In one of the most important cybersecurity regulatory developments in recent memory, the U.S. Securities and Exchange Commission (SEC) recently adopted new cybersecurity disclosure requirements for publicly traded companies, including a requirement to publicly disclose a “material” cybersecurity incident in Form 8-K within four business days of determining that it is material. Now, these "material" incidents are one of the hottest topics being discussed in the cybersecurity and legal communities today.
What exactly is a “material” cybersecurity incident?
The SEC cybersecurity rules describe a material incident as a matter “to which there is a substantial likelihood that a reasonable investor would attach importance” in an investment decision. A reasonable investor is a hypothetical investor generally understood to be a long-term, passive investor of average wealth and sophistication.
What makes a cybersecurity incident “material”?
According to the SEC rules, understanding whether a cyber incident is material requires an analysis of the total mix of quantitative and qualitative data surrounding the incident. There is not a specific financial threshold for a material cyber incident. In fact, the SEC states in the regulation, "...some cybersecurity incidents may be material yet not cross a particular financial threshold.”
The SEC offers a few examples of what a material cybersecurity incident might look like. “For example, an incident that results in significant reputational harm to a registrant may not be readily quantifiable and therefore may not cross a particular quantitative threshold, but it should nonetheless be reported if the reputational harm is material. Similarly, whereas a cybersecurity incident that results in the theft of information may not be deemed material based on quantitative financial measures alone, it may in fact be material given the impact to the registrant that results from the scope or nature of harm to individuals, customers, or others, and therefore may need to be disclosed."
However, as the SEC noted in comments to the rulemaking, “most organizations’ materiality analyses will include consideration of the financial impact of a cybersecurity incident.” For this reason organizations may wish to shine a brighter light on financial quantification of potential cyber risks. Organizations should consider performing a cyber risk quantification analysis to help them understand different impact scenarios where the company is exposed financially. This assessment can inform risk and security leaders about gaps in their program, areas to invest in, and potential risk transfer options.
Ultimately, incidents should be evaluated on a case-by-case basis in conjunction with legal counsel to determine materiality. CISOs can play a critical role in understanding what these incidents may look like and developing proactive plans to remediate the risk of an incident. However, the ultimate determination of materiality is often left to legal counsel, the CEO, and the board of directors.