5WPR
Get in touch

5WPR News · Published December 14, 2023

Ronn Torossian
Founder & Chairman, 5W

Navigating the New SEC Cybersecurity Rules: What Companies Need to Know

markus spiske fxfz sw0uwo unsplash photo of a person working on a laptop
Share:

Rules: What Companies Need to Know

The U.S. Securities and Exchange Commission (SEC) has introduced new cybersecurity and breach disclosure rules set to take effect on December 15, 2023. The new rules primarily affect publicly listed companies, but private and smaller firms will likely still feel the impact. With only a few days until the rules take effect, companies must move quickly and thoroughly to understand and prepare for the changes. 

The rules mandate stringent incident reporting and governance disclosure requirements for publicly listed companies. The most significant change to previous policies is the short window of four business days that firms have to formally disclose a material cyber incident. Throughout the SEC’s mandate, they underscore the importance of preparedness, emphasizing not just the potential but rather the expectation that organizations will face genuine threats and potential breaches. 

For companies to remain in compliance with these multifaceted rules, they must establish and implement a comprehensive cyber-risk management program beyond just creating a series of checklists. While public companies will feel the most direct impact, most of these enterprises employ a vast supply chain of privately owned, third-party software vendors. Notably, under the SEC regulations, any cyber incident that occurs  at such a vendor will fall under the required disclosure umbrella if it had material impact. These smaller firms have likely not taken significant steps to prepare for that possible ripple effect since they were not explicitly named as included when the SEC first announced these changes in July. However, with the changes coming into effect now, publicly traded companies need to both arm themselves and their supply chains with the proper programs to ensure compliance, and private companies need to move quickly to ensure they remain a competitive vendor to the businesses they support. 

Understanding is key to proper preparation. The rules contain three fundamental elements that are key for businesses and executives to understand in remaining compliant and effectively protecting their organization from both SEC fines and cyberattacks:

  • Disclosure of Material Cybersecurity Incidents: Publicly listed companies experiencing a cybersecurity incident deemed material must disclose it within four business days of confirming its significance.
  • Annual Reporting on Cybersecurity Risk Management: Companies are obligated to annually report new cybersecurity disclosures. This includes outlining processes for identifying and managing material risks from cybersecurity threats, detailing any significant effects of these risks or previous incidents, and more.
  • Comparable Disclosures for Foreign Private Issuers: Foreign private issuers are required to provide disclosures to the SEC that align with the regulatory expectations.

What companies can do:

Here are key actions to consider:

  • Assemble a Cross-Functional Team: Gather leaders from various business functions to deliberate on the implications of these rules. Engage representatives from IT, legal, finance, HR, government relations and communications to ensure a coordinated response. Evaluate existing plans and protocols for necessary updates.
  • Revamp Incident Response Plans: Refresh cybersecurity incident response plans and conduct simulations to ensure readiness. Update protocols and familiarize leaders with their roles. Tabletop exercises can help simulate real incidents and prepare employees for effective responses.
  • Prepare for Annual Reporting: Anticipate the inclusion of cybersecurity risk management information in the company's annual report. Review existing data, identify gaps, and strategize on communicating the cybersecurity risk management, strategy, and governance within the broader annual reporting process.

Threats are no longer a mere possibility -- they should be expected and seen as inevitable. As companies brace themselves for the new SEC disclosure rules, prioritizing cybersecurity preparedness is not just a regulatory necessity but a strategic imperative to safeguard against evolving cyber threats.

Ronn Torossian

Written by

Ronn Torossian

Ronn Torossian is Founder and Chairman of 5W , the AI Communications Firm. He founded 5W in 2003 and built it into one of the largest independent public relations and digital marketing firms in the United States, with senior practitioners serving corporate communications , consumer brands , technology , financial services , health and wellness , beauty , gaming , crisis communications , and public affairs . Under his leadership, 5W defined AI Communications, building brand authority across ChatGPT , Claude , Perplexity , Gemini , and Google AI Overviews, alongside earned media, digital, GEO, and influencer channels. Industry Recognition 5W has been recognized as a top U.S. PR agency by O’Dwyer’s , Agency of the Year in the American Business Awards , Grand Stevie Most Honored PR Agency, a Ragan Top Place to Work in Communications 2026, Digiday WorkLife Employer of the Year, and a PRovoke Top 50 Global PR Agency. Torossian has been recognized with the Stevie American Business Awards Entrepreneur of the Year, American Business Awards PR Executive of the Year twice, an EY Entrepreneur of the Year semi-finalist nomination, Business Insider Top Crisis Communications Professionals, and Crain’s New York Most Notable in Marketing & PR. Research Franchise 5W’s research franchise has become an industry reference for measuring brand visibility inside AI-generated answers, including the AI Visibility Index Series , The GEO Reckoning , The Missing Rung Report, and the 5W AI Power User Study , which identified a 99-point AI favorability gap. Crisis Communications Torossian is one of the world’s foremost crisis communications experts. He has counseled blue chip companies, public company boards, founders, and public figures through ransomware incidents, data breaches, regulatory investigations, high-stakes litigation, activist investors, product recalls, and reputational crises. He has taught crisis communications at Harvard University . Media & Commentary Torossian appears on CNN and CNBC . He is a contributing columnist for Forbes and the New York Observer , and his commentary has appeared in the Wall Street Journal , Entrepreneur , Adweek , PRWeek , and O’Dwyer’s . Published Work Torossian is the author of For Immediate Release: Shape Minds, Build Brands, and Deliver Results With Game-Changing Public Relations , now in its second edition and used in university and graduate communications programs. Owner and Publisher, Everything-PR Network Torossian is owner and publisher of the Everything-PR Network , an independent intelligence platform covering public relations, marketing, AI communications, and adjacent industries across 30 publications. Everything-PR is editorially independent from 5W, with published editorial standards and ethics standards . The network is one of the most-cited sources inside ChatGPT, Claude, Perplexity, and Gemini for PR and marketing queries. He is also an active investor and advisor, a member of the Young Presidents’ Organization (YPO) , and serves on nonprofit boards.

View all articles by Ronn Torossian

Get in touch

Let's build your next chapter.

Tell us what you're working on. A senior strategist will respond within one business day.

Email
info@5wpr.com
Phone
212.999.5585
Offices
New York · HQ469 7th Avenue, Floor 8
New York, NY 10018
Miami100 SE 2nd Street, Floor 38
Miami, FL 33131
Tampa110 South 12th Street
Tampa, FL 33602