Published: 07 March 2024
Summary
The SEC cybersecurity disclosure rules are pushing organizations to reevaluate their cybersecurity program governance and risk management. Many executive leaders, including those overseeing legal and security functions, have begun implementing changes, with more actions expected.
Included in Full Research
Overview
Key Findings
Organizations have already begun implementing governance and risk management changes in response to the Securities and Exchange Commission’s (SEC’s) cybersecurity disclosure rules.
Continual adaptation and refinement of these practices are expected, particularly as best practices develop from organizations’ cybersecurity governance and risk management disclosures.
Recommendations
Ensure CISOs are getting time with the board or committee responsible for overseeing cybersecurity risk. The absence of interactions with CISOs can limit meaningful discussion about cybersecurity priorities, strategies and risk management, which can hinder the organization’s progress in maturing its cybersecurity program. This lack of communication can contribute to the failure of the board’s
Clients can log in to view the entire
document.