{"id":3623,"date":"2024-05-17T09:00:00","date_gmt":"2024-05-17T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules"},"modified":"2024-05-17T09:00:00","modified_gmt":"2024-05-17T14:00:00","slug":"cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/17\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules\/","title":{"rendered":"CISOs and Their Companies Struggle to Comply With SEC Disclosure Rules"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt398f8252b8829818\/664675f45f79e0208b56d46c\/Dany_Kurniawan-cyber-stockmarket-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">About six months ago, CISO Steve Cobb noticed that the contract language proposed by public companies had some notable additions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the case of a breach, publicly traded companies wanted more control over how their third-party providers responded to an incident \u2014 in some cases, they proposed to take over the incident-response process or wanted the third-party provider to make a determination within hours of whether a breach could be material, says Cobb, who manages cybersecurity for risk intelligence firm SecurityScorecard. The company has even seen similar contract language proposed by its own customers, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The impetus for the changes? The Securities and Exchange Commission&#8217;s ruling on <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/proposed-sec-rules-require-more-transparency-about-cyber-risk\" rel=\"noopener\">cybersecurity risk management and incident disclosure<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which went into effect last December, and which is changing how companies handle incident response along with their third-party suppliers, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;[P]ublic companies are putting within contractual agreements that if one of their suppliers has a breach, they essentially give the rights to the public company to take over the incident response process,&#8221; Cobb says. &#8220;It&#8217;s scary for a for-profit organization [and] it&#8217;s a really dangerous slope to go down.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The impact on private third-party providers is just one way that enterprises are attempting to change their operations to comply with the SEC&#8217;s mandate. Already <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/dark-reading-confidential-the-ciso-and-the-sec\" rel=\"noopener\">chief information security officers worry<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that they will be <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/what-do-cisos-have-to-do-to-meet-new-sec-regulations-\" rel=\"noopener\">held to account for any mistakes<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in determining the materiality of a breach and point to the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/sec-charges-against-solarwinds-ciso-send-shockwaves-through-security-ranks\" rel=\"noopener\">prosecution of SolarWinds&#8217; CISO<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as representing the personal risk of the position. Companies could <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/orgs-face-major-sec-penalties-failing-disclose-breaches\" rel=\"noopener\">face millions of dollars in fines<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> if they fail to notify the SEC of a material breach.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Overall, 68% of cybersecurity teams do not believe that their company could comply with the four-day disclosure rule, according to a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.vikingcloud.com\/resources-form\/the-2024-threat-landscape-report-cyber-risks-opportunities-resilience\" rel=\"noopener\">survey published on May 16<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by cloud-security firm VikingCloud.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Large Public Firms Already Have the Tools\">Large Public Firms Already Have the Tools<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The largest public companies already have disclosure committees to determine whether a variety of events \u2014 from severe weather to economic changes and geopolitical unrest \u2014 might have a material impact. Adding cybersecurity incidents to their purview requires that various groups \u2014 IT, cybersecurity, legal, and business \u2014 be brought together and be presented with the necessary information to make a determination, says Naj Adib, principal for cyber and strategic risk at consultancy Deloitte.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The necessary level of effort is really about bringing those pieces together and having that orchestration between various parts of the organization,&#8221; he says. &#8220;Organizations [need] to say, for these risk domains and these risk factors, what would constitute something material to me.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CISOs can use tabletop exercises to help companies create the right process for determining materiality and to collect the evidence needed to sign off on a disclosure within the four-day window.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Companies that cannot determine the impact of an incident with certainty could result in preemptive disclosure of a breach to satisfy potential notification requirements. Such concerns led financial-services giant Prudential to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/prudential-files-voluntary-breach-notice-sec\" rel=\"noopener\">proactively file a disclosure statement with the SEC<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in February, despite the fact that the company had only started its investigation and had no indication that the breach would have a material impact.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Every Company's Response Differs\">Every Company&#8217;s Response Differs<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While larger companies have focused on the issue for over a year \u2014 even before the rule was finalized \u2014&nbsp;smaller companies have had a more difficult road, says Matt Gorham, leader of the Cyber and Privacy Innovation Institute at consultancy PricewaterhouseCoopers. Companies need to focus on creating a documented process and saving contemporaneous evidence as they work through that process for each incident.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;There&#8217;s a great disparity from one company to the other &#8230; and between incidents,&#8221; he says. &#8220;Initially, you may have decided that [the breach] may not be material at that point in time, but you&#8217;re going to have to continue to assess the damage and see if it&#8217;s risen to the level of materiality.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So far, there have not been a large volume of filings, so there is not enough data to pick out a trend, he says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Failure to Report\">Failure to Report<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Smaller companies \u2014 and third-party providers \u2014 are likely less prepared and a worry for their publicly-traded clients.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Companies with smaller cybersecurity teams \u2014 where analysts also configure security controls \u2014 can run afoul of regulations due to the human element. In a survey of security teams, for example, VikingCloud found that four-in-ten cybersecurity professionals have not reported an incident for fear of losing their jobs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The reason behind the fear? The worker who triaged the incident is likely the same worker who configured the security controls, says Jon Marler, a cybersecurity evangelist at VikingCloud.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;They have a really thin small team, and because the team is so small, you don&#8217;t have that separation of duties,&#8221; he says. &#8220;I think a lot of the way to solve this culturally is to set up things in place so that the person who finds a problem isn&#8217;t the person who gets fired for finding it. You don&#8217;t want to punish people for success.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"CISOs: &quot;Tip of the Spear&quot;\">CISOs: &#8220;Tip of the Spear&#8221;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security analysts are not the only ones feeling the pressure, of course. While SecurityScorecard&#8217;s Cobb feels he has the support needed to create a strong cybersecurity process to comply with customers&#8217; disclosure needs, he also believes he is in the minority. For the most part, CISOs are being asked to take responsibility for a determination of materiality when they often have neither the authority to make recommendations nor the budget to implement them, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The CISOs are &#8220;the tip of the spear&#8221; \u2014 the leading edge facing the legal repercussions of breach response, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;CISOs are becoming kind of expendable, if you will,&#8221; he says. &#8220;You put one down and bring another one in and start the whole process over again until the [next] breach happens. For the cybersecurity industry, that&#8217;s a really bad sign on the horizon of where we may be headed.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>About six months ago, CISO Steve Cobb noticed that the<\/p>\n","protected":false},"author":12,"featured_media":3624,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3623","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?fit=1600%2C900&ssl=1",1600,900,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?fit=1600%2C900&ssl=1",1600,900,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules.jpg?fit=1600%2C900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3623"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3623\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3624"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}