← Back to all briefings
Cybersecurity 5 min read Published Updated Credibility 40/100

Cybersecurity Briefing — SEC proposes rapid cyber incident disclosure

On 9 March 2022 the U.S. SEC proposed rules requiring public companies to disclose material cybersecurity incidents within four business days and to describe governance and risk management practices in annual filings.

Single-point timeline showing the publication date sized by credibility score.
Publication date and credibility emphasis for this briefing. Source data (JSON)

The U.S. Securities and Exchange Commission issued a proposal on 9 March 2022 to standardize how registrants report cybersecurity incidents and governance. The draft rule would mandate Form 8-K disclosures within four business days of determining materiality, with detailed information on incident nature, scope, and timing.

Public companies would also need to describe board oversight, management roles, and risk management processes in periodic reports. The proposal signaled regulator expectations for mature detection, escalation, and documentation practices, reinforcing the need for tested playbooks and cross-functional materiality assessments.

Single-point timeline showing the publication date sized by credibility score.
Publication date and credibility emphasis for this briefing. Source data (JSON)

Continue in the Cybersecurity pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

  • Incident Response
  • Regulation
  • Disclosure
  • United States
Back to curated briefings