{"id":1213,"date":"2018-01-31T11:38:06","date_gmt":"2018-01-31T16:38:06","guid":{"rendered":"https:\/\/seci.wpenginepowered.com\/?p=1213"},"modified":"2018-01-31T11:38:06","modified_gmt":"2018-01-31T16:38:06","slug":"cybersecurity-the-secs-official-guidance","status":"publish","type":"post","link":"https:\/\/seciblog.pli.edu\/index.php\/cybersecurity-the-secs-official-guidance\/","title":{"rendered":"Cybersecurity \u2013 The SEC\u2019s Official Guidance"},"content":{"rendered":"<p>By: George M. Wilson, SEC Institute<\/p>\n<p>Cybersecurity risk is an important \u201chot topic\u201d in period-end reporting. In our workshops we sometimes find that many people are not aware that the <strong>SEC has issued guidance about cybersecurity disclosures<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>As a period-end reporting reminder<\/strong>, don\u2019t forget to review <a href=\"https:\/\/www.sec.gov\/divisions\/corpfin\/guidance\/cfguidance-topic2.htm\"><u>CorpFin Disclosure Guidance Topic 2<\/u><\/a> as you address cybersecurity risk. The SEC, both at the staff and Commission level, have recently reiterated that they believe this guidance from 2011 is on-point for disclosure in the current environment. There have been some discussions about whether to move this from a CorpFin document to a more official Commission Release, but there has been no formal activity to date.<\/p>\n<p>&nbsp;<\/p>\n<p>As you read the <a href=\"https:\/\/www.sec.gov\/divisions\/corpfin\/guidance\/cfguidance-topic2.htm\"><u>Disclosure Guidance Topic<\/u><\/a> you will see it suggests that you should tailor information to your circumstances. Disclosure in Risk Factors (likely applicable for almost all companies!) is one issue, but disclosure may also be relevant in the Description of the Business, Legal Proceedings, MD&amp;A and the Financials Statements.<\/p>\n<p>&nbsp;<\/p>\n<p>Another reminder, <a href=\"https:\/\/www.sec.gov\/news\/press-release\/2017-186\"><u>Chairman Clayton\u2019s remarks about cybersecurity risk<\/u><\/a> also provide valuable insight into making appropriate disclosures in this complex area.<\/p>\n<p>&nbsp;<\/p>\n<p>And, as a last thought, PLI is presenting a One-Hour Briefing titled\u00a0<a href=\"https:\/\/www.pli.edu\/Content\/_\/N-\/Term-_Integrating_Enterprise_Risk_Management_Cybersecurity_and_Compliance_in_an_Era_of_Big_Data_Breaches_and_Vulnerability?fromsearch=true&amp;Ntk=RelevancySearch&amp;Ntt=+Integrating+Enterprise+Risk+Management%2c+Cybersecurity+and+Compliance+in+an+Era+of+Big+Data+Breaches+and+Vulnerability&amp;Ntx=mode%2bmatchall%2brel%2bNterm%2cMaxfield%2cGlom%2cPhrase%2cStatic(is_seminar%2cascending)&amp;Nty=1&amp;q=+Integrating+Enterprise+Risk+Management%2c+Cybersecurity+and+Compliance+in+an+Era+of+Big+Data+Breaches+and+Vulnerability\"><u>\u201cIntegrating Enterprise Risk Management, Cybersecurity and Compliance in an Era of Big Data Breaches and Vulnerability<\/u><\/a>\u201d on February 13, 2018.<\/p>\n<p>&nbsp;<\/p>\n<p>As always, your thoughts and comments are welcome!<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By: George M. Wilson, SEC Institute Cybersecurity risk is an important \u201chot topic\u201d in period-end reporting. In our workshops we sometimes find that many people are not aware that the SEC has issued guidance about cybersecurity disclosures. &nbsp; As a period-end reporting reminder, don\u2019t forget to review CorpFin Disclosure Guidance Topic 2 as you address &hellip; <a href=\"https:\/\/seciblog.pli.edu\/index.php\/cybersecurity-the-secs-official-guidance\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Cybersecurity \u2013 The SEC\u2019s Official Guidance<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false},"categories":[143],"tags":[243],"coauthors":[163],"class_list":["post-1213","post","type-post","status-publish","format-standard","hentry","category-hot-topic","tag-trending"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/seciblog.pli.edu\/index.php\/wp-json\/wp\/v2\/posts\/1213","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/seciblog.pli.edu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seciblog.pli.edu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seciblog.pli.edu\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/seciblog.pli.edu\/index.php\/wp-json\/wp\/v2\/comments?post=1213"}],"version-history":[{"count":0,"href":"https:\/\/seciblog.pli.edu\/index.php\/wp-json\/wp\/v2\/posts\/1213\/revisions"}],"wp:attachment":[{"href":"https:\/\/seciblog.pli.edu\/index.php\/wp-json\/wp\/v2\/media?parent=1213"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seciblog.pli.edu\/index.php\/wp-json\/wp\/v2\/categories?post=1213"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seciblog.pli.edu\/index.php\/wp-json\/wp\/v2\/tags?post=1213"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/seciblog.pli.edu\/index.php\/wp-json\/wp\/v2\/coauthors?post=1213"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}