← Back to feed
Breaches & RansomwareEmerging1 sourceApr 29, 2024 · 20:35via MIT News — Cybersecurity

Now corporate boards have responsibility for cybersecurity, too

Brief

A new ruling from the U. S. Securities and Exchange Commission (SEC), known as the Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure , went into effect last fall. The ruling requires public companies to disclose whether their boards of directors have members with cybersecurity expertise.

Specifically, registrants are required to disclose whether the entire board, a specific board member, or a board committee is responsible for the oversight of cyber risks; the processes by which the board is informed about cyber risks, and the frequency of its discussions on this topic; and whether and how the board or specified board committee considers cyber risks as part of its business strategy, risk management, and financial oversight.

Read more on MIT News — Cybersecurity