation of the SEC’s Latest Data Breach Disclosure Regulations”

Gettyimages 167959993
As the SEC’s new data breach disclosure rules take effect, here’s what you need to know The controversial regulation represents a major shake-up for U.S. organizationsStarting from today, December 18, publicly-owned companies operating in the U.S. must comply with a new set of rules requiring them to disclose “material” cyber incidents within 96 hours. In an 8-K filing, breached organizations must describe the incident’s nature, scope, timing, and material impact, including financial and operational. In addition to the SEC’s new data breach disclosure rules, the regulator has also added a new line item called Item 106 to the Regulation S-K that will be included on a company’s annual Form 10-K filing. In a recent interview with TechCrunch, Sullivan said he welcomed the SEC’s data breach reporting rules, saying: “We can nitpick the details as much as we want, but this is the right way to do it,” he said. Until now, many organizations have taken months to report a breach and only did so after they had completed their investigation.