SEC Adopts Statement and Interpretive Guidance on Public Company Cybersecurity Disclosures
The SEC issued interpretive guidance to clarify public companies' disclosure obligations regarding cybersecurity risks and incidents, enhancing transparency for investors.
The SEC unanimously approved interpretive guidance to clarify public companies' disclosure obligations regarding cybersecurity risks and incidents under existing securities laws. The guidance emphasizes the need for robust internal controls and compliance with insider trading prohibitions. No enforcement action or monetary penalty was involved.
The Securities and Exchange Commission unanimously approved a statement and interpretive guidance to assist public companies in preparing disclosures about cybersecurity risks and incidents. The guidance provides the Commission's views on public companies' disclosure obligations under existing law regarding cybersecurity risk and incidents. It emphasizes the need for robust internal controls, timely disclosure of material cyber incidents, and compliance with insider trading rules and Regulation FD to prevent selective disclosure. Chairman Jay Clayton urged companies to consider both legal and reputational impacts, particularly regarding executive securities trading. The guidance aims to enhance investor access to material cybersecurity information. The move reinforces existing regulatory frameworks rather than introducing new requirements. The outcome is enhanced transparency for investors, not enforcement action.
Exhibits & Attached Documents (1)
Extracted insights
- person Jay Clayton ×2
- agency Securities and Exchange Commission
- Securities And Exchange Commission Voted Unanimously To Approve A Statement And Interpretive Guidance To Assist Public Companies In Preparing Disclosures About Cybersecurity Risks And Incidents
- Jay Clayton Said Providing The Commission’s Views Will Promote Clearer And More Robust Disclosure By Companies About Cybersecurity Risks And Incidents
- Jay Clayton Urged Public Companies To Examine Their Controls And Procedures
- The Guidance Provides The Commission’s Views About Public Companies’ Disclosure Obligations Under Existing Law Regarding Cybersecurity Risk And Incidents
Yesterday, the Securities and Exchange Commission voted unanimously to approve a statement and interpretive guidance to assist public companies in preparing disclosures about cybersecurity risks and incidents. “I believe that providing the Commission’s views on these matters will promote clearer and more robust disclosure by companies about cybersecurity risks and incidents, resulting in more complete information being available to investors,” said SEC Chairman Jay Clayton. “In particular, I urge public companies to examine their controls and procedures, with not only their securities law disclosure obligations in mind, but also reputational considerations around sales of securities by executives.” The guidance provides the Commission’s views about public companies’ disclosure obligations under existing law with respect to matters involving cybersecurity risk and incidents. It also addresses the importance of cybersecurity policies and procedures and the application of disclosure controls and procedures, insider trading prohibitions, and Regulation FD and selective disclosure prohibitions in the cybersecurity context.
Yesterday, the Securities and Exchange Commission voted unanimously to approve a statement and interpretive guidance to assist public companies in preparing disclosures about cybersecurity risks and incidents. “I believe that providing the Commission’s views on these matters will promote clearer and more robust disclosure by companies about cybersecurity risks and incidents, resulting in more complete information being available to investors,” said SEC Chairman Jay Clayton. “In particular, I urge public companies to examine their controls and procedures, with not only their securities law disclosure obligations in mind, but also reputational considerations around sales of securities by executives.” The guidance provides the Commission’s views about public companies’ disclosure obligations under existing law with respect to matters involving cybersecurity risk and incidents. It also addresses the importance of cybersecurity policies and procedures and the application of disclosure controls and procedures, insider trading prohibitions, and Regulation FD and selective disclosure prohibitions in the cybersecurity context.