SEC Issues Statement and Interpretive Guidance on Public Company Cybersecurity Disclosures
On February 21, 2018, the Securities and Exchange Commission announced it had unanimously approved a statement and interpretive guidance to assist public companies in preparing disclosures about cybersecurity risks and incidents. This guidance expands upon the Division of Corporation Finance’s 2011 guidance regarding disclosure obligations related to cybersecurity risks and incidents. The release also addresses two topics not developed in the Staff’s 2011 guidance: the importance of cybersecurity policies and procedures and the application of insider trading prohibitions in the cybersecurity context.