Advertisement
Canada markets closed
  • S&P/TSX

    22,059.03
    -184.99 (-0.83%)
     
  • S&P 500

    5,567.19
    +30.17 (+0.54%)
     
  • DOW

    39,375.87
    +67.87 (+0.17%)
     
  • CAD/USD

    0.7332
    -0.0015 (-0.20%)
     
  • CRUDE OIL

    83.44
    -0.44 (-0.52%)
     
  • Bitcoin CAD

    79,651.38
    +2,242.08 (+2.90%)
     
  • CMC Crypto 200

    1,208.38
    -0.32 (-0.03%)
     
  • GOLD FUTURES

    2,399.80
    +30.40 (+1.28%)
     
  • RUSSELL 2000

    2,026.73
    -9.90 (-0.49%)
     
  • 10-Yr Bond

    4.2720
    -0.0830 (-1.91%)
     
  • NASDAQ

    18,352.76
    +164.46 (+0.90%)
     
  • VOLATILITY

    12.48
    +0.22 (+1.79%)
     
  • FTSE

    8,203.93
    -37.33 (-0.45%)
     
  • NIKKEI 225

    40,912.37
    -1.28 (-0.00%)
     
  • CAD/EUR

    0.6762
    -0.0030 (-0.44%)
     
Engadget
Why you can trust us

Engadget has been testing and reviewing consumer tech since 2004. Our stories may include affiliate links; if you buy something through a link, we may earn a commission. Read more about how we evaluate products.

SEC: Public companies must report cyberattacks within four days

Delays may be granted over public or national security risks.

Sean Anthony Eddy via Getty Images

In a move to prevent public companies from delaying news about cyberattacks, the US Security and Exchange Commission has set a four-day deadline to disclose "material cybersecurity incidents." A US attorney general could potentially delay that disclosure if doing so would lead to "substantial risk to national security or public safety." Otherwise, the rules will serve as a stiff new guidepost — albeit, one that's slightly less restrictive than the EU's GDPR cyberattack deadline of just three days.

The news comes after Microsoft was criticized by security experts for taking weeks to confirm an attack against Outlook and other online services. “We really have no way to measure the impact [of the attack] if Microsoft doesn’t provide that info," Jake Williams, a cybersecurity researcher and former NSA hacker, told the AP in June.

While GDPR rules are more about protecting the public, the SEC appears to be more focused on investors: “Currently, many public companies provide cybersecurity disclosure to investors," SEC Chair Gary Gensler said in a statement. "I think companies and investors alike, however, would benefit if this disclosure were made in a more consistent, comparable, and decision-useful way."

Technology companies have pushed against the SECs rules since they were initially announced last year, which ultimately led to the inclusion of a delay clause, Bloomberg reports. Additionally, the Information Technology Industry Council argued that the four-day deadline is too short, since companies may not know enough about the cyberattack by then.