<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Harvard Law School Forum on Corporate Governance</title>
	<atom:link href="https://corpgov.law.harvard.edu/2022/04/03/sec-proposes-unprecedented-cybersecurity-rules-and-reporting-requirements/feed/" rel="self" type="application/rss+xml" />
	<link>https://corpgov.law.harvard.edu</link>
	<description>The leading online blog in the fields of corporate governance and financial regulation.</description>
	<lastBuildDate>Mon, 20 Jul 2026 20:07:07 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.5.8</generator>

<image>
	<url>https://corpgov.law.harvard.edu/wp-content/uploads/2024/02/cropped-photography-4-e1706898544564-1-32x32.png</url>
	<title>SEC Proposes Unprecedented Cybersecurity Rules and Reporting Requirements &#8211; The Harvard Law School Forum on Corporate Governance</title>
	<link>https://corpgov.law.harvard.edu</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>SEC Proposes Unprecedented Cybersecurity Rules and Reporting Requirements</title>
		<link>https://corpgov.law.harvard.edu/2022/04/03/sec-proposes-unprecedented-cybersecurity-rules-and-reporting-requirements/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=sec-proposes-unprecedented-cybersecurity-rules-and-reporting-requirements</link>
		<comments>https://corpgov.law.harvard.edu/2022/04/03/sec-proposes-unprecedented-cybersecurity-rules-and-reporting-requirements/#comments</comments>
		<pubDate>Sun, 03 Apr 2022 12:13:23 +0000</pubDate>
<!-- 		<dc:creator><![CDATA[]]></dc:creator> -->
				<category><![CDATA[Accounting & Disclosure]]></category>
		<category><![CDATA[Practitioner Publications]]></category>
		<category><![CDATA[Securities Regulation]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Risk disclosure]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SEC]]></category>
		<category><![CDATA[SEC rulemaking]]></category>
		<category><![CDATA[Securities regulation]]></category>

		<guid isPermaLink="false">https://corpgov.law.harvard.edu/?p=144340?d=20220403081323EDT</guid>
		<description><![CDATA[On March 9, 2022, the SEC voted to propose rules mandating sweeping cybersecurity measures for public companies and foreign private issuers. Most notably, the rules would impose a 4-day reporting requirement for domestic issuers who have experienced a “material cybersecurity incident.” The rules would also require foreign issuers to disclose information about material cybersecurity incidents [&#8230;]]]></description>
				<content:encoded><![CDATA[<hgroup><em>Posted by Adam Fee, Antonia M. Apps, and George S. Canellos, Milbank LLP, on Sunday, April 3, 2022 </em><div class='e_n' style='background:#F8F8F8;padding:10px;margin-top:5px;margin-bottom:10px;text-indent:2.5em;'><strong style='margin-left:-2.5em;'>Editor's Note: </strong> <p style="margin:0; display:inline;"><a class="external" href="https://www.milbank.com/en/professionals/adam-fee.html" target="_blank" rel="nofollow noopener">Adam Fee</a>, <a class="external" href="https://www.milbank.com/en/professionals/antonia-m-apps.html" target="_blank" rel="nofollow noopener">Antonia M. Apps</a>, and <a class="external" href="https://www.milbank.com/en/professionals/george-s-canellos.html" target="_blank" rel="nofollow noopener">George S. Canellos</a> are partners at Milbank LLP. This post is based on their Milbank memorandum.</p>
</div></hgroup><p>On March 9, 2022, the SEC voted to propose rules mandating sweeping cybersecurity measures for public companies and foreign private issuers. <a class="footnote" id="1b" href="https://corpgov.law.harvard.edu/2022/04/03/sec-proposes-unprecedented-cybersecurity-rules-and-reporting-requirements/#1">[1]</a> Most notably, the rules would impose a 4-day reporting requirement for domestic issuers who have experienced a “material cybersecurity incident.” The rules would also require foreign issuers to disclose information about material cybersecurity incidents on Forms 6-K and 20-F.</p>
<p>The proposed rules broadly define a “cybersecurity incident” to cover effectively any intrusion of a company’s systems: “an unauthorized occurrence on or conducted through a registrant’s information systems that jeopardizes the confidentiality, integrity, or availability of a registrant’s information systems or any information residing therein.”  Within four days of determining that such an incident is material—with no extension of time for an “ongoing investigation”—the issuer would have to disclose on an amended Form 8-K:</p>
<ul>
<li>when the incident was discovered;</li>
<li>whether it was ongoing;</li>
<li>a brief description of its nature and scope;</li>
<li>whether any data was stolen, altered, accessed, or used for any other unauthorized purpose;</li>
<li>the effect of the incident on operations; and</li>
<li>whether the company “has remediated or is currently remediating the incident.”</li>
</ul>
<p>The proposed rules do not offer any further color on what may render a cybersecurity incident “material” but reiterate the conventional standard: “information is material if ‘there is a substantial likelihood that a reasonable shareholder would consider it important.’”</p>
<p> <a href="https://corpgov.law.harvard.edu/2022/04/03/sec-proposes-unprecedented-cybersecurity-rules-and-reporting-requirements/#more-144340" class="more-link"><span aria-label="Continue reading SEC Proposes Unprecedented Cybersecurity Rules and Reporting Requirements">(more&hellip;)</span></a></p>
]]></content:encoded>
			<wfw:commentRss>https://corpgov.law.harvard.edu/2022/04/03/sec-proposes-unprecedented-cybersecurity-rules-and-reporting-requirements/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
