Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Different teams start with different VCs

Tesla’s cheaper vehicles aren’t helping its declining sales

Salesforce announces a heavy overhaul for Slack, with 30 new features

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Salesforce announces a heavy overhaul for Slack, with 30 new features

    2 April 2026

    Meta’s gas glut could power South Dakota

    2 April 2026

    Anthropic is one month old

    1 April 2026

    Mercor Says It Was Hit By Cyber ​​Attack Linked To Compromise Of LiteLLM Open Source Project

    1 April 2026

    With its new app store, Ring bets on artificial intelligence to overcome home security

    31 March 2026
  • Apps

    Exclusive: Beehiiv expands into podcasting, targeting Patreon

    2 April 2026

    A new dating app, Sonder, has a deliberately annoying sign-up process (and it works)

    2 April 2026

    Truecaller Caller ID app reaches 500 million monthly users

    1 April 2026

    Go play this secret game in the TikTok DMs

    1 April 2026

    Speechify’s Windows app uses local models for transcription and dictation

    31 March 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    Doss raises $55 million for AI inventory management that connects to ERP

    24 March 2026

    Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

    23 March 2026

    Amid legal turmoil, Kalshi is temporarily banned in Nevada

    20 March 2026

    Nominations for the Startup Battlefield 200 are still open

    19 March 2026

    Kalshi’s legal woes pile up as Arizona files first criminal charges for ‘illegal gambling operation’

    17 March 2026
  • Hardware

    Nothing’s AI device design reportedly includes smart glasses and headphones

    2 April 2026

    Cognichip wants AI to design the chips that power AI, and it just raised $60 million to test

    2 April 2026

    Meta launches two new Ray-Ban glasses designed for prescription wearers

    1 April 2026

    Whoop’s valuation just tripled to $10 billion

    1 April 2026

    The Pixel 10a doesn’t have a camera bump, and it’s great

    30 March 2026
  • Media & Entertainment

    Roku is launching a standalone app for Howdy, its $2.99 ​​streaming service

    31 March 2026

    SXSW is making a comeback as a premier networking, ideas festival for founders and VCs

    30 March 2026

    ‘Project Hail Mary’ becomes Amazon MGM’s biggest box office hit

    30 March 2026

    Sora’s shutdown could be a reality check moment for video AI

    29 March 2026

    Netflix confirms it’s raising prices again

    27 March 2026
  • Security

    Apple releases security patch for older iPhones and iPads to protect against DarkSword attacks

    2 April 2026

    WhatsApp is alerting hundreds of users who installed a fake app made by a government-run spyware maker

    1 April 2026

    Health data giant CareCloud says hackers accessed patient medical records

    1 April 2026

    North Korean hackers accused of hijacking popular open source project Axios to spread malware

    31 March 2026

    Apple will hide your email address from apps and websites, but not from the police

    30 March 2026
  • Startups

    Different teams start with different VCs

    2 April 2026

    YC’s troubled startup Delve’s reputation just got worse

    2 April 2026

    StrictlyVC San Francisco is less than a month away

    1 April 2026

    It’s not your imagination: AI startups have higher valuations

    1 April 2026

    The company behind ClassPass and Mindbody just got a lot bigger with a $7.5 billion merger

    31 March 2026
  • Transportation

    Tesla’s cheaper vehicles aren’t helping its declining sales

    2 April 2026

    The Rivian spinoff will also build autonomous delivery vehicles for DoorDash

    2 April 2026

    Uber and WeRide are ramping up robotaxi operations in Dubai

    1 April 2026

    Robotaxi companies decline to say how often their AVs need remote assistance

    1 April 2026

    TechCrunch Mobility: When a robotaxi needs to call 911

    30 March 2026
  • Venture

    Toyota’s Woven Capital appoints new CIO and COO in push to find ‘future of mobility’

    1 April 2026

    Exclusive: Runway Launches $10M Fund, Builders Program to Back Early-Stage AI Startups

    31 March 2026

    Former Coatue Partner Raises Massive $65M Seed Fund for Enterprise AI Agent Startup

    31 March 2026

    From Moon Hotels to Cattle Grazing: 8 Startup Investors Hunted at YC Demo Day

    28 March 2026

    16 of the most interesting startups from the YC W26 Demo Day

    27 March 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»As the SEC’s new data breach disclosure rules take effect, here’s what you need to know
Security

As the SEC’s new data breach disclosure rules take effect, here’s what you need to know

techtost.comBy techtost.com24 December 202307 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
As The Sec's New Data Breach Disclosure Rules Take Effect,
Share
Facebook Twitter LinkedIn Pinterest Email

Starting today, on December 18, public companies operating in the US must comply with a new set of rules requiring them to disclose “material” cyber incidents within 96 hours. The regulation represents a significant upheaval for agencies, many of which have argued that the new rules open them up to more risks and that four days is not enough time to confirm a breach, understand its impact or coordinate alerts.

Regardless, those who don’t comply — whether a new entrant or a decades-old publicly held company — could face significant consequences courtesy of the US Securities and Exchange Commission (SEC).

What do businesses need to know?

In accordance with incoming cyber security disclosure requirements, was first approved by the Securities and Exchange Commission in July, organizations must report cybersecurity incidents, such as data breaches, to the SEC on a specific line item in a Form 8-K report within four business days. According to the regulator, the rules are intended to increase visibility into cybersecurity governance and provide disclosure in a more “consistent, comparable and useful way for decision-making” that will benefit both investors and companies.

“Whether a company loses a factory in a fire — or millions of records in a cyber security incident — it can matter to investors,” SEC Chairman Gary Gensler said at the time.

In an 8-K filing, breached organizations must describe the nature, scope, timing and material effects of the incident, including financial and operational. Specifically, the regulation does not require companies to disclose information “regarding the incident recovery status, whether it is ongoing, and whether data has been breached,” as this could jeopardize ongoing recovery efforts.

“This means companies must have the appropriate controls and processes in place to ensure that a materiality determination can be made once a cybersecurity incident is identified,” Jane Norberg, partner in the Securities Enforcement Defense practice at the Washington, D.C.-based law firm. . Arnold & Porter. “Practically speaking, companies will also want to consider having the incident response team in the process chain when making materiality determinations.”

Norberg added, “The rule also includes breaches of registrant information that may be in a third-party system. This means that a company should collect and evaluate information and make materiality determinations based on breaches of third-party systems.”

“I seem to be the person who criticizes the SEC less than everyone else because I think they should be praised for trying to set rules.” Joe Sullivan, former CSO of Uber

Smaller companies, which the SEC defines as companies with a public float of less than $250 million or less than $100 million in annual revenue, will get a 180-day extension before they need to file their Form 8-K disclosing an incident.

There is also an exception to the four-day deadline for larger organizations, a clause added after businesses argued that early disclosure of a cyber vulnerability or incident could hinder ongoing law enforcement investigations. The SEC says disclosure can be delayed if the US attorney general determines that notifying shareholders of the incident “would pose a significant risk to national security or public safety.”

The FBI will be responsible for collecting delay request forms and forwarding viable ones to the Department of Justice.

In addition to the SEC’s new data breach disclosure rules, the regulator has also added a new line item called Item 106 to Regulation SK to be included in a company’s annual Form 10-K filing. This will require businesses to outline their process “for assessing, identifying and managing significant risks from cyber security threats”. Companies must also disclose their management’s ability to assess and manage significant risks from cyber attacks.

What are the consequences if businesses do not comply?

If an organization subject to the SEC’s jurisdiction does not comply with the new rules on cybersecurity disclosures, it can lead to several consequences, the SEC says.

“The SEC has the power to enforce compliance and can take action against organizations that do not comply with the regulations. Some potential consequences include financial penalties, legal liabilities, reputational damage, loss of investor confidence and regulatory scrutiny,” Safi Raza, senior director of cybersecurity at Fusion Risk Management, told TechCrunch. “The SEC is unwavering in its commitment to protect investors, making clear that enforcement measures will be implemented to ensure transparency and accountability.”

As demonstrated by the SEC’s recent action against SolarWinds and its chief information security officer (CISO), the regulator’s action could be even more far-reaching.

“In this case, the SEC is seeking civil monetary penalties, disbarment and permanent disqualification against the CISO from serving as an officer or director of a public company based on alleged material misstatements and failure to maintain proper disclosures and controls with respect to SolarWinds cyberattack,” Norberg said.

This controversial case shares similarities with the case against former Uber CSO Joe Sullivan, who in 2022 was found guilty of obstruction of justice and misdemeanor counts of misdemeanor failure to report in connection with a 2014 breach of Uber’s systems. .

In a recent interview with TechCrunch, Sullivan said he welcomes the SEC’s data breach reporting rules, saying, “We can pick apart the details as much as we want, but this is the right way to do it,” he said. “I seem to be the person who criticizes the SEC less than everyone else because I think they should be praised for trying to set rules.”

Was there pushback?

Not surprisingly, yes.

Some firms have expressed concern about the short four-day reporting window to determine whether or not an incident is material and then report it to the Securities and Exchange Commission. Until now, many organizations took months to report a breach and did so only after they had completed their investigation.

“The real challenge for companies is to stay up-to-date and on top of all the changing laws and requirements related to cybersecurity hygiene and breaches, and to put in place the appropriate controls, processes and procedures to reduce the risk of this constantly evolving landscape”. Norberg said.

Some organizations have also raised concerns about the SEC’s definition of “material events,” since the regulator has not provided a definition of materiality specifically for cybersecurity events. Instead, the SEC directs companies to apply the longstanding definition of materiality used in securities law, which says: “Information is material if there is a substantial likelihood that a reasonable shareholder would consider it relevant to making an investment decision, or whether it would have significantly changed the set of information available to investors.

Norberg added that there is also concern from businesses that the timing and scope of the information to be disclosed “could give hackers information about the steps the company took.”

In fact, they may have just gone into effect, but hackers have already abused the SEC’s new data breach rules. Earlier this year, the notorious Alphv/BlackCat ransomware group has filed an SEC complaint against one of its victims, MeridianLinkbecause the incident was not reported to the regulator.

“It has come to our attention that MeridianLink, in light of a significant breach compromising customer data and business information, has failed to file the required disclosure pursuant to Item 1.05 of Form 8-K within the prescribed four business days as defined by the new SEC Rules,” read a post on the gang’s dark web leak site.

Matthew Gracey-McMinn, head of threat research at cybersecurity firm Netacea, told TechCrunch that this tactic — adopted by attackers in an attempt to extort extra money from victims — could become a big problem in the future.

“We expect this to become a common practice of most cyberattacks in 2024 and may act as an additional charge alongside or even replace data encryption by ransomware,” Gracey-McMinn said.

breach cyber security data data breaches disclosure effect heres rules SECs security US Securities and Exchange Commission
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleLabrys Technologies collects seeds to serve humanitarian, military scenarios
Next Article Flipboard becomes a federated app with support for ActivityPub
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Apple releases security patch for older iPhones and iPads to protect against DarkSword attacks

2 April 2026

WhatsApp is alerting hundreds of users who installed a fake app made by a government-run spyware maker

1 April 2026

Health data giant CareCloud says hackers accessed patient medical records

1 April 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Different teams start with different VCs

2 April 2026

Tesla’s cheaper vehicles aren’t helping its declining sales

2 April 2026

Salesforce announces a heavy overhaul for Slack, with 30 new features

2 April 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Doss raises $55 million for AI inventory management that connects to ERP

24 March 2026

Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

23 March 2026

Amid legal turmoil, Kalshi is temporarily banned in Nevada

20 March 2026
Startups

Different teams start with different VCs

YC’s troubled startup Delve’s reputation just got worse

StrictlyVC San Francisco is less than a month away

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.