SEC Mandates Public Companies to Disclose Cyberattacks Within Four Days
The US Security and Exchange Commission has implemented a new regulation to prevent public companies from withholding information about cyberattacks. Under this rule, companies must disclose any significant cybersecurity incidents within four days. However, if a US attorney general believes that disclosing the information could pose a significant threat to national security or public safety, they may delay the disclosure. While these rules are a strict guideline, they are slightly less stringent than the European Union’s General Data Protection Regulation (GDPR), which requires disclosure within three days. The news comes…
Read More