Proxy Advisory Firm Issues Guidance on Cyber Oversight and Disclosure
Time 2 Minute Read

Glass Lewis & Co. recently published its updated Benchmark Policy Guidelines for 2024 (the “Policy”), which reflect investors’ continuing focus on corporate disclosure and board oversight of cyber risks. The Policy indicates that Glass Lewis may recommend “against” directors following a cybersecurity incident if it finds the board’s risk oversight or its post-incident response to be insufficient. The Policy also provides guidance on what Glass Lewis expects companies to disclose after such an incident.  

While the updated Policy says Glass Lewis generally will not make voting recommendations based on cyber oversight or disclosure, it states that, if “a company has been materially impacted by a cyber-attack, we may recommend against appropriate directors should we find the board’s oversight, response or disclosures concerning cybersecurity-related issues to be insufficient or are not provided to shareholder.” 

With respect to disclosure, the updated Policy provides that, if “a company has been materially impacted by a cyber-attack,” Glass Lewis “believe[s] shareholders can reasonably expect periodic updates from the company communicating its ongoing progress towards resolving and remediating the impact of the cyber-attack.” For example, Glass Lewis indicates that a company’s disclosure would include “details such as when the company has fully restored its information systems, when the company has returned to normal operations, what resources the company is providing for affected stakeholders, and any other potentially relevant information, until the company considers the impact of the cyber-attack to be fully remediated.” The Policy states, however, that companies should not “reveal specific and/or technical details that could impede the company’s response or remediation of the incident or that could assist threat actors.”

You May Also Be Interested In

Time 1 Minute Read

On February 6, 2026, the Federal Trade Commission announced its second report to Congress on its efforts to combat ransomware and other cyber attacks.

Time 2 Minute Read

Congress has extended the Cybersecurity Information Sharing Act of 2015 through September 30, 2026 as part of the Consolidated Appropriations Act, a government funding package enacted in early February 2026.

Time 2 Minute Read

On November 20, 2025, the U.S. Securities and Exchange Commission issued a brief announcement that it filed a joint stipulation with defendants SolarWinds Corporation and its Chief Information Security Officer to dismiss, with prejudice, the SEC’s ongoing civil enforcement action against them.

Time 3 Minute Read

Ace American Insurance Company (“Ace”) recently filed a subrogation lawsuit against two technology and cybersecurity providers, following a cybersecurity incident suffered by an insured policyholder that had engaged the providers. This case highlights the growing risk of subrogation lawsuits following a cybersecurity incident.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page