This website collects cookies to deliver better user experience. Cookie Policy
Accept
Sign In
The Wall Street Publication
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Reading: Businesses Seek to Soften SEC Cyber Rules
Share
The Wall Street PublicationThe Wall Street Publication
Font ResizerAa
Search
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Have an existing account? Sign In
Follow US
© 2024 The Wall Street Publication. All Rights Reserved.
The Wall Street Publication > Blog > Tech > Businesses Seek to Soften SEC Cyber Rules
Tech

Businesses Seek to Soften SEC Cyber Rules

Editorial Board Published May 11, 2022
Share
Businesses Seek to Soften SEC Cyber Rules
SHARE

Companies including Chevron Corp. , Quest Diagnostics Inc. and Ernst & Young LLP are pushing to narrow proposed cybersecurity rules from the Securities and Exchange Commission in the private sector’s latest attempt to shape a growing array of regulations by Washington.

Contents
Newsletter Sign-upWSJ Pro Cybersecurity

In comments on rules proposed by the SEC, businesses in recent days have urged the agency to harmonize its deadline of four business days to disclose security incidents with similar rules from other agencies. They also warned public disclosures could result in new compliance costs, additional confusion while responding to breaches and hits to their stock prices.

Some companies and security chiefs said in interviews and public comments on the proposals that they are broadly supportive of an SEC reporting regime, and provisions in the draft rules that help to fortify cybersecurity risk management.

“The regulators are saying that they need this consistent view of risk so that they can compare and contrast, and ensure that they’re delivering effective oversight of the organizations that they regulate, that they can calibrate that digital risk,” said David Reilly, who was chief information officer at Bank of America Corp.’s global banking and markets unit until November.

Listed companies have long been required to disclose risks and incidents they deem material to investors. But SEC officials have said in recent years that disclosures of cyber incidents have been spotty, necessitating more specific regulations for incident-response planning, board oversight and reporting of material hacks or breaches.

The SEC, which didn’t immediately respond to a request for comment, has taken a more aggressive approach to rulemaking under Chairman Gary Gensler.


Newsletter Sign-up

WSJ Pro Cybersecurity

Cybersecurity news, analysis and insights from WSJ’s global team of reporters and editors.


Many companies and lobbying groups filing comments on the proposals by Monday’s deadline want the SEC to coordinate its approach with a new law requiring critical-infrastructure operators to confidentially report incidents to the Cybersecurity and Infrastructure Security Agency within 72 hours. That statute aims to help U.S. officials exchange information with the private sector to respond to cyberattacks.

The SEC’s proposed rules, on the other hand, would require listed firms to file public reports in a bid to provide more information to investors.

Lobbying groups including the National Association of Manufacturers and the Chamber of Commerce, which both prefer CISA’s confidential approach, warn of an overlapping set of reporting requirements that could lead to risks such as litigation or additional cyber threats.

“We oppose the rulemaking in its current form,” said Christopher Roberti, senior vice president for cyber, space and national security policy at the U.S. Chamber of Commerce. “We’d like to see [the SEC] withdraw it or shelve it.”

Energy giant Chevron, meanwhile, warned in a comment last week that the SEC’s proposed public reporting regime could also complicate CISA’s attempt to analyze data shared by critical infrastructure firms and share it across the public and private sectors. Chevron and medical test company Quest Diagnostics called for the SEC to allow companies working with law enforcement to investigate incidents to delay their reporting.

CISA declined to comment. The SEC also declined to comment.

Others warned that public reports could provide hackers information while attacks are in progress. “If a registrant discloses that it is currently the victim of a material cyber incident, that would tip off the malicious actor that the registrant is aware they’re in the victim company’s systems,” said Henry Young, policy director at industry lobbying group BSA, The Software Alliance, which represents commercial software makers. That may prompt hackers to steal data faster, or speed up timelines on attacks such as ransomware strikes once tipped off, he said.

Ernst & Young and others also took issue with the SEC’s suggestion that companies report aggregate incidents once their collective impact is deemed material. Jerry Perullo, former chief information security officer of New York Stock Exchange owner Intercontinental Exchange Inc., said the idea doesn’t reflect how cyber teams work to counter near-constant attempted cyberattacks, such as phishing emails.

“Should a security organization have some situational awareness of trends in what’s hitting them? Yes,” he said. “But that’s threat intelligence. You certainly don’t have to be calling up the SEC when something like this happens.”

However, intrusions can often start with small incidents, and what seems like an innocuous event may herald a more severe breach later, said Cyrus Vance Jr. , partner and global chair of law firm Baker McKenzie’s cybersecurity practice.

“I think it’s strong rulemaking,” said Mr. Vance, a former district attorney in Manhattan until the end of last year.

The proposed rule comes as Congress and the Biden administration have unveiled a raft of new cyber regulations after a series of disruptive cyberattacks in recent years. In addition to the SEC’s forthcoming rules for listed companies, the agency in February proposed regulations that would require investment funds and advisers to report incidents within 48 hours.

—Kim S. Nash contributed to this article.

Write to David Uberti at david.uberti@wsj.com and James Rundle at james.rundle@wsj.com

Corrections & Amplifications
Christopher Roberti is the senior vice president for cyber, space and national security policy at the U.S. Chamber of Commerce. An earlier version of this article incorrectly referred to him as its senior vice president for cyber, intelligence and supply chain security policy. (Corrected on May 11.)

Copyright ©2022 Dow Jones & Company, Inc. All Rights Reserved. 87990cbe856818d5eddac44c7b1cdeb8

TAGGED:Tech NewsWall Street Publication
Share This Article
Twitter Email Copy Link Print
Previous Article Coinbase Shares Slide Further on Deep Loss Coinbase Shares Slide Further on Deep Loss
Next Article Cryptocurrency TerraUSD Plunges as Investors Bail Cryptocurrency TerraUSD Plunges as Investors Bail

Editor's Pick

UnitedHealth Group names new CEO, shares slide

UnitedHealth Group names new CEO, shares slide

UnitedHealth Group on Tuesday mentioned Chairman Stephen Hemsley will return to the helm of the well being care conglomerate, succeeding…

By Editorial Board 3 Min Read
Justin Baldoni Shares Emotional Message Amid Blake Vigorous Lawsuit
Justin Baldoni Shares Emotional Message Amid Blake Vigorous Lawsuit

Studying Time: 3 minutes Justin Baldoni has damaged his silence. In a…

5 Min Read
Trump yanks controversial US legal professional decide after intense backlash
Trump yanks controversial US legal professional decide after intense backlash

It’s a nasty day to be a Donald Trump nominee. Simply 24…

4 Min Read

Oponion

Jury Hears Closing Arguments in Trial of Nikola Founder Milton

Jury Hears Closing Arguments in Trial of Nikola Founder Milton

The trial of Nikola Corp. founder Trevor Milton concluded Thursday…

October 13, 2022

Millennium, Capula, Tudor pile bitcoin ETFs into portfolios

Predominant Road Asset Administration chief funding…

November 18, 2024

Congress’ to-do record grows whereas on the marketing campaign path

As Congress enters a crucial stretch…

October 21, 2024

ClassicSavages on Ethereum Classic

What is a ClassicSavage? A ClassicSavage…

December 16, 2021

Dramatic particulars emerge after climber survives 400-foot fall that killed 3 mates in Washington state

A rock climber who fell a…

May 14, 2025

You Might Also Like

The Finest LED Face Masks and Pink-Gentle Remedy for At-Dwelling Therapies
Tech

The Finest LED Face Masks and Pink-Gentle Remedy for At-Dwelling Therapies

Finest Cooling LED Face Masks{Photograph}: SHARKShark CryoGlow Pink Blue & Infrared iQLED Face Masks & Underneath Eye CoolingThe Shark CryoGlow…

4 Min Read
Which Google Pixel Telephone Ought to You Purchase?
Tech

Which Google Pixel Telephone Ought to You Purchase?

Google Pixel telephones are our favourite Android telephones right here at WIRED and have been for a number of years.…

6 Min Read
The Finest Cat Toys for Your Furry Buddy
Tech

The Finest Cat Toys for Your Furry Buddy

Cats are stunning, attention-grabbing, bizarre creatures. They're additionally very choosy. Discovering toys that they're going to truly play with is…

16 Min Read
KLN GROUP INC. Revolutionizes Auto Transport with Technology-Driven Logistics Solutions Driving Innovation and Efficiency in High-End and Classic Car Shipping
TechTrending

KLN GROUP INC. Revolutionizes Auto Transport with Technology-Driven Logistics Solutions Driving Innovation and Efficiency in High-End and Classic Car Shipping

Chicago, IL – 03.11.2025 – KLN GROUP INC., a leader in high-end and classic vehicle transportation, is transforming the car…

3 Min Read
The Wall Street Publication

About Us

The Wall Street Publication, a distinguished part of the Enspirers News Group, stands as a beacon of excellence in journalism. Committed to delivering unfiltered global news, we pride ourselves on our trusted coverage of Politics, Business, Technology, and more.

Company

  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • WP Creative Group
  • Accessibility Statement

Contact

  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability

Term of Use

  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices

© 2024 The Wall Street Publication. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?