(800) 341-2684

Call Toll Free

Contact us

Online Inquiries 24/7

Laura Anthony Esq

MAKE VALUED ALLIANCES

Cybersecurity Disclosures

SEC Division Of Corporation Finance Statement On Disclosure Review

On June 24, 2024, Erik Gerding the Director of the SEC’s Division of Corporation Finance made a statement regarding the SEC’s state of disclosure review.  In fiscal year 2023 and continuing into 2024, the top areas of review and comment by the SEC were China-related matters, artificial intelligence, non-GAAP disclosures, management’s discussion and analysis, revenue recognition and financial statement presentation.  In addition, disruptions in the banking industry, cybersecurity risks, the impact of inflation and disclosure related to or as a result of newly adopted rules (such as pay versus performance) are gaining attention by SEC review teams.

The director’s statement gives some insight into the SEC’s focus and serves as a reminder to our clients and us practitioners alike to be sure we are staying abreast of the ever-changing capital markets environment.

China Related Disclosures

A few years ago, the SEC enacted the Holding Foreign Companies Accountable Act and approved rules implementing same (see HERE).   The SEC continues to

SEC Publishes More New C&DI On Cybersecurity Rules

On June 24, 2024 the SEC published five (5) new compliance and disclosure interpretations (C&DI) on cybersecurity incident disclosures supplementing the C&DI published in December 2023 (see HERE).

Cybersecurity

In July, 2023 the SEC adopted final new rules requiring disclosures for both domestic and foreign companies related to cybersecurity incidents, risk management, strategy and governance (see HERE for a review of the new rules).

The cybersecurity rules add new Item 1.05 to Form 8-K requiring disclosure of a material cybersecurity incident including the incident’s nature, scope, timing, and material impact or reasonably likely impact on the company.  An Item 1.05 Form 8-K is due within four business days following determination that a cybersecurity incident is material. Given the sensitive nature of cybersecurity crimes, the SEC has added a provision allowing an 8-K to be delayed if it is informed by the United States Attorney General, in writing, that immediate disclosure would pose a substantial risk to national security or

SEC Publishes New C&DI On Cybersecurity Rules

Back in fourth quarter 2023, the SEC published several new compliance and disclosure interpretations on various topics including cyber incident disclosure, proxy and information statements, the inclusion of securities in the filing fee exhibit, and Inline XBRL.  As my blog topic list tends to be very long, I am finally getting to this and will cover the various new C&DI topics over the next few weeks.

Cybersecurity

In July, 2023 the SEC adopted final new rules requiring disclosures for both domestic and foreign companies related to cybersecurity incidents, risk management, strategy and governance (see HERE for a review of the new rules).  The SEC has published three new C&DI directly related to the Form 8-K reporting requirements and ability to delay reports based on national security concerns.

The cybersecurity rules add new Item 1.05 to Form 8-K requiring disclosure of a material cybersecurity incident including the incident’s nature, scope, timing, and material impact or reasonably likely impact on the

The New 10-K Requirements For Annual Report Season

As 2023 has come to a close it is time to prepare for the upcoming annual report season and this year there are multiple new requirements to be cognizant of.  With annual reports being followed by proxies and first quarter 10-Q’s in rapid succession, it is important to get ahead of all the new disclosures. This blog will summarize each of the new disclosures and include some practice tips.

First, though is what is suddenly not a new requirement and in particular the share repurchase disclosures.  Adopted on May 3, 2023 (see HERE) the new disclosure requirements would have taken effect for inclusion in the upcoming 10-K season.  Following a successful court challenge, on November 22, 2023, the SEC issued an order postponing the effective date of the new rules pending further SEC action (see HERE).  However, the SEC may not get the opportunity to resurrect the rules.  The U.S. Chamber of Commerce is doubling down and

SEC Chair Gary Gensler’s Annual Congressional Testimony

On September 12, 2023, Gary Gensler gave his annual testimony to the United States Senate Committee on Banking, Housing and Urban Affairs and then on September 27th to the United States House of Representatives Committee on Financial Services (for a review of last year’s testimony see HERE).  Both appearances included the same prepared remarks followed by robust Q&A from the lawmakers.

This year Chair Gensler’s prepared remarks focused on: (i) rule amendments and updates; (ii) improving efficiency in equity markets; (iii) disclosure matters and related enforcement including related to cryptocurrency; and (iv) general updates on the SEC and capital markets.

Prepared Remarks

We shouldn’t expect the busy SEC rule making agenda to slow down any time soon.  Chair Gensler prioritizes updating rules for technology, business and market changes.  Although Gensler’s speech focuses on rule changes to make the markets more efficient and resilient and lower costs, the reality is that not all rule changes will accomplish

SEC Adopts Final New Rules On Cybersecurity Disclosures

On July 26, 2023, the SEC adopted final new rules requiring disclosures for both domestic and foreign companies related to cybersecurity incidents, risk management, strategy and governance.  The proposed rules were published in March 2022 (see HERE).  In response to numerous comments, the final rules made several changes to the proposal, including narrowing the disclosures in both the Form 8-K/6-K and annual reports on Form 10-K and 20-F.

The final rules add new Item 1.05 to Form 8-K requiring disclosure of a material cybersecurity incident including the incident’s nature, scope, timing, and material impact or reasonably likely impact on the company.  An Item 1.05 Form 8-K will be due within four business days following determination that a cybersecurity incident is material. Given the sensitive nature of cybersecurity crimes, the SEC has added a provision allowing an 8-K to be delayed if it is informed by the United States Attorney General, in writing, that immediate disclosure would pose a substantial

Proposed Rules On Cybersecurity Disclosure

Earlier this year, the SEC published proposed rules on cybersecurity risk management, strategy, governance and incident disclosure by public companies.  Although the comment period has passed, a final rule has not yet been issued.  As of now, cybersecurity disclosures are encompassed within the general anti-fraud provisions including the requirement to disclose “such further material information, if any, as may be necessary to make the required statements, in light of the circumstances under which they are made, not misleading” as well SEC guidance last updated in 2018 (see HERE).

The proposed amendments would require, among other things, current reporting about material cybersecurity incidents and updates about previously reported cybersecurity incidents. The proposal also would require periodic reporting about a company’s policies and procedures to identify and manage cybersecurity risks; the company’s board of directors’ oversight of cybersecurity risk; and management’s role and expertise in assessing and managing cybersecurity risk and implementing cybersecurity policies and procedures. The proposal would further

Russia-Ukraine Disclosures And Supply Chain Issues

Supply chain issues continue to plague just about every industry and the continuing attack by Russia against the Ukraine, gives little hope of a respite in the near future.  The recent easing of congestion at the handful of U.S. ports big enough to accommodate container ships is likely more a result of inflation and a summer slowdown than effective logistical management.  Amid the ongoing difficulties, the SEC has published a sample letter to companies regarding disclosures pertaining to Russia’s invasion of the Ukraine and related supply chain issues.

SEC Sample Comment Letter

The SEC is of the view that companies should provide detailed disclosure, to the extent material or if required by a prescriptive rule, regarding: (i) direct or indirect exposure to Russia, Belarus, or Ukraine through their operations, employee base, investments in Russia, Belarus, or Ukraine, securities traded in Russia, sanctions against Russian or Belarusian individuals or entities, or legal or regulatory uncertainty associated with operating in or exiting

Intellectual Property And Technology Risks – International Business Operations

In December 2019, the SEC Division of Corporation Finance issued CF Disclosure Guidance: Topic No. 8 providing guidance related to the disclosure of intellectual property and technology risks associated with international business operations.

The global and technologically interconnected nature of today’s business environment exposes companies to a wide array of evolving risks, which they must individually examine to determine proper disclosures using a principles-based approach.  A company is required to conduct a continuing analysis on the materiality of risks in the ever-changing technological landscape to ensure proper reporting of risks.  To assist management in making these determinations, the SEC has issued additional guidance.

The guidance, which is grounded in materiality and a principles-based approach, is meant to supplement prior guidance on technology and cybersecurity matters including the February 2018 SEC statement on public company cybersecurity disclosures (see my blog HERE); Director Hinman’s speech at the 18th Annual Institute on Securities Regulation in Europe in March, 2019; the SEC

Categories

Contact Author

Laura Anthony Esq

Have a Question for Laura Anthony?