left-caret

PH Privacy

SEC Cybersecurity Incident Disclosure Report

December 18, 2024

By Sherrese M. Smith,Michelle A. Reed,Aaron Charfoos,Dave Coogan,& Jeremy Berkowitz

Paul Hastings released its SEC Cyber Incident Disclosure Report today, providing a unique look at how public companies have responded to new incident disclosure requirements. The Securities Exchange Commission (SEC) approved new rules in July 2023 around Cybersecurity Risk Management, Strategy, Governance and Incident Disclosures, requiring public companies to disclose material cybersecurity incidents that impact their organizations within 96 hours of determining that they are “material.” This report discusses analysis and trends noted in these disclosures, including:

  • The amount of time between when a public company is made aware of an incident and when it files a disclosure with the SEC;
  • Which individuals are filing the required SEC disclosures on behalf of their public companies;
  • What information is being included in these disclosures and how public companies and the SEC are determining “materiality” as it relates to an incident;
  • Which industries have been most affected by the new SEC rules; and
  • How threat actors have chosen to exploit the new rules to blackmail public companies.

The Paul Hastings Data Privacy and Cybersecurity team regularly advises on compliance with cybersecurity regulations. We are happy to answer any questions related to the report, or how your organization may be affected by these rules.

Click here for a PDF of the full text

Contributors

Image: Michelle A. Reed
Michelle A. Reed

Partner, Litigation Department


Image: Aaron Charfoos
Aaron Charfoos

Partner, Litigation Department


Image: Dave Coogan
Dave Coogan

Associate, Litigation Department


Image: Jeremy Berkowitz
Jeremy Berkowitz

Senior Privacy Director and Deputy Chief Privacy Officer


Image: Hannah Edmonds
Hannah Edmonds

Associate, Litigation Department


Image: Kimia Favagehi
Kimia Favagehi

Associate, Litigation Department


Image: Rachel Kurzweil
Rachel Kurzweil

Of Counsel, Litigation Department


Image: Marisa Polowitz
Marisa Polowitz

Associate, Litigation Department


Image: Scott H. Kaiser
Scott H. Kaiser

Knowledge & Innovation Attorney


Practice Areas

Data Privacy and Cybersecurity

Privacy and Cybersecurity Solutions Group


For More Information

Image: Michelle A. Reed
Michelle A. Reed

Partner, Litigation Department

Image: Aaron Charfoos
Aaron Charfoos

Partner, Litigation Department

Image: Dave Coogan
Dave Coogan

Associate, Litigation Department

Image: Jeremy Berkowitz
Jeremy Berkowitz

Senior Privacy Director and Deputy Chief Privacy Officer