New SEC Requirements for Cybersecurity Incident Reporting Skip to main content

Understanding the New SEC Requirements for Cybersecurity Incident Reporting

Understanding the New SEC Requirements for Cybersecurity Incident Reporting

Overview



Video: Understanding the New SEC Requirements for Cybersecurity Incident Reporting webinar, part of McDermott’s 2024 programming (runtime: 38m)
During this webinar, Partners Stephen Reynolds and Dan Woodard and Associate Charles Darantiere discussed the new US Securities and Exchange Commission (SEC) disclosure requirements for cybersecurity incidents.

Top takeaways from the webinar include:

  • When a public company experiences a cybersecurity incident, response procedures should be implemented promptly, including early communications with law enforcement.
  • Disclosure on Form 8-K are not required until a materiality determination has been made; public companies should make such determination without unreasonable delay, in consultation with external advisors and law enforcement.
  • Materiality determinations should involve careful consideration of both quantitative and qualitative factors, with contemporaneous documentation of such analysis.
  • When providing disclosure on Form 8-K, public companies should avoid specifying metrics or facts that are subject to ongoing change to avoid misleading omissions or the creation of a duty to update.

Dig Deeper

New York, NY / In-person / December 8

AI Governance and Security Assessment Workshop

Coral Gables, FL / Speaking Engagements / November 12-14, 2025

Consero's Chief Privacy Officer Forum 2025

Washington, DC / Speaking Engagements / November 12-14, 2025

Privacy + Security Forum Fall Academy 2025

San Diego, CA / Speaking Engagements / October 30-31, 2025

IAPP Privacy. Security. Risk. 2025

San Francisco, CA / In-person / October 28, 2025

Founder and Investor Happy Hour 2025

Get In Touch