Counsel Eric Gyasi is quoted by the Wall Street Journal in a Sept. 20 article titled “Clorox Cyberattack Brings Early Test of New SEC Cyber Rules” (subscription required).
New Securities and Exchange Commission rules took effect Sept. 5, and Clorox is the first large U.S. company to suffer a cyberattack since then, according to the article. Under those rules, a company now has four days to “outline the nature, scope and timing of a cyber incident after determining it will have material consequences.”
Gyasi told the WSJ that the SEC “wants investors to have access to more standardized information about significant cyber breaches,” which is new territory for most companies. Now, they will need to “make sure there’s a process for bringing actionable information to disclosure committees,” he said.
