New SEC Ruling: Transatlantic convergence in dealing with cyber security incidents
Foreign Filers / Private Issuers watch out! 2023 brought further harmonization of European and US standards for cyber incident reporting. According to the SEC Ruling, all companies listed on the US stock exchange are now required to publicly report significant data security incidents to the SEC within four working days. In addition, they must outline in their annual report (10-K) their procedures for identifying and addressing material cybersecurity risks, including the role of the board of directors. Note: This rule also applies to foreign private issuers (e.g., German companies that issue a