February 26, 2018 - Privacy and Cybersecurity Group News: SEC Issues New Cybersecurity Disclosure Guidance for Public Companies


On February 21, 2018, the SEC approved new interpretive guidance to assist public companies in preparing their disclosures about cybersecurity risks and incidents. The Release builds upon and expands on the SEC’s 2011 staff guidance on cybersecurity matters.

In the Commission’s release, the SEC explained that it:


The SEC also reminded public companies of the ways in which cybsersecurity incidents, and their related costs, can impact a company’s financial statements, its disclosure controls and procedures, and insider trading compliance program. The SEC Release also specifically addresses the importance of company disclosure to investors about how the company’s board of directors is discharging its risk oversight responsibility with respect to the company’s cybersecurity risk management policies and procedures.

The SEC’s February 21st release is here: https://www.sec.gov/rules/interp/2018/33-10459.pdf

The statement of Commissioner Clayton is here: https://www.sec.gov/news/public-statement/statement-clayton-2018-02-21


© Copyright 2025 Murtha Cullina
National Law Review, Volume VIII, Number 58