In one of the most important cybersecurity regulatory developments in recent memory, the U.S. Securities and Exchange Commission (SEC) recently adopted new cybersecurity requirements for publicly traded companies, creating new obligations for reporting “material” cybersecurity incidents and requiring more detailed disclosure of cybersecurity risk management, expertise, and governance. Companies are required to disclose risks in their annual reports beginning on December 15, 2023.
Although the SEC cybersecurity disclosure requirements are drafted relatively broadly, there is one particular area in which the SEC requires specific disclosure: third party risk. In fact, the SEC clearly states in its regulation that companies should disclose whether they have “processes to oversee and identify such risks from cybersecurity threats associated with its use of any third-party service provider.”
Why the explicit focus on third party risk? The SEC recognizes that third parties are increasingly the source of significant cyber risk to an organization. Fueled by the accelerated digital transformation and the shift to the cloud, organizations are turning to more third party vendors to increase efficiency, innovation, and competitive advantage. However, the risk of experiencing a cybersecurity incident introduced by a third party has also risen dramatically. Some of the biggest and costliest data breaches in history used third-party vendors and software vulnerability exploits across the supply chain as entry points. The SEC is clear: a third party incident could absolutely materially impact a company.