Skip to content
Search

Latest Stories

NatSecEdge
cipherbrief

Welcome! Log in to stay connected and make the most of your experience.

Input clean

The Days of Responsible Cybersecurity are Finally Here

OPINION — The days of cyber negligence are numbered. While nobody can expect perfect cybersecurity, a vast supermajority of the painful breaches we learn about are the result of known vulnerabilities, lackadaisical security practices and poor cyber hygiene — things that could have been avoided with diligence and care. It's an attitude that exudes fiduciary negligence and a blatant disregard for shareholders, partners, and customers.  

The Securities and Exchange Commission’s proposed rule on Cybersecurity Risk Management, Strategy, Governance and Incident Disclosure will trigger dramatic and long-overdue changes in how businesses disclose their cybersecurity policies, procedures, oversight and governance. It will force leaders to treat cybersecurity risk as a business risk — something responsible executives started doing a long time ago — and provide shareholders, customers, partners and the public with essential information needed to make responsible decisions.


The proposed rule requires public companies to disclose their policies and procedures for identifying and managing cybersecurity risks. It also requires disclosure of the oversight role and cybersecurity expertise of public companies’ leadership and board of directors over their cybersecurity risk assessment program. 

Before even reading the comments, I can hear all of those trying to shirk their responsibilities go on and on about the invasiveness of these draconian measures and the ill effects of government interference in corporate affairs and free markets. But free markets cannot work without transparency and informed decision making. Such measures will root out secrecy in the disclosure process and help us all understand which organizations are respecting the duty of care that they owe their customers and stakeholders. 



What do former NSA General Counsel Glenn Gerstell, former Executive Director of the Cyberspace Solarium Commission Adm. Mark Montgomery (Ret.) and other cyber leaders think about the proposed rule?  Read The National Security Implications of new Rules of the Road for Cyber – comments on the SEC proposal by Principal Members of The Cyber Initiatives Group



Cybersecurity breaches damage a company’s financial position. In addition to the costs of remediation and loss of customers, revenue and reputation, there are risks of shareholder lawsuits, customer lawsuits, increases in insurance premiums and increased scrutiny from auditors and regulators, distraction of management, and significant expenses. 

Former NSA Director Keith Alexander called cyber espionage, “the greatest transfer of wealth in history.” Cybercrime costs the US economy over $100 billion per year, and cost estimates of intellectual property theft surpass $250 billion per year.  This is a real-world risk, and investors have a right to know whether or not a public company has robust cybersecurity risk assessment practices and policies in place so they can factor that risk into their investment decisions.

Today’s threat landscape is highly dynamic and requires organizations to continuously assess and defend against new tactics, techniques and procedures used by threat actors and cyber criminals. Continuous cyber risk assessments must be a foundational and strategic function. It is to the benefit of companies and shareholders to ensure that adequate cybersecurity controls and defenses are implemented. Requiring greater transparency of cyber risk practices and oversight promotes stronger cybersecurity governance and accountability among corporate leaders and boards and, ultimately, will produce a healthier market equilibrium.

While there are still details to be ironed out, the SEC’s proposed rule is an enormous step in the right direction, and I hope the SEC doesn’t get derailed by those advocating for status quo.

Discuss this issue live on Wednesday, May 25 at The Cyber Initiatives Group’s Spring Summit.  Register for your virtual seat today.

This piece was originally published on the Tenable blog and is republished with permission from the author.

Save Your Seat

Related Articles

The UN Cybercrime Convention is Digital Solidarity's First Real Test

OPINION — Earlier this year, the United Nations Ad Hoc Committee to Elaborate a Comprehensive International Convention on Countering the Use of [...] More

Unpacking the National Cyber Director's Posture Report

OPINION / CYBER INITIATIVES GROUP — The 2024 Report on the Cybersecurity Posture of the United States, released by the Office of the National Cyber [...] More

America's Food Supply Has a Cyber Problem

OPINION — Fine-tuned sensors let farmers know which fields need more water and which crops need more fertilizer. But today, a hacker halfway around [...] More

Hackers are Taking Advantage of Gaps in U.S. Cybersecurity Policy

OPINION — When you press the power button on your computer, it turns on because a specialized code called firmware turns this stimulus into a signal [...] More

A New Year Means Further Transformative Shifts in Cyber

EXPERT PERSPECTIVE — 2023 saw the start of a transformative shift in cybersecurity, bringing both new opportunities and new challenges to the [...] More

To Beat China and Russia in Cyberspace, Change the Game

OPINION — Recent U.S. threat assessments have made it clear that the defense industrial base (DIB), critical infrastructure providers, and other [...] More