When the Board Becomes the Compliance Officer: SEC Cyber Disclosure Rules
and the New Governance Reality
For decades, cybersecurity
oversight lived several layers below the boardroom. A CISO reported to a CIO,
who reported to a COO, who occasionally briefed directors after a major
incident. The SEC's 2023 disclosure rules ended that arrangement.1
Public companies must now describe, in every annual filing, which board
committee owns cyber risk and how that committee receives information about it.2
The requirement did not ask boards to manage cybersecurity. It asked them to
prove, in writing, that they already do.
Two obligations sit at the
center of the rule. Item 1.05 of Form 8-K requires disclosure of a material
cybersecurity incident within four business days of the materiality
determination — not four days from discovery, four days from the decision.3
That distinction has mattered more than most executives expected. Legal
commentators have identified enforcement patterns targeting companies that took
weeks to determine materiality on facts that should have taken days.4
The second obligation, Item 106 of Regulation S-K, requires an annual account
of how the company assesses, identifies, and manages cyber risk, including the
specific expertise management brings to that task.5
None of this replaces a
security program. It documents one. That distinction has produced its own
enforcement pattern: the SEC has cited companies not for weak security, but for
describing controls they did not actually have.6 Aspirational
language — “we conduct regular penetration testing,” when testing happens
sporadically — now carries securities law exposure alongside reputational risk.
For organizations outside the
public markets, none of these rules apply directly. The logic behind them has
migrated anyway. Cyber insurers ask the same questions Item 1C asks. Lenders
and acquirers increasingly do too. A board, or for a private company an owner
or executive team, that cannot describe its cyber governance in plain language
is now behind a standard that started with public companies but has not stayed
there.
Regulation S-P, with a
compliance deadline of June 3, 2026, extends similar accountability to
broker-dealers, investment advisers, and other SEC registrants regarding the
safeguarding of customer information.7 The direction across these
rules is consistent. Governance that used to live quietly in an IT department
now lives, on paper, with the people ultimately responsible for the
organization.
#CyberSecurity #CyberGovernance
#SECCompliance #BoardGovernance #GarlickGroup
1. U.S. Securities and Exchange Commission, “Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure,” Release Nos. 33-11216; 34-97989, effective for fiscal years ending on or after December 15, 2023, as discussed in “SEC Cybersecurity Disclosure Rules: What Every Board Director Must Know in 2026,” Aprio, April 20, 2026, https://aprioboardportal.com/landing-board-directors/.
2. “SEC Cybersecurity Disclosure Rules: Board Accountability,” Citanex, April 8, 2026, https://citanex.com/resources/sec-cybersecurity-disclosure-board-accountability-2026/.
3. Aprio, “SEC Cybersecurity Disclosure Rules.”
4. Aprio, “SEC Cybersecurity Disclosure Rules.”
5. “SEC Cyber Disclosure Rules: The Board-Savvy CISO of 2025,” Vantedge Search, April 3, 2026, https://www.vantedgesearch.com/resources/blog/sec-cyber-disclosure-rules-the-new-profile-of-a-board-savvy-ciso-2/.
6. “SEC Cybersecurity Disclosure Rules Guide 2026: 8-K Incident Reporting,” Decryption Digest, accessed July 2026, https://www.decryptiondigest.com/blog/sec-cybersecurity-disclosure-rules-incident-reporting-guide.
7. “SEC's New Cyber-Security Rules Put Boards on the Hook,” Governance Intelligence, https://www.governance-intelligence.com/regulatory-compliance/secs-new-cyber-security-rules-put-boards-hook.
No comments:
Post a Comment