On March 9, 2022, the Security and Exchange Commission (SEC) proposed new rules to improve upon and standardize cybersecurity-related disclosure obligations for public companies. The SEC is expected to finalize the rules in April 2023, which means registrants should begin working now to bring their reporting practices in line with the new requirements. Below is a high-level overview of certain upcoming changes introduced by the SEC’s disclosure amendments.

Cyber Incident Reporting

Risk Management, Strategy, and Governance Reporting

Bond attorneys regularly assist and advise clients on an array of data privacy and cybersecurity matters, including regulatory reporting. If you have any questions regarding the SEC’s upcoming cybersecurity disclosure requirements, please contact Jessica Copeland, CIPP/US, Mario Ayoub or any attorney in Bond’s cybersecurity and data privacy practice.