Dave Lynn spoke to IT Brew about the U.S. Securities and Exchange Commission's (SEC) final cybersecurity disclosure rules for public companies that went into effect on September 5th. The new regulations specify what kinds of information public companies will need to disclose regarding cybersecurity risk management and strategies.
According to Dave, “It’s the same framework that applies to basically every other sort of disclosure obligation that a company has, for the most part, under the SEC’s requirements.”
He added, “It’s inevitably going to cause people to go back and hone their materiality analysis and beef up…their controls and procedures around how this information is communicated internally.”
Read the full article.