No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

SEC’s New Cybersecurity Rules Have Global Reach

Recently adopted regulations expected to impact hundreds of companies based outside the US

by Jordan Rae Kelly and Adriana Villasenor
August 22, 2023
in Compliance, Cybersecurity
An emblem on the SEC building

The SEC’s long-awaited cybersecurity rules for publicly traded companies have had, as expected, a huge impact in the United States. But the effect won’t stop at U.S. borders, and as FTI Consulting’s Jordan Rae Kelly and Adriana Villasenor explain, foreign companies listed on American stock exchanges should take note.

As a result of new cybersecurity rules adopted by the SEC, any public company doing business in the United States will need to assess its cybersecurity stance to make sure it is in compliance. Depending on their cyber maturity, some may already be headed in that direction and simply need to refine their adherence to the previous 2018 rules. 

Others may need to make significant adjustments or changes to their cybersecurity strategy. The new rules could have a profound impact on risk management programs through material incident reporting and board oversight and accountability requirements.

For companies headquartered abroad but operating in the United States, especially those with a less mature cyber stance in their home countries, the amendments could be a real game-changer for two reasons: 1) they present an opportunity for the company to strengthen its cybersecurity infrastructure at home by aligning with U.S. standards, commonly seen as the highest in the world; and 2) this could be a market differentiator for the organization.

This is where the new rules have international reach. Companies that otherwise are not required to prioritize cybersecurity, often due to a lack of existing regulation where they are headquartered, now face the demand of complying with the SEC’s rules.

The same concept applies to U.S.-based companies with international operations in less cyber mature markets. These companies will also be required to disclose incidents with the potential for a material impact, even if the incident occurs outside of the U.S.

In both instances, the location where the incident took place is irrelevant if the company is listed in the U.S. It might be cliché, but it is nevertheless true in this situation — companies are only as strong as their weakest link. This means global companies will need to develop comprehensive cybersecurity programs that have oversight across the entire enterprise and are not siloed by country.

While this may sound like a tall task, companies that proactively decide to bolster their cybersecurity infrastructure will be better prepared to comply with the SEC rules and will also stand out among their peers, especially in regions where cybersecurity is not prioritized. By demonstrating compliance and an active desire to protect customer and organization information, companies can be viewed more favorably by stakeholders, investors and customers, adding market value.    

sec building exterior
Cybersecurity

SEC’s New Cybersecurity Rules Are Finally Out. Are They as Strict as Many Feared?

by Alisa Chestler
August 1, 2023

It’s official. Last week, the SEC issued rules requiring public companies to report what the agency calls “material” cybersecurity incidents within four business days. Baker Donelson’s Alisa Chestler breaks down what’s in the new rules and explores what companies should do from here.

Read moreDetails

The intent of the rules

The new rules are significant, and they require companies to concentrate efforts in three primary areas:

Increased transparency for investors

Organizations must report material cybersecurity incidents and data breaches within four days. They will also need to provide information and updates regarding previously disclosed incidents on a quarterly basis.

Enterprise risk management gains importance

Organizations must adopt controls to mitigate cyber risk. The required key controls include security risk assessments, access controls, continuous monitoring, detection and response, vulnerability management and vendor risk management.

Boards that are fit for the future

Organizations are required to disclose summary descriptions of their cyber risk and how much oversight the board and management have on cybersecurity risk. This includes descriptions of policies and procedures for the identification and management of cyber risks.

Regulators, governments and investors are looking closely at an organization’s cybersecurity governance and, in some cases, demanding oversight at the board level. In today’s digitized business environment, the existential threat of an incident means cybersecurity must be proactively managed, factored into all decisions and treated like any other business risk.

Get ready now

Integrating cybersecurity into corporate governance is the key to compliance and provides greater flexibility as new rules come down the pike. The starting place for integration for any organization lies in these critical areas:

Training and communication

Organizations will need to update how they prepare and process disclosure forms to include the relevant information related to cybersecurity governance, risk management and data breaches. Is the board up to speed on current cybersecurity threats and emerging trends? Is it working in concert with other stakeholders on priorities, security initiatives and investments? Those operating in markets without robust cybersecurity regulation often do not properly manage cybersecurity risks because they are unaware they exist, until they experience a cyber attack directly. Do boards have knowledge regarding how cybersecurity programs at their subsidiaries are performing?

Cybersecurity program assessment

An organization must have a thorough understanding of its cybersecurity stance — across all company locations — prior to implementing or changing processes. Are security policies current? How are they managed, implemented and enforced? Penetration testing can go a long way: Knowing where your critical assets are at risk and where your attackers might come from — whether inside or outside the organization — is key to strengthening your infrastructure.

Conclusion

No matter where an organization is headquartered, the SEC rules will have a major impact on all publicly traded companies in the United States. Seizing the moment now to factor cybersecurity into corporate governance will better position companies to walk in the SEC’s light.

Kyung Kim contributed to this report.

 


Tags: SEC
Previous Post

Continuous Compliance Keeps Organizations From Focusing on the Past

Next Post

Pay Transparency — It’s Not Just Good for Workers

Jordan Rae Kelly and Adriana Villasenor

Jordan Rae Kelly and Adriana Villasenor

Jordan Rae Kelly is a senior managing director and the head of cybersecurity for the Americas at FTI Consulting. She has more than 15 years of experience coordinating incident response and managing cyber policy planning. Before joining FTI Consulting, Kelly served as the director for cyber incident response on the National Security Council at the White House.
Adriana Villasenor is a senior director in FTI Consulting’s cybersecurity practice and is based in New York. She has 18 years of experience managing crisis, cyber and ESG communications for publicly traded and privately held organizations, from billion-dollar consumer brands to global financial technology firms.

Related Posts

sec building sign

What to Expect From Atkins-Led SEC

by Jaclyn Jaeger
May 6, 2025

Former Bush-era commissioner returns with mission to streamline regulations and enhance capital markets

news roundup new

Bang for the Buck: Regulators Pivot to Fewer But Higher-Value Enforcement Actions

by Staff and Wire Reports
April 11, 2025

CCI staff share recent surveys, reports and analysis on risk, compliance, governance, infosec and leadership issues. Share details of your...

freshly picked cherries

Fair Dealing or Foul Play? Preventing Trade Allocation Pitfalls

by Chris Hoyle and Howard Scheck
March 18, 2025

Investment advisers face heightened scrutiny of their allocation practices as regulators deploy advanced analytics to detect favoritism

imessage on phone

The Hidden Compliance Risks Lurking in Your iMessages

by Harriet Christie
March 3, 2025

How end-to-end encryption and lack of native archiving tools complicate regulatory compliance

Next Post
a clear piggybank holding coins

Pay Transparency — It’s Not Just Good for Workers

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights