SEC Adopts New Rules Requiring Disclosure of Cyber Incidents
Time 3 Minute Read
Categories: Cyber, D&O

Hardly a day passes without hearing about another major cyber incident. Recent studies show that cybersecurity incidents are becoming more common, but they are also costly, with some reports estimating an average cost of $9.44 million for breaches in the US. In recognition of this mounting problem, government agencies continue to ramp up enforcement and issue new rules, regulations and other guidance aimed at curbing cyber risks. Last week, the SEC adopted final rules requiring registered entities to periodically disclose material cybersecurity incidents and annually disclose their cybersecurity risk management, strategy and governance plans. In announcing the new rules, the SEC specifically noted that “an ever-increasing share of economic activity is dependent on electronic systems.” According to SEC Chair Gary Gensler, “Whether a company loses a factory in a fire—or millions of files in a cybersecurity incident—it may be material to investors.” 

The SEC’s new rules will require registered entities to, among other things:

  • Disclose on Form 8-K any cybersecurity incident the company determines to be “material” within four days of that determination. There is a narrow exception if the US Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety.
  • Describe on Form 10-K the company’s processes for assessing, identifying and managing material risks from cyber threats and whether those risks have or will materially affect the company. Companies must specifically describe the board of directors’ oversight of risks from cybersecurity threats and management’s role and expertise in assessing and managing these risks. 

The Form 8-K disclosures will be due beginning the later of 90 days after publication in the Federal Register, or December 15, 2023. Smaller companies may have more time before they must comply. Form 10-K disclosures will be due beginning with annual reports for fiscal years ending on or after December 15, 2023. For more information about the SEC’s new rules, see SEC Adopts Final Public Company Cyberdisclosure Rules

While these new rules may make our data safer, they may also create additional risk for registered entities and their officers and directors. The four-day disclosure rule, for example, may leave companies scrambling to comply while still responding to the incident itself. Also, requiring companies to describe the board’s and management’s oversight, roles and expertise in managing cyber risks will draw even more attention to the individuals making decisions about cybersecurity processes and incidents.  Cyber and directors and officers (“D&O”) liability policies can help mitigate some of these risks. Each offers distinct, but complementary, coverages that will help protect a company in the event of a cyber incident. Before a cyber incident occurs, companies should carefully review their cyber and D&O policies to determine what claims may be covered and consider modifications to strengthen coverage, narrow exclusions and maximize changes of recovery should a claim arise. For additional guidance, including specific tips and best practices to follow when purchasing, renewing and evaluating cyber and D&O policies, please see our recent client alert.

  • Partner

    Andrea helps companies navigate disasters and swiftly recover insurance funds to restore operations with minimal impact to the bottom line. She leads the firm’s cyber insurance practice and serves as a firmwide hiring partner.

  • Partner

    Geoff works closely with corporate policyholders and their directors and officers to resolve high-stakes insurance disputes. He leads the firm’s directors and officers (D&O) insurance and executive protection practice.

    As a ...

  • Associate

    Charlotte advises policyholders in complex insurance coverage matters. Charlotte represents policyholders in insurance coverage actions in federal and state courts across the country.  Her work includes environmental ...

You May Also Be Interested In

Time 1 Minute Read

The California Consumer Privacy Act continues to drive significant enforcement activity—particularly when minors’ data is involved. In a recent action, the California Privacy Protection Agency imposed a $1.1 million fine on youth sports platform PlayOn Sports for alleged violations involving student data and inadequate opt-out mechanisms. The case highlights growing regulatory scrutiny around how companies collect, share, and provide transparency about personal information—especially when schools and students are involved. 

Time 4 Minute Read

Colleges and universities have long sat at the crossroads of freedom of expression and societal change. As campus activism surges, they face growing pressure to protect their institutional missions while upholding students’ individual rights in an era of heightened scrutiny.

Time 9 Minute Read

Since its first day in office, the current administration has taken steps to curtail the development of renewable energy, and wind energy in particular. Just over a year in, the administration’s intentions do not seem to have changed, but there are signs that legal challenges are affecting implementation of its policies toward renewable energy development.

Time 1 Minute Read

If recent years have taught insurance practitioners anything, it is that the most consequential coverage disputes rarely turn on novelty alone. In 2025, courts continued to resolve high‑stakes insurance disputes by returning to first principles—examining when claims are related, how losses and occurrences are defined and aggregated, and how policy language allocates risk across time and conduct. D&O coverage and other core insurance law issues again occupied center stage, while decisions in property, cyber, and liability disputes reinforced a familiar theme: policy interpretation remains the decisive factor in determining whether coverage is available in an increasingly complex claims environment. As the decisions discussed below demonstrate, 2025 confirmed that even as risks evolve, coverage disputes remain grounded in careful, policy‑specific analysis.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Authors

Archives

Jump to Page