Products Intelligence Pricing Methodology Contact
FINANCIAL & CAPITAL MARKETS

Cybersecurity incident disclosure

Cybersecurity incident disclosure requirements for Financial & Capital Markets firms have tightened considerably, with the U.S. Securities and Exchange Commission's Rule 10b-5 amendments and its dedicated cybersecurity disclosure rule (effective December 2023) now requiring public companies to report material incidents within four business days of determining materiality. The U.S. Federal Reserve and the European Banking Authority have layered operational resilience and incident reporting obligations on top of that baseline, leaving compliance teams to reconcile overlapping timelines and materiality thresholds across multiple regimes. The coordination burden is real and immediate.

Watch

  • SEC 10-K/8-K cybersecurity disclosure rule: materiality determination triggers and timelines
  • EBA DORA incident classification thresholds taking effect January 2025 for EU-licensed entities
  • Federal Reserve SR 23-4 guidance on third-party cyber incident notification expectations
  • Gap between SEC 'material' standard and DORA 'major incident' definitions for cross-border firms
  • Proposed New York DFS amendments to Part 500 expanding notification scope to include ransomware payments

Recent material activity in Financial & Capital Markets

Active monitoring in place across Financial & Capital Markets. Material developments related to cybersecurity incident disclosure will appear here as they are published.