Skip to content
SBA

SBA

Business Investment News

  • American Business News
    • Best Business Newspaper
    • Business Breaking News
    • Business Card Companies
    • Business Current News
    • Business Company News
  • Business Financial News
    • Business Funding Website
    • Business Fundraising Sites
    • Business Google News
    • Business Information Companies
    • Business Information Website
  • Business Intelligence Homepage
    • Business Intelligence Logo
    • Business Investment News
    • Business Magazine Articles
    • Business Magazine Online
    • Business Market News
  • Business Money News
    • Business News Online
    • Business News Sources
    • Business Pages Online
    • Business Periodical Online
    • Business Phone Company
  • General
  • Toggle search form
  • VerifyMe to Report Fourth Quarter 2022 Fiscal Effects on March 28, 2023 Business Intelligence Homepage
  • What to know on new artificial intelligence company Business Intelligence Homepage
  • Exclusive: Goldman Sachs to cut asset management investments that weighed on earnings Business Financial News
  • Capital Small Finance Bank eyes Rs 14,000 crore of total business in FY24 Business Financial News
  • Beyond the tech hype, how healthy is American business? American Business News
  • Factiva – Global News Monitoring & Search Engine Business Intelligence Homepage
  • American Express – American Express Honors Asian Pacific American Small Business Owners and Grant Recipients American Business News
  • Ukraine Raising Funds for Strike Force of 1,000 Exploding Drones Business Intelligence Homepage

Time is Short – Reporting your Data Breach

Posted on August 1, 2023 By admin

Over the past years, hotel companies – including brands, managers and owners – have increasingly sought the benefit of access to public markets and, in doing so, have become subject to the registration and disclosure requirements of the United States Securities Act and Securities Exchange Act. In doing so, these companies need to comply with a broad variety of detailed regulations addressing their disclosure and reporting obligations. The Securities Exchange Commission recently adopted regulations which will have an impact on publicly traded hotel companies that suffer a data breach.

Breach Notifications for the Past 20 Years. Ever since California became the first state to require companies to notify their customers of data breaches in 2003, the time between the date a breach was discovered and the time the breach was reported has been an issue of contention. Early reporting gives consumers a leg up in protecting their personal information, and lets investors, vendors and customers of companies know if key business information has been compromised. At the same time, companies want as much time as possible to investigate a breach, understand what happened, and provide accurate information – companies that give early notice often have to give multiple notices as more information becomes available, and may even find that the original notice wasn’t necessary. Regardless, lawsuits against companies that have suffered data breaches almost universally point to the gap in time between the discovery and notification of a breach.

The SEC Acts. Regulators have stepped in and identified time frames for public notification of a data breach. Most recently, the Securities Exchange Commission issued a final rule that reduces the time for reporting companies (companies whose securities are registered with the SEC) to disclose cyberattacks publicly. As has been widely reported, with some exceptions, a company that is the victim of a cyberattack now has four days to publicly disclose the impact of the attack. Cyberattacks that involve the theft of intellectual property, a business interruption or reputational damage will likely require disclosure under the regulations.

The rules were proposed last year and contested by trade organizations and businesses, arguing that four days is inadequate to identify the nature and scope of a breach, and would be as likely to disclose inaccurate information as it would to benefit consumers and shareholders.

In contrast, the SEC, in adopting the new regulation, cited the new rule as enhancing transparency into cyber threats after years of attacks against businesses by criminal gangs and, most significantly, groups backed by nation states. The SEC also saw this as an opportunity to address gaps in existing cybersecurity disclosures.

Gaps in Disclosure. Because there are a side variety of laws and rules governing disclosure, there is little consistency in the timing or content of breach notifications. Companies that report incidents provide different amounts of detail about the impact and their response to it. Some cyber incidents aren’t reported in a timely manner, while others aren’t disclosed at all. Christopher Hetner, a former cybersecurity adviser at the SEC, who at the National Association of Corporate Directors, said, “The outcome of this rule will be to create more normalcy across disclosures.”

Arguments against the Regulation. The tight timeframe for disclosure raises concerns. The brief period for making incident disclosures could leave investors with information that isn’t accurate. The rules allow a company to update its incident disclosure with added information that was unavailable at first, but that also could create consumer and shareholder confusion.

The regulation is also unclear in defining how an incident would become material and how much detail will be required in public filings. This is a particular issue, since four days is unlikely to be adequate to collect and verify meaningful information about a security incident.

Third Party Risks. The regulation also will require companies will also have to create stronger reporting relationships with vendors. Over the past several years, the cyberattack risks raised in the supply chain of information management has become key, and unless vendors (and all of the parties in the vendors’ supply chain) cooperate promptly, a reporting company may be unable to meet the requirements of the new rule.

Annual Reporting. An issue that has not been widely reported is the requirement that companies must describe in their annual report, what processes, if any, a company has in place to assess, identify and manage material risks form cybersecurity threats “in sufficient detail for a reasonable investor to understand those processes.” Combined with the SEC’s “plain language” mandate, this requirement alone might be a significant task.

Companies can deal with these new regulations by creating, implementing, testing and updating strong cybersecurity incident response plans. When a company has 96 hours to report publicly a cybersecurity incident, it cannot waste time trying to create a playbook to respond; the playbook must be in place and accurate, and the necessary parties must have the “muscle memory” to know how to respond, not only to respond directly to the breach, but to comply with new and potentially burdensome regulations. 

link

Business Company News Tags:breach, data, Reporting, Short, Time

Post navigation

Previous Post: How can financial disclosures support sustainable business?
Next Post: Clive Humby – data can predict nearly everything about running a business

Related Posts

  • Symend, one of Calgary’s top tech firms, cuts workforce by 25% Business Company News
  • DNA Extraction Kits Market Strategies 2023: Business Insights, Top Companies, Latest Trends and Growth Predictions 2030 Business Company News
  • medZERO Prepares for National Growth; Adds to Advisory Board With a Cadre of Six Leaders in Healthcare, Employee Benefits, and Health Plan Business. Business Company News
  • These 200 companies are leading the clean economy in 2023 Business Company News
  • What the Most Productive Companies Do Differently Business Company News
  • Leading 5 Approaches Info Roles Will Adjust in 2023 Business Company News

Recent Posts

  • Today’s news: Trending business stories for September 28, 2023
  • Companies Can Unleash the Power of Business Credit Reports with MCB Business Credit
  • Menendez scandal may stymie flood insurance, other Senate Banking business
  • China still a key market, US businesses say, but hope dims for improved prospects
  • Billions of dollars in western profits trapped in Russia

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • August 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • August 2021
  • January 2021
  • September 2020
  • October 2019
  • November 2018
  • October 2018
  • September 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • June 2017
  • May 2017
  • April 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015

Categories

  • Advertising & Marketing
  • American Business News
  • Arts & Entertainment
  • Auto & Motor
  • Best Business Newspaper
  • Business
  • Business
  • Business Breaking News
  • Business Card Companies
  • Business Company News
  • Business Current News
  • Business Financial News
  • Business Funding Website
  • Business Fundraising Sites
  • Business Google News
  • Business Information Companies
  • Business Information Website
  • Business Intelligence Homepage
  • Business Intelligence Logo
  • Business Investment News
  • Business Magazine Articles
  • Business Magazine Online
  • Business Market News
  • Business News Online
  • Business News Sources
  • Business Pages Online
  • Business Periodical Online
  • Business Phone Company
  • Business Products & Services
  • Clothing & Fashion
  • Employment
  • General
  • Health & Fitness
  • Health Care & Medical
  • Home Products & Services
  • Internet Services
  • Personal Product & Services
  • Real Estate

Pages

  • Advertise with Us
  • Contact Us
  • Disc Policy & TOS
  • sitemap

Visit Us

Home Design Software
  • Agile & Business Business Intelligence Logo
  • 4 Artists Who Are Now Performing Veiled Clothing & Fashion
  • Practical and Helpful Tips: Dogs Arts & Entertainment
  • How to Write a Company Profile (Plus Samples and Templates to Aid You) Business Information Companies
  • Motor Insurance Market Outlook: Market Size, Major Business Company News
  • EVI Industries Reports Record Results for Second Quarter of Fiscal 2023 Business Intelligence Homepage
  • Are we on the brink of a corporate credit crisis? American Business News
  • The entire world struggles to forecast money fallout from California bank collapse Business Financial News

Copyright © 2023 SBA.

Powered by PressBook News WordPress theme

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
Go to mobile version