Intelligent CIO North America Issue 37 | Page 75

t cht lk

RESPONDING TO NEW CYBERATTACK REPORTING RULES

rThe US Securities and Exchange Commission ( SEC ) has approved new rules that require publicly traded companies to publicise details of a cyberattack within four days of identifying a material impact on their finances , marking a major shift in how computer breaches are disclosed . Richard Suls , Security and Risk Management Consultant , WithSecure and Paul Brucciani , Cybersecurity Advisor , WithSecure , offer their expert commentary .

Richard Suls about cyber incidents , ensuring that investors and stakeholders are promptly informed of potential As a security researcher focused on cybersecurity financial implications resulting from breaches . This will and the protection of sensitive data , I believe that the help in preventing the manipulation of financial data SEC ’ s decision to require publicly traded companies and the withholding of crucial information that could to disclose cyberattacks within four days of identifying impact investors ’ decisions . a “ material ” impact on their finances is a significant step in the right direction . This rule change represents Secondly , the new rule can act as a strong incentive for a major shift in how cyberbreaches are handled and companies to invest more resources in cybersecurity disclosed , and it has several potential benefits for both investors and the overall security landscape .
Firstly , the mandatory disclosure of cyberattacks within a specific timeframe will enhance transparency and accountability . By imposing a strict deadline , companies cannot delay or obscure information measures and incident response capabilities . When faced with the prospect of publicizing a cyberattack and its financial impact , companies are likely to prioritize cybersecurity as a core aspect of their business strategy . This could lead to increased spending on advanced security technologies , threat intelligence , employee training , and proactive risk
www . intelligentcio . com INTELLIGENTCIO NORTH AMERICA 75