The US stock market regulator wants to tighten reporting requirements for security breaches at publicly traded firms. Credit: SARINYAPINNGAM / AzFree / Getty Images The US Securities and Exchange Commission today proposed legal changes that would require publicly traded companies to disclose material cybersecurity incidents within four days of such a breach.The SEC also wants to require “periodic disclosures” of the impact of ongoing cybersecurity threats in regularly scheduled quarterly 10-Q and annual 10-K reports filed by publicly traded firms, further increasing the mandate for transparency on cybersecurity issues. The more immediate reports disclosing security incidents would be filed in 8-K forms, used for unscheduled disclosures.The idea is to protect investors by improving their ability to inform themselves about the risks involved in investing in a given company, according to the SEC. Given the severity of the threat posed by bad cybersecurity actors, a breach could have a huge impact on a company’s stock value and line of business, the commission said in a statement. “Across industries, companies increasingly rely on information technology, collection of data, and use of digital payments as critical components of their business model and strategy,” the SEC said. “Their exposure to cybersecurity risks and previous cybersecurity incidents may affect these critical components, informing changes in their business model, financial condition, financial planning, and allocation of capital.” It’s a change that appears to have been in the works for some time. SEC chairman Gary Gensler told a conference on securities law in January that his agency wanted to strengthen regulations around cybersecurity, and outlined a multipart plan to do so, touching on consumer information protection, requirements for stronger security measures in the financial sector, and updates to existing regulations designed to incentivize large organizations to improve their technological security programs.Staff guidance issued as far back as 2011 gave a good indication of the SEC’s interest in cybersecurity matters, staking out the agency’s position that cybersecurity incidents and risks are matters that responsible companies need to disclose. That guidance quickly bore fruit, prompting many large publicly traded firms to begin making those disclosures on their 8-K forms, and the SEC has even sanctioned companies with multimillion-dollar fines for failing to disclose important security incidents. This week’s proposals by the SEC included a request for comment from industry stakeholders — comments are due either 30 days after first publication of the proposal in the Federal Register or May 9, whichever is later. An online form for providing comments can be accessed here. Related content feature The CSO guide to top security conferences Tracking postponements, cancellations, and conferences gone virtual — CSO Online’s calendar of upcoming security conferences makes it easy to find the events that matter the most to you. By CSO Staff 30 Aug 2024 8 mins Technology Industry IT Skills Events news F5, Intel team up to boost AI delivery, security F5 and Intel are working together to combine security and traffic-management capabilities from F5’s NGINX Plus suite with Intel’s OpenVINO open-source toolkit for optimizing AI inference and Intel IPU hardware accelerators. By Michael Cooney 29 Aug 2024 1 min Network Security Artificial Intelligence Security news Cisco snaps up AI security player Robust Intelligence Plans call for integrating Robust Intelligence's AI security platform with Cisco Security Cloud to streamline threat protection for AI applications and models and increase visibility into AI traffic. By Ann Bednarz 28 Aug 2024 1 min Mergers and Acquisitions Artificial Intelligence Security feature What is OWASP? A standard bearer for better web application security The Open Web Application Security Project (OWASP) is an international nonprofit dedicated to providing free documentation, tools, videos, and forums for anyone interested in improving the security of their web applications. By Linda Rosencrance 28 Aug 2024 8 mins Internet Security IT Skills Application Security PODCASTS VIDEOS RESOURCES EVENTS SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe