Looking for the latest information security and privacy insights from EXTEND? Follow us on LinkedIn.
Comprehensive Guide on SEC Cyber Rules for Boards of Directors

Comprehensive Guide: SEC Cybersecurity Rules for Boards of Directors

From data breaches and ransomware attacks to business disruption and reputational damage, cybersecurity incidents can have a devastating impact on an organization’s financial health and investor confidence. Ultimately, the board of directors is the last line of defense against these threats — they oversee the company’s overall risk management and hold the executive team accountable for implementing effective protections against them.

Case in point: On May 28th, 2024, Ticketmaster and its parent company Live Nation suffered from a high-profile data breach. According to several reports, Ticketmaster later confirmed the breach involved the theft of email addresses, phone numbers, and encrypted credit card information. Reports further state that the cybercrime group claimed to “have stolen 1.3TB of data from Ticketmaster — including information on 560 million users.”

Data breaches not only affect consumers, but they also negatively impact companies and the markets they serve, posing significant concern to investors who should be aware of instances when their investments could be at risk. Indeed, the evidence is clear:

Quote: Organizations are spending more money than ever on cybersecurity—an estimated $188 billion globally in 2023, a figure expected to grow to almost $215 billion in 2024—yet hackers always seem to stay a step ahead. The number of reported data breaches in the U.S. rose to a record 3,205 in 2023, up 78% from 2022 and 72% from the previous high-water mark in 2021.

 

A graphic with a quote that says “In 2024, “the global average cost of a data breach increased 10% over the previous year, reaching $4.88 million, the biggest jump since the pandemic. In the US, that number is almost double, averaging $9.36 million.”

With increasing cybersecurity threats, the rising cost of data breaches to companies and investors, and investors’ need for more transparent information, the U.S. Securities and Exchange Commission (SEC) adopted a new set of governance rules in July 2023, which were effective in September 2023. What is the end goal? To provide investors with timely, consistent, and useful information about cybersecurity risks and incidents.

The newly introduced rules have two components: one requires companies to disclose material cybersecurity incidents within four business days, while the other mandates annual reporting on cybersecurity risk management, strategy, and governance — as seen in the new 8-K and 10-K cybersecurity disclosure requirements.

Now, boards of directors are closely watching the SEC to see how they scrutinize disclosures and what enforcement actions they might take in the event of a data breach, which naturally raises the following questions:

  • Is our governance and disclosure process comprehensive and compliant with the SEC rules?
  • How can we govern and oversee cyber risk across the enterprise without a reasonable amount of cybersecurity knowledge at the board level?
  • How should we quantify risk to understand the potential costs and support good budget decisions?
  • Is the management team effectively mitigating cyber risk? How do we know for sure?

In this blog post, we offer a comprehensive overview of the SEC cybersecurity rules, specifically focusing on their impact on boards of directors and other stakeholders. We delve into the four key pillars of these regulations, explore the challenges they address, and provide actionable steps for boards to help them navigate the evolving cybersecurity landscape.

Key Highlights:

  • The new SEC cybersecurity rules aim to build trust and protect investors by requiring transparency.
  • Effective cybersecurity governance requires board oversight and a solid understanding of an organization’s cyber risk.
  • Boards set the tone for integrating cybersecurity into strategic planning and fostering a culture of awareness.
  • EXTEND Resources provides tailored services to boards looking to improve cybersecurity knowledge, quantify risk, build effective governance processes, and be prepared to report incidents.

The Rise of the Cybersecurity Governance Gap

For many public companies, the lack of cyber risk knowledge and oversight experience at the board level creates a gap between those handling day-to-day information security activities and those who govern cyber and business risk management and investments. This disparity introduces significant challenges.

Now, the SEC rule and disclosure requirements have certainly amplified this issue. Hence, this blog aims to help readers recognize that they need expert cyber resources to help them understand and oversee cyber risk and meet SEC governance requirements — requiring key cyber resiliency services for boards that EXTEND resources can offer.

If we take a closer look, traditional board structures often lack the technical expertise and specific cybersecurity knowledge required to fully evaluate the complexities of cyber threats and risks. This lack of understanding can hinder effective oversight and implementation of robust cybersecurity measures.

A green graphic with a quote that states: “Too often, cybersecurity gets lost in translation when board members engage the C-suite. This leaves the board unsure of precisely what the organization is funding and where residual gaps remain.”

Without some background in cybersecurity, boards do not have the knowledge to create a cyber risk governance program—much less a program they can use to perform their oversight duties each quarter, are confident will deliver results, and are comfortable disclosing to investors.

In the same ways boards leverage outside HR experts for overseeing compensation planning, directors are turning to cybersecurity board advisory services to enhance their cyber knowledge, develop governance plans, stay up to date on threats and risks, and reduce the risk of regulatory penalties.

The Impacts of Poor Cyber Governance

New information about data breaches affecting public companies regularly makes the news, even though significant funds are spent on cyber defenses. These breaches may result in reputational damage, tarnish user trust, cause stock prices to plummet, and erode investor confidence. Why is this happening?

One place to look for possible answers is the Ticketmaster breach. In fact, the company had to file an 8-K form to the SEC, showing the public that companies do face threats and that the potential for significant financial losses should be a concern.

The question then becomes: With better governance, could this breach have been avoided (or at least have had a less severe impact)? The SEC will be scrutinizing these disclosures. How transparent were they? How comprehensive was the company’s cyber risk management methodology? The potential for enforcement could be large… and although the company had various tools to defend against incoming attacks, it still got breached, which leaves a lot of unanswered questions.

While understanding the full impact of a breach takes time, incidents like these raise even more questions for senior management and boards of directors who should clearly understand their risks:

  • With strong governance processes, could the cyber risks that led to the breach have been identified earlier?
  • Could the breach have been prevented?
  • Could a cyber governance program reduce the severity of the breach and the amount of extracted data?
  • How will the SEC scrutinize the company’s disclosures following the security incident?
  • What impact could a potential investigation have on the organization, its investors, and the board?
  • How can board members quickly understand cyber risks across the organization, close gaps in cyber governance and oversight, and help protect against cyber criminals?
  • What governance and oversight processes should be implemented to help defend against cyber risk?

To explore these critical topics in more detail, readers may access the latest recorded event here. This briefing covers the steps that boards of directors should take to understand the organization’s cyber risk, implement effective cybersecurity governance processes, and meet ongoing SEC disclosure requirements.

What are the SEC Cybersecurity Governance Rules?

The SEC’s cybersecurity governance rules require companies to disclose their processes for identifying, managing, and mitigating significant cybersecurity risks and incidents in their annual filings. The rules consist of four key components, each designed to strengthen cybersecurity posture and enhance transparency for investors:

Governance and Risk Management: Companies are now required to disclose details concerning their processes for assessing, identifying, and managing material risks from cybersecurity threats and whether those threats are reasonably likely to materially affect their business strategy. This information will be included in their annual 10-K filings. As a result, investors can gain valuable insights into the company’s approach to cybersecurity, enabling them to assess its preparedness and risk management strategies.

Board Oversight: The new regulations emphasize the importance of board-level oversight in cybersecurity. Companies must disclose in their 10-K filings how their board is engaged in cybersecurity risk management and what oversight practices are in place. This requirement spotlights the board’s role in cybersecurity governance, promoting greater accountability and encouraging more active involvement.

A green graphic with a quote stating: “Companies must disclose in their 10-K filings how their board is engaged in cybersecurity risk management and what oversight practices are in place. This requirement spotlights the board's role in cybersecurity governance, promoting greater accountability and encouraging more active involvement.”

Incident Reporting: Public companies are obligated to report material cybersecurity incidents on Form 8-K within four business days of determining the materiality of the incident. Materiality, discussed in greater detail below, considers the potential financial, operational, and reputational harm stemming from the incident. This timely disclosure requirement compels companies to be transparent about cyber incidents and ensures investors are promptly informed of potential risks.

Transparency and Investor Confidence: Increased transparency around cybersecurity strengthens investor confidence. Thus, companies can maintain public trust and protect investors’ interests by disclosing information regarding cybersecurity policies, reporting any incidents, improving their board oversight, and demonstrating their commitment to safeguarding sensitive data and protecting investors’ interests.

These comprehensive regulations represent a significant shift in the cybersecurity landscape for public companies. They hold boards accountable for understanding and overseeing cyber risks, prompting a reevaluation of current practices and a move toward more comprehensive cybersecurity governance structures.

Note: The SEC rules affect more than just the board of directors. Access our infographic here to learn more about the different stakeholders impacted by SEC cybersecurity rules.

Determining Materiality: A Critical Factor in Cybersecurity Incident Reporting

The SEC cybersecurity governance rules mandate timely reporting of material cybersecurity incidents. However, the concept of “materiality” can be subjective, and determining whether an incident reaches this threshold can be a complex process. Below, we explore the factors involved in assessing materiality and provide guidance for boards navigating this critical decision.

What does the materiality of a cybersecurity incident mean?

The SEC considers information material if “… there is a substantial likelihood that a reasonable investor would attach importance in determining whether to buy or sell the securities registered.” In the context of cybersecurity incidents, materiality hinges on the potential impact of the incident on a company’s financial performance, operations, and reputation. The following factors should be considered when assessing materiality:

Nature and Scope of the Incident: Breaches involving Social Security numbers, financial information, or intellectual property are more likely to be deemed material than breaches of less sensitive data. The number of individuals or systems affected also influences materiality (i.e. a large-scale breach impacting millions of customers is likely to be considered material).

Financial Impact: Evaluate the potential financial losses resulting from the incident. This may include costs associated with data recovery, notification to affected individuals, legal fees, potential regulatory fines, and reputational damage that could lead to a decline in customer trust and sales.

Operational Disruption: Assess the potential disruption to business operations caused by the incident: downtime of critical systems, hampering productivity, or hindering the ability to deliver services to customers.

Reputational Damage: Consider the potential damage to the company’s reputation. A data breach can erode customer trust and brand loyalty, leading to negative publicity and potentially impacting customer acquisition and retention.

Remediation Efforts: The effectiveness and timelines associated with remediation efforts also factor into materiality. A swift and efficient response can mitigate the incident’s impact, potentially lowering the threshold. Conversely, a slow or ineffective response may amplify the incident’s impact, making it more likely to be deemed material.

How To Determine Materiality of Cyber Incidents

If you need to report an incident and determine whether it is material or not, you should involve the company’s legal counsel, cybersecurity team, senior management, and the board. These experts should analyze all available information, gather evidence, assess potential impacts, and document the entire decision-making process.

Seeking External Board Guidance Services for Material Incidents

In complex cases, seeking external cybersecurity board guidance from industry or legal experts can be prudent. These experts can provide objective assessments of the incident’s potential impact and assist in navigating the materiality determination process.

Remember, even if an incident isn’t considered material for SEC reporting, it’s essential to implement remediation measures and notify affected individuals or authorities based on the nature of the breach. Prioritizing transparency and proactively addressing all cyber incidents can help build trust with investors and other stakeholders while fulfilling compliance obligations.

If your business requires external board guidance, EXTEND Resources has industry-leading experts who possess first-hand board advisory and SEC cybersecurity advisory experience. Especially so, our CEO, Howard Hoffmann, has served as a Board Member or Chairman of the Board for 10+ public and privately held companies, participating in audit, compensation, and governance subcommittees. Our team has extensive experience partnering with board members and the C-Suite to:

  • Explain effective cyber risk management practices using clear business language and context
  • Enhance leadership knowledge of information security fundamentals
  • Establish a strong security and privacy “tone from the top” at the board level
  • Enable boards to effectively oversee risk from cybersecurity threats and describe how risks may affect business strategy, results of operations, or financial condition
  • Evaluate management’s role in assessing and managing material risks from cybersecurity threats
  • Enhance confidence in an organization’s cyber defense and resilience strategies
  • Empower the organization to leverage cyber insurance wisely

Discover more about the unique strengths and know-how that EXTEND can bring to your board by clicking here.

Cyber Risk Governance Recommendations for Boards of Directors

The SEC’s cybersecurity governance rules place greater responsibility on boards of directors to understand and oversee cybersecurity risks. Here are some key recommendations for board members to consider:

Establish a Dedicated Cybersecurity Board Committee

Form a specialized board committee — such as a Cybersecurity or Risk Committee — to oversee cybersecurity. This committee, composed of members with relevant expertise in cybersecurity, risk management, and information technology, can be better prepared to delve into technical details, assess the company’s cyber risk profile, and recommend appropriate mitigation strategies to the full board.

Prioritize Cybersecurity Education

Equip board members with essential knowledge of cybersecurity threats through targeted programs, workshops, and briefings by experts. Investing in cybersecurity education for board members arms directors with the knowledge needed to understand the complexities of cyber threats, ask informed questions, engage in meaningful cybersecurity discussions, and make well-informed risk management decisions.

Leverage Independent Validation

Consider hiring a reputable cybersecurity firm to independently validate your cybersecurity program. These assessments evaluate your cyber defenses, identify vulnerabilities, and recommend improvements, providing valuable insights into the effectiveness of your controls and areas for strengthening your cybersecurity posture.

Quantify Cyber Risk

Develop a process to quantify cyber risk and its business impact, considering factors like data asset value, breach costs, and threat likelihood. Risk quantification methodologies help boards make informed decisions about investments in cybersecurity controls. By understanding the financial implications of cyber risks, boards can allocate resources more strategically, focusing on mitigating the most financially significant risks.

A blue graphic outlining Board Advisory Services that enable board directors to Incorporate Cyber Risk Oversight Into Your Governance Process

Why You Should Create a Resilient Cybersecurity Posture

Boards have an opportunity to support organizations in establishing a resilient cybersecurity posture — significantly strengthening their defenses in an effort to minimize the impact of cyberattacks. Here’s how:

Integrate Cybersecurity into Strategic Planning

Integrate cybersecurity considerations into the overall strategic planning process. Cybersecurity risks should be factored into business continuity planning, disaster recovery planning, and crisis management strategies. By considering cybersecurity throughout the strategic planning process, boards can ensure the company has a holistic approach to cyber risk management.

Foster a Culture of Cybersecurity Awareness

Boards should ensure that the CEO and executive management prioritize cybersecurity and set the right tone from the top. When leadership demonstrates a clear commitment to cybersecurity, it encourages a company-wide culture of awareness and empowers employees to prioritize cyber hygiene practices with the objective of reducing the likelihood of human error that can lead to cyber incidents.

Foster Continuous Improvement

Cybersecurity is an ongoing process, not a one-time fix. Boards should encourage a culture of continuous improvement in cybersecurity by regularly reviewing and updating the company’s cybersecurity policies, processes, procedures, and compliance with one or more established frameworks and applicable regulatory requirements to maintain a robust cybersecurity posture.

Promote Open Communication and Information Sharing

Establish clear communication channels between the cybersecurity team and the board. Regular updates on the cyber threat landscape, incident reports, and risk mitigation strategies should be provided to the board. Open communication and information sharing enables boards to make informed decisions about cybersecurity and hold management accountable for the effectiveness of the company’s cybersecurity program.

If you’re interested in creating a board cyber resilience strategy, you can learn more about cyber risk governance for corporate boards here.

SEC Cybersecurity Readiness: Building a Robust Defense

The SEC’s cybersecurity governance rules establish a framework for public companies to enhance their cybersecurity posture. While the regulations don’t prescribe a specific set of controls, they do highlight key elements that contribute to a company’s overall cybersecurity readiness. Let’s delve into these essential components:

Governance and Risk Management

Policies and Procedures: The company should have documented cybersecurity policies, processes, and procedures that outline its approach to managing cyber risks. This documentation should address areas like data security, access controls, incident response, and personnel training.

Risk Assessment: Conducting regular risk assessments is essential for identifying vulnerabilities in systems and processes. These assessments should consider internal threats, external threats, and the likelihood and potential impact of various cyber incidents.

Management Oversight: Senior management and the board of directors should have a clear understanding of the company’s cyber risk profile and be actively involved in overseeing cybersecurity strategy and mitigation efforts.

Incident Response and Business Continuity

Incident Response Plan: A well-defined incident response plan is crucial for effectively responding to cyber incidents. This plan should outline roles and responsibilities, communication protocols, data recovery procedures, and escalation processes. Regularly testing and updating the incident response plan is essential to ensure its effectiveness.

Business Continuity Plan: Cyber incidents can disrupt business operations. Having a business continuity plan provides a roadmap to recover quickly and minimize downtime. This plan should detail recovery procedures for critical systems, data backups, and alternative methods for delivering essential services.

Cybersecurity Training and Awareness

Workforce Education: The company’s workforce is often the first line of defense against cyberattacks. Regular cybersecurity awareness training programs are essential for educating personnel on best practices for data security, phishing scams, and social engineering tactics.

Security Culture: Fostering a culture of security within the organization is crucial. This involves encouraging personnel to report suspicious activity and creating an environment where cybersecurity is a top priority.

Vendor Management

Third-Party Risk Management: Many companies rely on third-party vendors for critical services. It’s important to assess the cybersecurity posture of these vendors and implement appropriate risk mitigation strategies. This may involve conducting security audits, negotiating the addition of cybersecurity audit rights into contracts, and ongoing monitoring of vendor security practices.

Monitoring and Detection

Security Monitoring: Continuously monitoring systems and networks is essential for detecting suspicious activity and identifying potential cyber threats. This includes deploying security tools to monitor for unauthorized access attempts, malware infections, and other security incidents.

Vulnerability Management: Regularly patching vulnerabilities in software and systems is critical for preventing attackers from exploiting these weaknesses. Companies should have a process for identifying, prioritizing, and patching vulnerabilities in a timely manner.

By focusing on these elements of SEC Cybersecurity Readiness, public companies can build a strong foundation for protecting their sensitive data, mitigating cyber risks, and complying with the SEC’s new regulations. Remember, cybersecurity is an ongoing process, and these elements should be continuously reviewed and updated based on evolving threats and industry best practices.

How EXTEND Helps Boards Manage Cybersecurity Governance

EXTEND Resources advises boards to help them improve their understanding of cyber risk management, facilitate effective oversight of risk assessment and mitigation tactics and costs, boost cyber resilience, and reduce the risk of regulatory penalties. Our team of cybersecurity and compliance experts can advise your board in the following specialty areas:

SEC Cybersecurity Compliance​

Reduce the risk of SEC penalties and fines by disclosing material cybersecurity incidents and reporting Risk Management, Strategy, and Governance information in accordance with SEC requirements.

Mergers and Acquisitions​

Cyber risk and cybersecurity maturity have become key criteria for management teams who are evaluating organizations as merger and acquisition targets. They want to understand how cyber threats could affect the value of the opportunity, what it will take to reduce information security risks, and how to leverage that information in their deals. EXTEND can help you evaluate an organization’s cybersecurity posture in advance of a major transaction.

NY Department of Financial Services Compliance​

Be aware of the latest amendment to the state’s cybersecurity regulation for banking, insurance, and financial services organizations. Recognize your potential exposure and mitigate risks by fostering compliance with the enhanced range of cybersecurity requirements. This includes expanded governance requirements for senior stakeholders, incident response and business continuity planning, incident notification, and certification of compliance.

Why Choose EXTEND for Cyber Risk Management Advice?

Our team’s personal experience serving on boards, combined with our extensive knowledge of information security and data privacy, enables us to advise clients on better protecting against threats, recovering from incidents, and continuing to operate.

EXTEND brings cybersecurity expertise and an independent, objective view of an organization’s security posture directly to your boardroom, enabling you to:

  • Develop processes to evaluate security incidents for materiality and proper disclosure
  • Understand your changing role and cybersecurity responsibilities
  • Master cybersecurity fundamentals needed for oversight
  • Set the tone for a culture of security & privacy
  • Gain confidence in your organization’s security posture
  • Be prepared for third-party audits
  • Recognize the role cyber insurance plays in your organization’s risk mitigation strategy
  • Evaluate the efficacy of your organization’s disaster recovery and business continuity plans

EXTEND holds a comprehensive ISO 27001 certification for information security management. We are serious about security services and operate accordingly.

To learn more about how EXTEND resources can help your board of directors with risk management, incident reporting, or other needs, contact our team here.

 

 

 

 

 

Scroll to Top
Skip to content