The U.S. Securities and Exchange Commission (SEC) has proposed rule changes that would require publicly traded companies to report data breaches and other cybersecurity incidents within four days of being deemed a material incident.
See also: Russian hackers strike with ransomware attack using open-source tools

Under recently proposed amendments to the applicable rules, listed companies will be required to provide information in periodic reporting filings regarding the policies, procedures implemented, and measures taken to identify and manage cybersecurity risks on Form 8-K.
The amended rules will mandate companies to provide updates on previously reported security breaches.
See also: REvil ransomware member extradited to US to stand trial for Kaseya attack
The SEC wants public companies to regularly share disclosures about their management's role in implementing cybersecurity procedures and policies, as well as about their board's cybersecurity expertise and oversight of cybersecurity risk.
Timely disclosure to inform investors
These proposed amendments are designed to provide investors with timely notifications of security breaches affecting publicly traded companies and to better inform them about their cybersecurity management and strategy.
If the rules are revised as the SEC wants, the new regulations [PDF] would require disclosure of the following information about violations (if the information is available when 8-K forms are filed):
- When was the incident discovered and whether it is ongoing?
- Brief description of the nature and extent of the incident
- If any data was stolen, modified, intercepted or used for any other unauthorized purpose
- The impact of the event on the registrant's operations
- Whether the registrant has remediated or is currently remediating the incident.

See also: Malware targets supporters and members of Ukraine's IT Army
However, companies affected by a breach are not expected to disclose technical information about their planned response to the incident or details about potential vulnerabilities that will affect their response or recovery from the incident.
Information source: bleepingcomputer.com
