CISOs beware: the SEC is watching
“The teachings [of this latest ruling] are that the SEC is taking note of this difficulty,” Zukis mentioned, “so get your home so as by way of the brand new guidelines.”
“The SEC is being very affected person with the brand new guidelines,” he added. However, he alleged, “there’s an infinite quantity of non-compliance to the brand new guidelines. Corporations usually are not describing the fabric impression of an incident of their present filings below the brand new guidelines. So get centered in your processes, get your documentation in place and disclose [information in filings] in truth.”
“This isn’t rocket science,” he mentioned, “however it requires some consistency and maturity in processes. The SEC will maintain you accountable should you’re enjoying quick and unfastened with these guidelines. In case your documentation [of cyber incidents] is inconsistent, you don’t have a mature course of … It’s not about getting it proper or unsuitable. It’s about displaying you’ve some maturity as a enterprise administration and governance physique to constantly apply some thoughtfulness and rigor to the method.”