The most popular and comprehensive Open Source ECM platform
Cybersecurity and SEC Guidelines: Updating Guidelines for Security Best Practices
In November 2017, following a string of huge data breaches from companies like Equifax and Yahoo, affecting the data and privacy of millions of people, the US Securities and Exchange Commission (SEC) announced that it will revise its guidance to public businesses for how cybersecurity incidents should be reported and responded to.
Matt Rossi, a former assistant chief litigation counsel to the SEC, said that “unfortunately, in the reality that we live in now, cyber breaches are going to be increasingly common, and this is in part why the SEC is so fully focused on cybersecurity. Chairman [Jay] Clayton said it’s one of the greatest risks to the financial system right now.”
Eldon Sprickerhoff, founder and chief security strategist at cyber security company eSentire, said that “at the heart of SEC regulations is the recognized need for preparedness in the financial industry. Identifying risks, writing policies and procedures, and having the appropriate defenses in place are essential for businesses in 2018.”
Rossi said that “we’re likely to see an increased emphasis on having public companies disclose the cyber risks they face, focusing on their business model, the nature of their operations and the evolving and changing nature of cyber risks. I also think there’s going to be an expectation by the commission that we’re going to see more timely disclosure of data breaches when they do occur.”
Remember that guidance isn’t the same as regulations. The SEC will typically release their guidance or perspective on what best practices should be. When businesses don’t comply to these best practices, the SEC is likely to investigate and potentially take action if businesses are found to be negligent in their approach to security.














SEC announced that it will revise its guidance to public businesses for how cybersecurity incidents should be reported and responded to the incident.