Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on lemmy.world
technology·TechnologybyL4sBot

U.S. rule requires public companies to disclose cybersecurity breaches in 4 days

U.S. rule requires public companies to disclose cybersecurity breaches in 4 days::The Securities and Exchange Commission adopted rules Wednesday to require public companies to disclose within four days all cybersecurity breaches that could affect their bottom lines. Delays will be permitted if immediate disclosure poses serious national security or public safety risks.

U.S. rule requires public companies to disclose cybersecurity breaches in 4 dayshttps://www.ctvnews.ca/business/new-u-s-sec-rule-requires-public-companies-to-disclose-cybersecurity-breaches-in-4-days-1.6495286Open linkView original on lemmy.world
257

7 replies

Technically, the clock doesn't start ticking on the four-day window for reporting until companies have determined a breach is material.

It's not all breaches. In fact, because this is the SEC, it's about financial impact, not privacy or security.

It's a good start, but I worry that a financial impact based approach creates the wrong incentive.

14

4 days!? That's awfully fucking generous. I would have made the requirement at 24 hours because fuck corporations.

3
ech0reply
lemdro.id

Eh I disagree. You have to give companies time to patch their shit. If they disclose hours or days before they have time to patch that can lead to another breach assuming the vulnerability is shared.

But yes fuck Corporations.

35
lemmy.world

This, sometimes not showing all the goods is the best measure. Once it’s known it can become a lot more of a threat.

But yes fuck corporations

15

Public companies, really? They only managed to gather political will to impose that with securities in mind?

3

You reached the end

U.S. rule requires public companies to disclose cybersecurity breaches in 4 days | Spyke