Tuesday, July 28, 2026

When the Board Becomes the Compliance Officer

 

When the Board Becomes the Compliance Officer: SEC Cyber Disclosure Rules and the New Governance Reality

For decades, cybersecurity oversight lived several layers below the boardroom. A CISO reported to a CIO, who reported to a COO, who occasionally briefed directors after a major incident. The SEC's 2023 disclosure rules ended that arrangement.1 Public companies must now describe, in every annual filing, which board committee owns cyber risk and how that committee receives information about it.2 The requirement did not ask boards to manage cybersecurity. It asked them to prove, in writing, that they already do.

Two obligations sit at the center of the rule. Item 1.05 of Form 8-K requires disclosure of a material cybersecurity incident within four business days of the materiality determination — not four days from discovery, four days from the decision.3 That distinction has mattered more than most executives expected. Legal commentators have identified enforcement patterns targeting companies that took weeks to determine materiality on facts that should have taken days.4 The second obligation, Item 106 of Regulation S-K, requires an annual account of how the company assesses, identifies, and manages cyber risk, including the specific expertise management brings to that task.5

None of this replaces a security program. It documents one. That distinction has produced its own enforcement pattern: the SEC has cited companies not for weak security, but for describing controls they did not actually have.6 Aspirational language — “we conduct regular penetration testing,” when testing happens sporadically — now carries securities law exposure alongside reputational risk.

For organizations outside the public markets, none of these rules apply directly. The logic behind them has migrated anyway. Cyber insurers ask the same questions Item 1C asks. Lenders and acquirers increasingly do too. A board, or for a private company an owner or executive team, that cannot describe its cyber governance in plain language is now behind a standard that started with public companies but has not stayed there.

Regulation S-P, with a compliance deadline of June 3, 2026, extends similar accountability to broker-dealers, investment advisers, and other SEC registrants regarding the safeguarding of customer information.7 The direction across these rules is consistent. Governance that used to live quietly in an IT department now lives, on paper, with the people ultimately responsible for the organization.

#CyberSecurity #CyberGovernance #SECCompliance #BoardGovernance #GarlickGroup

1. U.S. Securities and Exchange Commission, “Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure,” Release Nos. 33-11216; 34-97989, effective for fiscal years ending on or after December 15, 2023, as discussed in “SEC Cybersecurity Disclosure Rules: What Every Board Director Must Know in 2026,” Aprio, April 20, 2026, https://aprioboardportal.com/landing-board-directors/.

2. “SEC Cybersecurity Disclosure Rules: Board Accountability,” Citanex, April 8, 2026, https://citanex.com/resources/sec-cybersecurity-disclosure-board-accountability-2026/.

3. Aprio, “SEC Cybersecurity Disclosure Rules.”

4. Aprio, “SEC Cybersecurity Disclosure Rules.”

5. “SEC Cyber Disclosure Rules: The Board-Savvy CISO of 2025,” Vantedge Search, April 3, 2026, https://www.vantedgesearch.com/resources/blog/sec-cyber-disclosure-rules-the-new-profile-of-a-board-savvy-ciso-2/.

6. “SEC Cybersecurity Disclosure Rules Guide 2026: 8-K Incident Reporting,” Decryption Digest, accessed July 2026, https://www.decryptiondigest.com/blog/sec-cybersecurity-disclosure-rules-incident-reporting-guide.

7. “SEC's New Cyber-Security Rules Put Boards on the Hook,” Governance Intelligence, https://www.governance-intelligence.com/regulatory-compliance/secs-new-cyber-security-rules-put-boards-hook.



No comments:

Post a Comment