Armanino Blog

SEC Plans to Update Guidance on Disclosing Cybersecurity Risks

by Liam Collins
February 23, 2018

In the wake of hacks such as the 2017 Equifax breach, which exposed personal information of roughly 145.5 million people, the Securities and Exchange Commission (SEC) has announced plans to update its interpretive guidance for disclosing cybersecurity issues. The SEC wants to remind public companies of their responsibility to keep investors informed when data is breached or severe hacks are attempted.

Need for change

At a recent American Bar Association meeting, David Fredrickson, chief counsel of the SEC’s Division of Corporation Finance, said that the SEC doesn’t expect to overhaul its Disclosure Guidance: Topic No. 2, Cybersecurity. But he said that the SEC needs to “refresh” it. Specifically, it plans to consider whether important information about cybersecurity should be disclosed to stakeholders within the context of the existing rules. For example, companies may need to beef up their management’s discussion and analysis (MD&A) and footnote disclosures to reflect potential cyber risks and material financial implications of data breaches.  

The current guidance on cybersecurity, which was published in 2011, doesn’t include a specific requirement for companies to disclose computer system intrusions. The SEC’s effort to update the guidance comes amid concerns that more public companies have been experiencing attacks to their computer systems, but their disclosures haven’t been timely or informative enough.

Investors in the past few years have been especially vocal about pushing companies to provide more information about cybersecurity. And SEC Chairman Jay Clayton has told lawmakers during congressional hearings that he believes companies can do a better job of disclosing the risks they face and the hacks into their computers.

Substance over form

Regulators in the SEC haven’t decided whether the update will be issued in the form of staff-level guidance or a regulatory release approved by the SEC’s commissioners. But Fredrickson has identified two new areas the SEC needs to address in the update:

  1. Financial reporting controls and procedures that identify and disclose cybersecurity threats in a timely manner
  2. Corporate strategies and policies regarding cybersecurity prevention, detection and breach response
Many public companies welcome additional guidance from the SEC. Currently, executives often find it difficult to determine the appropriate time to disclose a hack into their systems. 

On the one hand, public companies feel a responsibility to share relevant information openly and honestly with stakeholders. On the other, they don’t want to prematurely disclose information about a breach before they know the extent of the damage or to release inaccurate information that later needs to be revised. Company executives may also be working with law enforcement, in which case they don’t want to disclose information that could compromise the investigation.  

Lead by example

Public companies aren’t the only entities that struggle with determining the appropriate cyber-disclosures; the SEC has also faced criticism over how quickly it disclosed a breach of its own systems. Last September, the SEC reported a 2016 hack of its Electronic Data Gathering, Analysis and Retrieval (EDGAR) filing system, which likely led to illegal stock trades. 

Senator Sherrod Brown (D-OH), a ranking member of the Senate Banking Committee, told regulators during a September hearing that the SEC must abide by the same, or even a higher standard than that applied to companies. Brown also questioned why the SEC seemed to have swept the issue under the rug and whether other information is at risk. 

Plan your breach protocol

Does your company have policies and procedures in place in case its systems are hacked? When a business is struck by a data breach, it’s not the time for do-it-yourself disclosures. Many legal and financial issues are at stake, so it’s important to have a premeditated team of professional advisors—including legal, insurance and financial experts—to handle breach response, measure the impact and mitigate potential losses.


February 23, 2018

Stay In Touch

Sign up to stay up-to-date with the latest accounting regulations, best practices, industry news and technology insights to run your business.

Liam Collins - Partner, Audit - San Francisco CA | Armanino
Related News & Insights
The Bridge BOOtique
Live Event
Join us for an evening of shopping while supporting nearly 50 local, women-owned businesses.

October 27, 2021 | 02:00 PM - 06:00 PM PT
VIP Networking Event at Topgolf
Live Event
Swing by for an evening of conversation, cocktails and food with fellow Dallas nonprofit leaders.

October 14, 2021 | 03:30 PM - 06:30 PM PT
Armanino’s VIP Event at Community Summit
Live Event
See you in-person alongside your Dynamics peers in Houston!

October 13, 2021 | 04:00 PM - 06:00 PM PT