No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

SEC’s New Cybersecurity Rules Have Global Reach

Recently adopted regulations expected to impact hundreds of companies based outside the US

by Jordan Rae Kelly and Adriana Villasenor
August 22, 2023
in Compliance, Cybersecurity
An emblem on the SEC building

The SEC’s long-awaited cybersecurity rules for publicly traded companies have had, as expected, a huge impact in the United States. But the effect won’t stop at U.S. borders, and as FTI Consulting’s Jordan Rae Kelly and Adriana Villasenor explain, foreign companies listed on American stock exchanges should take note.

As a result of new cybersecurity rules adopted by the SEC, any public company doing business in the United States will need to assess its cybersecurity stance to make sure it is in compliance. Depending on their cyber maturity, some may already be headed in that direction and simply need to refine their adherence to the previous 2018 rules. 

Others may need to make significant adjustments or changes to their cybersecurity strategy. The new rules could have a profound impact on risk management programs through material incident reporting and board oversight and accountability requirements.

For companies headquartered abroad but operating in the United States, especially those with a less mature cyber stance in their home countries, the amendments could be a real game-changer for two reasons: 1) they present an opportunity for the company to strengthen its cybersecurity infrastructure at home by aligning with U.S. standards, commonly seen as the highest in the world; and 2) this could be a market differentiator for the organization.

This is where the new rules have international reach. Companies that otherwise are not required to prioritize cybersecurity, often due to a lack of existing regulation where they are headquartered, now face the demand of complying with the SEC’s rules.

The same concept applies to U.S.-based companies with international operations in less cyber mature markets. These companies will also be required to disclose incidents with the potential for a material impact, even if the incident occurs outside of the U.S.

In both instances, the location where the incident took place is irrelevant if the company is listed in the U.S. It might be cliché, but it is nevertheless true in this situation — companies are only as strong as their weakest link. This means global companies will need to develop comprehensive cybersecurity programs that have oversight across the entire enterprise and are not siloed by country.

While this may sound like a tall task, companies that proactively decide to bolster their cybersecurity infrastructure will be better prepared to comply with the SEC rules and will also stand out among their peers, especially in regions where cybersecurity is not prioritized. By demonstrating compliance and an active desire to protect customer and organization information, companies can be viewed more favorably by stakeholders, investors and customers, adding market value.    

sec building exterior
Cybersecurity

SEC’s New Cybersecurity Rules Are Finally Out. Are They as Strict as Many Feared?

by Alisa Chestler
August 1, 2023

It’s official. Last week, the SEC issued rules requiring public companies to report what the agency calls “material” cybersecurity incidents within four business days. Baker Donelson’s Alisa Chestler breaks down what’s in the new rules and explores what companies should do from here.

Read moreDetails

The intent of the rules

The new rules are significant, and they require companies to concentrate efforts in three primary areas:

Increased transparency for investors

Organizations must report material cybersecurity incidents and data breaches within four days. They will also need to provide information and updates regarding previously disclosed incidents on a quarterly basis.

Enterprise risk management gains importance

Organizations must adopt controls to mitigate cyber risk. The required key controls include security risk assessments, access controls, continuous monitoring, detection and response, vulnerability management and vendor risk management.

Boards that are fit for the future

Organizations are required to disclose summary descriptions of their cyber risk and how much oversight the board and management have on cybersecurity risk. This includes descriptions of policies and procedures for the identification and management of cyber risks.

Regulators, governments and investors are looking closely at an organization’s cybersecurity governance and, in some cases, demanding oversight at the board level. In today’s digitized business environment, the existential threat of an incident means cybersecurity must be proactively managed, factored into all decisions and treated like any other business risk.

Get ready now

Integrating cybersecurity into corporate governance is the key to compliance and provides greater flexibility as new rules come down the pike. The starting place for integration for any organization lies in these critical areas:

Training and communication

Organizations will need to update how they prepare and process disclosure forms to include the relevant information related to cybersecurity governance, risk management and data breaches. Is the board up to speed on current cybersecurity threats and emerging trends? Is it working in concert with other stakeholders on priorities, security initiatives and investments? Those operating in markets without robust cybersecurity regulation often do not properly manage cybersecurity risks because they are unaware they exist, until they experience a cyber attack directly. Do boards have knowledge regarding how cybersecurity programs at their subsidiaries are performing?

Cybersecurity program assessment

An organization must have a thorough understanding of its cybersecurity stance — across all company locations — prior to implementing or changing processes. Are security policies current? How are they managed, implemented and enforced? Penetration testing can go a long way: Knowing where your critical assets are at risk and where your attackers might come from — whether inside or outside the organization — is key to strengthening your infrastructure.

Conclusion

No matter where an organization is headquartered, the SEC rules will have a major impact on all publicly traded companies in the United States. Seizing the moment now to factor cybersecurity into corporate governance will better position companies to walk in the SEC’s light.

Kyung Kim contributed to this report.

 

Tags: SEC
Previous Post

Continuous Compliance Keeps Organizations From Focusing on the Past

Next Post

Pay Transparency — It’s Not Just Good for Workers

Jordan Rae Kelly and Adriana Villasenor

Jordan Rae Kelly and Adriana Villasenor

Jordan Rae Kelly is a senior managing director and the head of cybersecurity for the Americas at FTI Consulting. She has more than 15 years of experience coordinating incident response and managing cyber policy planning. Before joining FTI Consulting, Kelly served as the director for cyber incident response on the National Security Council at the White House.
Adriana Villasenor is a senior director in FTI Consulting’s cybersecurity practice and is based in New York. She has 18 years of experience managing crisis, cyber and ESG communications for publicly traded and privately held organizations, from billion-dollar consumer brands to global financial technology firms.

Related Posts

Freshfields Trends & Updates From Proxy Season 2026

2026 Proxy Season Trends & Updates

by Corporate Compliance Insights
July 17, 2026

A new report from Freshfields examines the trends and regulatory developments that defined the 2026 proxy season, from a sharp...

sec building sign

Making It Easier to Go Public Isn’t the Same as Making It Easier to Be Public

by Kyle Jeziorski
July 17, 2026

Investors won’t ignore a company’s lack of quarterly reporting and the controls that come along with it

scotus building

SCOTUS Broadens White House Influence Over ‘Independent’ Agencies

by Jennifer L. Gaskin
July 8, 2026

In part of a flurry of end-of-term activity, the Supreme Court in late June overturned a 90-year-old precedent and held...

sec building with color treatment

Supreme Court Rules SEC May Claw Back Ill-Gotten Gains Regardless of Investor Loss

by Ferdose al-Taie, Lindsay E. Ray and J. Tyler Wampler
June 19, 2026

The Sripetch decision eliminates a meaningful defense previously available to SEC defendants

Next Post
a clear piggybank holding coins

Pay Transparency — It’s Not Just Good for Workers

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights