<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SEC now requires companies to disclose cyberattacks in 4 days in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61263#M923</link>
    <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1542574691"&gt;@JKWiniger&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Excellent news then.... yay&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
    <pubDate>Sat, 29 Jul 2023 04:47:22 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2023-07-29T04:47:22Z</dc:date>
    <item>
      <title>SEC now requires companies to disclose cyberattacks in 4 days</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61207#M917</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wonder whether organisations will actually comply with this requirement?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/sec-now-requires-companies-to-disclose-cyberattacks-in-4-days/" target="_blank" rel="noopener"&gt;https://www.bleepingcomputer.com/news/security/sec-now-requires-companies-to-disclose-cyberattacks-in-4-days/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How will smaller companies comply?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:40:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61207#M917</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T10:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: SEC now requires companies to disclose cyberattacks in 4 days</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61209#M918</link>
      <description>&lt;P&gt;Smaller companies will not be effected by this because it only applies to publicly traded companies, I think once a company gets to that point they are no longer small.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I don't see is any kind of penalty if a company does not disclose in time or at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John-&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 23:09:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61209#M918</guid>
      <dc:creator>JKWiniger</dc:creator>
      <dc:date>2023-07-26T23:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: SEC now requires companies to disclose cyberattacks in 4 days</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61210#M919</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1542574691"&gt;@JKWiniger&lt;/a&gt;&amp;nbsp;&amp;nbsp; I agree, I have asked the question on social media, but no response as yet.&amp;nbsp; Apparently not implemented before December 2023.&amp;nbsp; So it will be interesting what the reaction will be from organisations as a whole.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 03:10:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61210#M919</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-07-27T03:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: SEC now requires companies to disclose cyberattacks in 4 days</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61218#M920</link>
      <description>&lt;P&gt;I find it interesting that publicly traded companies get all these requirements, but SMBs struggle to determine their own cyber-centric identity, posture, and value.&amp;nbsp; It wasn't until yesterday that I learned about the &lt;A href="https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314" target="_blank" rel="noopener"&gt;FTC's Section 314&lt;/A&gt;, which only broadly addresses cybersecurity through the eyes of consumer protection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No matter, good move on SEC's part.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 13:01:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61218#M920</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2023-07-27T13:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: SEC now requires companies to disclose cyberattacks in 4 days</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61251#M922</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp;I wasn't sure if I should make this a new post or just reply... From the same SEC change comes.. Companies Must Have Corporate Cybersecurity Experts!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this is a step in the right direction..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.darkreading.com/edge-articles/companies-must-have-corporate-cybersecurity-experts-sec-says" target="_blank" rel="noopener"&gt;https://www.darkreading.com/edge-articles/companies-must-have-corporate-cybersecurity-experts-sec-says&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 16:12:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61251#M922</guid>
      <dc:creator>JKWiniger</dc:creator>
      <dc:date>2023-07-28T16:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: SEC now requires companies to disclose cyberattacks in 4 days</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61263#M923</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1542574691"&gt;@JKWiniger&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Excellent news then.... yay&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jul 2023 04:47:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/SEC-now-requires-companies-to-disclose-cyberattacks-in-4-days/m-p/61263#M923</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-07-29T04:47:22Z</dc:date>
    </item>
  </channel>
</rss>

