Skip to main content

Banking Industry Challenges SEC’s Cybersecurity Disclosure Rule

Major banking groups are urging the Securities and Exchange Commission (SEC) to reconsider its new cybersecurity incident disclosure rule. In a recent petition, five influential banking associations, including the American Bankers Association and the Securities Industry and Financial Markets Association (SIFMA), argue that the rule’s mandatory, rapid disclosure of cybersecurity incidents directly conflicts with confidential reporting protocols designed to safeguard critical infrastructure and alert potential victims.

The rule, part of the SEC’s Cybersecurity Risk Management rule published in July 2023, mandates prompt disclosure of incidents like data breaches and hacks. The banking groups contend that this approach hinders effective incident response efforts and law enforcement investigations, leading to “market confusion” between mandatory and voluntary disclosures. Furthermore, they claim that public disclosure can be exploited by ransomware criminals for extortion, worsening insurance and liability issues for companies, and chilling internal communication and information sharing.

Specifically, the petition targets Item 1.05 of the SEC’s Form 8-K reporting requirements. This item mandates disclosure of cybersecurity incidents to investors, a requirement the banking groups argue is counterproductive. They believe existing disclosure frameworks for material information adequately protect investor interests, even without Item 1.05.

The petition cites instances of confusion among market participants and specific examples of ransomware attacks that illustrate the rule’s negative consequences. The impact extends to publicly-traded cryptocurrency firms. Coinbase, for example, recently faced multiple lawsuits after disclosing a data breach incident resulting from a bribery scheme targeting its support staff. This highlights the potential financial and legal ramifications for companies operating under the current SEC regulations.

The banking industry’s challenge to the SEC’s rule underscores the ongoing debate between transparency and the need for a balanced approach to cybersecurity incident reporting. The potential rescission of Item 1.05 could significantly alter the landscape for public companies’ cybersecurity disclosure practices, impacting not only financial institutions, but also firms in the cryptocurrency industry.

Banking groups ask SEC to drop cybersecurity incident disclosure rule

Source: SIFMA