Challenges of SEC cyber-security disclosure rules proposal

The recent proposal to adopt a framework that can instruct companies on how to deal with cyber-attacks and define the role of a company’s board in risk oversight and disclosure has raised eyebrows within the IR community. 

The framework would establish strategies and governance for companies to follow to counter more sophisticated threats and address concerns related to the pervasive use of digital technologies due to the shift to hybrid work environments, the rise in the use of crypto assets and the increase in illicit profits from ransomware and stolen data. 



Neil McCarthy, Morrow Sodali
Neil McCarthy,
Morrow Sodali

But while adoption would protect firms against loss of revenue, reputational damage and erosion of shareholder value, industry experts argue the proposed framework is too complex to implement.

‘When I first started looking at the rule proposal, I thought it would be very straightforward,’ said Neil McCarthy, senior director of sales enablement and business development at Morrow Sodali, in an IR Magazine Webinar. ‘As you dig into it and look at the comment letters from law firms and accounting firms, they are very technical and very focused.

‘A lot of the concerns rise around reporting on 8K ­– there is a lot of complexity on how to do this.’

A tangled web 

The 8K form is a report required by the SEC that companies need to file within four business days to announce significant material events relevant to shareholders. The first challenge, experts say, is to define what makes an event material.

‘There is a judgment call to be made on what’s material,’ said Evan Barth, vice president, associate general counsel and assistant secretary at Kyndryl Holdings. 



Evan Barth
Evan Barth,
Kyndryl Holdings

‘Once you have determined that, it’s one decision made. But with cyber-events, the assessment of materiality could change every day as you learn more facts. Disclosing an 8K form is market-moving information and companies would need to be really careful on how they phrase things when they come up with that materiality assessment.’ 

Barth stressed that disclosure of the report is one of the main challenges the new regulation would bring for companies, which can risk scrutiny for not disclosing information at the right time or disclosing information too early before being able to correctly assess the materiality of the event. 

The second biggest challenge of the proposed regulation panelists addressed was the requirement for companies to have cyber-security experts on their board. 

McCarthy called for the SEC to ‘back off’ on this specific requirement and put forward a ‘more reasonable’ version that can be met by all companies. 

‘The SEC sees that some companies in certain industries have cyber-security experts on the board, but that’s because some companies have more exposure on this front,’ he said. ‘But I think it’s unnecessary for some companies to have a specific designee all the time. It also raises liability concerns for the individuals if they are designated as experts and then something goes wrong.’ 

Click here to watch the IR Magazine Webinar – How companies can prepare for cyber-security regulations, in partnership with Morrow Sodali.

Upcoming events

  • Forum & Awards – South East Asia
    Tuesday, December 2, 2025

    Forum & Awards – South East Asia

    Building trust and driving impact: Redefining investor relations in South East Asia Investor Relations in South East Asia is at a turning point. Regulatory fragmentation, macroeconomic volatility and the growing importance of retail investors require IROs to strategically analyze and reform traditional practices. The ability to deliver transparent, dependable and…

    Singapore
  • Briefing – The value of IR in an increasingly passive investment landscape
    Wednesday, December 3, 2025

    Briefing – The value of IR in an increasingly passive investment landscape

    In partnership with WHEN 8.00 am PT / 11.00 am ET / 4.00 pm GMT / 5.00 pm CET DURATION 45 minutes About the event Explore how IR teams can adapt to the rise of passive investing while effectively measuring and communicating their impact. As index funds and ETFs reshape…

    Online
  • Forum & Awards – Greater China
    Thursday, December 4, 2025

    Forum & Awards – Greater China

    Adapting to change in Greater China: IR strategies for a sustainable, digital and global era The investor relations landscape in Greater China is being reshaped by rapid technological advances, growing ESG expectations, tighter budgets and increasing geopolitical pressures. Digital tools such as automation and Artificial Intelligence (AI) are transforming how…

    Hong Kong SAR

Explore

Andy White, Freelance WordPress Developer London