The U.S. Securities and Exchange Commission (the “SEC,” or the “Commission”) has in recent years demanded greater transparency from public companies in how they identify, measure, and manage cyber-risk.
In the wake of SolarWinds and the increased supply-chain security scrutiny in Washington DC, companies should be explaining to investors the specific risks they face from cybersecurity threats, including, among others, operational disruption, intellectual property theft, loss of sensitive client data, and fraud caused by business email compromises.
SecurityScorecard, NACD, Cyber Threat Alliance, Diligent, and IHS Markit partnered to create The State of Cyber-Risk Disclosures of Public Companies report.
To download the report, visit: The State of Cyber-Risk Disclosures of Public… | SecurityScorecard
Author: Cyber Threat Alliance
An Update on the State of the SEC’s Approach to Cyber Risk
This update follows the March 2021 State of Cyber-Risk Disclosures of Public Companies. Recent cyber-related comments and enforcement actions by the U.S. Securities and Exchange Commission made clear that the SEC has escalated its scrutiny of the cybersecurity disclosures of [...]
The Power of Partnerships
Written by Devin Lynch, Senior Director, Policy & Government Affairs, SecurityScorecard As CISA’s 4th Annual National Cybersecurity Summit concludes this week, the theme for the final day is “The Power of Partnerships.” Before national cybersecurity month concludes, we should take a moment to join CISA and consider the power of partnerships. We all want the […]