Skip to main content
Page header background image

Legal Updates

New Guidance on SEC Cybersecurity Reporting Regulations

Privacy & Cybersecurity Update

The Securities and Exchange Commission's (SEC) new rule that requires companies to publicly disclose material cybersecurity incidents enters into force on December 18, 2023. The U.S. Department of Justice, acting through the Federal Bureau of Investigation (FBI), recently published a Policy Notice and Guidance on how companies that are subject to a cybersecurity incident can request permission to delay publicly disclosing the incident for “national security” or “public safety” reasons. It is important that organizations incorporate this FBI Guidance into their cybersecurity incident response plans (IRPs) as they could have significant impacts on their disclosure obligations and whether an organization’s response to a cyberattack is protected under the attorney-client privilege.

Background: SEC Cybersecurity Reporting Obligations

Beginning on December 18, 2023, many publicly traded companies will be required to file an “Item 1.05 Material Cybersecurity Incidents” Form 8-K to publicly report a “cybersecurity incident” that is “material.” The term “cybersecurity incident” is defined as “an unauthorized occurrence, or a series of related unauthorized occurrences, on or conducted through a [company’s] information systems that jeopardizes the confidentiality, integrity or availability of a [company’s] information systems or any information residing therein.” This definition may implicate a wide range of cybersecurity attacks, including network intrusion, data exfiltration, and ransomware.

The SEC indicated the determination on whether a cybersecurity incident is “material if there is a ‘substantial likelihood’ that a reasonable shareholder would consider it important in making an investment decision, or if it would have significantly altered the ‘total mix’ of information” that is made available to an investor.

Form 8-K is required to include (i) a description of the material aspects of the nature, scope, and timing of the incident and (ii) the material impact, or reasonably likely material impact, of the incident on the company, including its financial condition and results of operations. Companies should consider both qualitative and quantitative factors in assessing whether an incident’s impact is material, such as harm to a company’s reputation, customer or vendor relationships, competitiveness, or the possibility of litigation or regulatory investigations. Importantly, cybersecurity incidents on a third-party system may trigger the required Form 8-K disclosure and therefore “vendor management” must be a key component of an organization’s information security program and IRP.

Cybersecurity Incident Notification Timing

If an organization experiences a cybersecurity incident, it must submit its Form 8-K within four business days of determining that the incident is “material.” In turn, companies are required to determine whether such incident is material “without unreasonable delay” (see our previous bulletin on this “without unreasonable delay” framework). However, the SEC rules expressly state that a Form 8-K filing may be delayed in certain specified instances, including when the U.S. attorney general notifies the SEC in writing that it has determined that an immediate disclosure of a cybersecurity incident would pose a substantial risk to national security or public safety (a “National Security and Public Safety Delay”).

The SEC’s rule permits the attorney general to delay a material cybersecurity incident public disclosure 30 business days, with an option to delay it for an additional 30 business days. In extraordinary circumstances, the attorney general can delay this disclosure for an additional 60 business days due to substantial national security (but not public safety) risks. Delays, however, cannot exceed a total of 120 business days without an exemptive order from the SEC. Per the SEC rule, companies may submit a National Security and Public Safety Delay request directly to the FBI, or through the U.S. Secret Service (USSS), the Cybersecurity and Infrastructure Security Agency (CISA), the Department of Defense (DOD), and Sector Risk Management Agencies.

FBI Guidance on Delaying Cyber Incident Notification

On December 6, the attorney general and acting FBI published a Policy Notice on how companies can submit a National Security and Public Safety Delay request. The Policy Notice provides that its framework applies to all such requests, regardless of whether the request is the FBI’s first notice of the incident, or the request is made after the FBI is already aware of the incident, or a company is requesting a delay determination for the first time or an extension of an existing delay determination.

The Policy Notice indicates that to facilitate a National Security and Public Safety Delay request, organizations must submit their requests to CyWatch, which is a 24/7/365 cyber operation center within the federal government. More specifically, FBI Guidance states that to request a reporting delay, companies must send an email to the FBI (at a dedicated email address that is coming soon), and the email must address all of the following information:

  • The name of the impacted company.
  • Identify when the cyber incident occurred.
  • Identify when the impacted company determined the cyber incident is material.
  • Whether the impacted company already contacted the FBI regarding this incident, and if so, the names and field offices of the relevant FBI points of contact.
  • A description of the incident, including at minimum: the type of cybersecurity incident; the known or suspected intrusion vectors; the infrastructure or data affected by the incident; the operational impact on the company; any confirmed or suspected attribution of the threat actors; where the incident occurred; the company’s points of contact for this matter; and, whether the company previously submitted a delay request.

Once a National Security and Public Safety Delay request is received by the FBI, the FBI is responsible for “intaking” and documenting the request, coordinating checks of U.S. government national security and public safety equities, and referring information to the Justice Department. If companies do not make the National Security and Public Safety Delay request to the FBI concurrently with the materiality determination, the FBI will not process the request. The FBI encourages “victims” to engage the FBI before determining whether a cybersecurity incident is “material.”

Conclusion

The National Security and Public Safety Delay framework is especially narrow and does not align with many broader exceptions in state data breach notification laws, which allow for delays in incident reporting when it would interfere with or impede a federal, state, or local criminal investigation or would be inconsistent with the legitimate needs of a law enforcement agency. Yet, companies may need to invoke it based on their business sector or the type of cyberattack they are addressing. Accordingly, companies should review their cybersecurity IRP to identify the appropriate phases and mechanisms in which they (i) report a cybersecurity incident to compliance officers, legal teams, management, and board members, and (ii) analyze whether they need to, or should, submit a National Security and Public Safety Delay request. It is important to note that engaging with the federal authorities during a response to a cyberattack can have significant impacts on whether the response is protected under the attorney-client privilege.

This advisory bulletin may be reproduced, in whole or in part, with the prior permission of Thompson Hine LLP and acknowledgment of its source and copyright. This publication is intended to inform clients about legal matters of current interest. It is not intended as legal advice. Readers should not act upon the information contained in it without professional counsel.

This document may be considered attorney advertising in some jurisdictions.

© 2023 THOMPSON HINE LLP. ALL RIGHTS RESERVED.

Services