• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
NewslettersCFO Daily

The SEC just released new rules for reporting cybersecurity breaches—here’s what it means for CFOs

Sheryl Estrada
By
Sheryl Estrada
Sheryl Estrada
Senior Writer and author of CFO Daily
Down Arrow Button Icon
Sheryl Estrada
By
Sheryl Estrada
Sheryl Estrada
Senior Writer and author of CFO Daily
Down Arrow Button Icon
August 1, 2023, 6:53 AM ET
The headquarters building of the U.S. Securities and Exchange Commission (SEC) stands in Washington, D.C., U.S.
The headquarters building of the U.S. Securities and Exchange Commission (SEC) stands in Washington, D.C.Getty Images

Good morning.

Recommended Video

Four business days. That’s how long public companies have to report to the U.S. Securities and Exchange Commission (SEC) a cybersecurity breach that may impact an organization’s bottom line.

The SEC announced the adoption of new rules on July 26 that requires the disclosure on the new Item 1.05 of Form 8-K of any cybersecurity incident the company determines to be “material,” along with a description including the “nature, scope, and timing,” and likely impact.

The new rules also add Regulation S-K Item 106, which will require companies to describe their processes for assessing, identifying, and managing material risks from cybersecurity threats, and the board of directors’ oversight of risks from cybersecurity threats. These disclosures will also be required in a registrant’s annual report on Form 10-K. 

The new rules will take effect in December or 30 days after publication in the Federal Register. The Form 10-K and Form 20-F disclosures will be due beginning with annual reports for fiscal years ending on or after Dec. 15, the SEC announced.

Many companies have already been sharing information on cyber incidents in 8-K forms, but there’s now a standard. And CFOs are increasingly tasked by companies to have a greater role in regulatory reporting. In Deloitte’s CFO Signals Survey for Q2 2023, finance chiefs cited increasing regulations and working with regulators as one of their top challenges related to managing enterprise risk (43%). And implementing processes to identify, monitor, and address risks was also listed as a concern (27%). 

It’s crunch time…for some

Since March 2022, there was indication that the SEC would take some action on cybersecurity reporting, and public companies should have been preparing, according to Courtney Adante, president of the security risk advisory at Teneo, a global CEO advisory firm. In addition to managing the division, Adante supports Fortune 500 clients with the design and delivery of enterprise security strategy programs including cybersecurity risk management.

“My perspective is the SEC was really aiming for more transparency for the investment community,” Adante says. “What I’ve seen is companies, particularly in highly regulated industries or sectors like financial services, or even defense, were largely positioned ahead of the game because they’ve had to adhere to regulation for some time now. For other industries and other sectors that may not have been spending the time here, it’s crunch time. I think that they’ve got a window of about six months to get themselves organized before these rules go into effect.”

What role does Adante think CFOs will play in SEC reporting? “The materiality assessment in terms of business disruption, and impact to financials and bottom line, obviously, lies with the CFO,” she says. “But the CFO will need to make that decision informed by a whole suite of stakeholders within the company and peers in the C-suite, and below, in the ensuing days and weeks after a breach in order to make that decision on materiality.”

If it is a material breach, and worthy of being reported to the SEC, how does a company beat the clock on the four-day rule? Prepare around crisis management to have the “ability to very quickly mobilize as an executive leadership team to share information and do that in a seamless way,” Adante explains. “And not only ensuring that they have those incident response and crisis management frameworks in place, but test them out now.”

Guy Melamed, CFO and COO at Varonis Systems Inc. (Nasdaq: VRNS), a software company that provides data security and analytics, shares his perspective. “CFOs are usually responsible for many things, but the SEC rules mean they now have to gain knowledge of one more subject that was never taught in any accounting class: cybersecurity,” Melamed says. “The responsibility for keeping companies secure is still under the security team—but CFOs must start stepping up and asking questions about their organization’s security, and the right ones. All too often, risk starts when critical information is overexposed.”

What’s a good security question? “Ask your [chief information security officer] who can or who has accessed your financial statements in the last 30 days. If they can’t answer you in five
minutes, you are exposed,” Melamed says.


Sheryl Estrada
sheryl.estrada@fortune.com

Big deal

A report by S&P Global Market Intelligence finds that publicly traded media and telecom companies in North America collectively raised $868 million through capital offerings in June. The total represents a "significant decline" from the revised $26.51 billion raised in May 2023 and the $1.33 billion raised in June 2022, according to the report. 

Courtesy of S&P Global Market Intelligence

Going deeper

The Federal Reserve's July 2023 Senior Loan Officer Opinion Survey on Bank Lending Practices released on Monday found that in the second quarter of 2023, a growing number of banks tightened lending standards. "Regarding loans to businesses, survey respondents reported, on balance, tighter standards and weaker demand for commercial and industrial loans to firms of all sizes," according to the report. "Meanwhile, banks reported tighter standards and weaker demand for all commercial real estate loan categories."

Leaderboard

Jami Rubin was named CFO at Boundless Bio, a clinical-stage, oncology company. Rubin brings more than 30 years of experience to the role. Rubin was most recently CFO of EQRx. She spent the majority of her career as a biopharma equity analyst, including as a partner at Goldman Sachs. Rubin also served as a Partner at PJT Partners, a global advisory-focused investment bank.

Monica Vinay was named CFO at Visual Edge IT, Inc., which specializes in managed IT services and security, and cloud computing. Vinay's experience has been focused on finance and analysis. Most recently, she served as interim CFO and VP of investor relations and treasurer at Myers Industries, Inc. Before that, Vinay was the director of finance at Barnes Group, Inc.

Overheard

"We forecast house prices in 2023 to finish the year flat versus 2022 before falling 2% in 2024 as affordability continues to adjust slowly back to long-run averages and inventories begin a slow climb off multi-decade lows."

—Morgan Stanley housing analysts wrote in a research note they expect home prices to hold steady year over year in 2023, before trending lower in 2024, Yahoo Finance reported.

This is the web version of CFO Daily, a newsletter on the trends and individuals shaping corporate finance. Sign up to get CFO Daily delivered free to your inbox.

About the Author
Sheryl Estrada
By Sheryl EstradaSenior Writer and author of CFO Daily
LinkedIn iconTwitter icon

Sheryl Estrada is a senior writer at Fortune, where she covers the corporate finance industry, Wall Street, and corporate leadership. She also authors CFO Daily.

See full bioRight Arrow Button Icon

Latest in Newsletters

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Newsletters

Aerie built a brand based on ‘real.’ That’s at the heart of its ‘no AI’ promise
NewslettersMPW Daily
Aerie built a brand based on ‘real.’ That’s at the heart of its ‘no AI’ promise
By Emma HinchliffeMay 1, 2026
1 day ago
The fruit fly cancer researcher who built his first prototype out of lollipop sticks and straws
NewslettersTerm Sheet
The fruit fly cancer researcher who built his first prototype out of lollipop sticks and straws
By Allie GarfinkleMay 1, 2026
1 day ago
Apple CEO Tim Cook in Washington, D.C. on December 10, 2025. (Tom Williams/CQ-Roll Call/Getty Images)
NewslettersFortune Tech
Tim Cook’s advice for Apple’s next CEO
By Andrew NuscaMay 1, 2026
1 day ago
Brian Niccol’s nascent Starbucks turnaround starts with treating workers better
NewslettersCEO Daily
Brian Niccol’s nascent Starbucks turnaround starts with treating workers better
By Phil WahbaMay 1, 2026
1 day ago
Meta's Hyperion data-center site in Northeastern Louisiana.
NewslettersEye on AI
Big Tech will spend nearly $700 billion on AI this year. No one knows where the buildout ends
By Sharon GoldmanApril 30, 2026
2 days ago
The Tory Burch Foundation is almost halfway to its $1 billion goal for women entrepreneurs
NewslettersMPW Daily
The Tory Burch Foundation is almost halfway to its $1 billion goal for women entrepreneurs
By Emma HinchliffeApril 30, 2026
2 days ago

Most Popular

Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
Personal Finance
Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
By Fatima Hussein and The Associated PressMay 1, 2026
1 day ago
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
North America
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
By Jake AngeloApril 30, 2026
2 days ago
A Chick-fil-A worker got fired and then showed up behind the register to allegedly refund himself over $80,000 in mac and cheese
Law
A Chick-fil-A worker got fired and then showed up behind the register to allegedly refund himself over $80,000 in mac and cheese
By Catherina GioinoMay 1, 2026
23 hours ago
Current price of oil as of May 1, 2026
Personal Finance
Current price of oil as of May 1, 2026
By Joseph HostetlerMay 1, 2026
1 day ago
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
5 days ago
The U.S. economy is booming — just not where 50 million Americans live
Commentary
The U.S. economy is booming — just not where 50 million Americans live
By Derek KilmerMay 1, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.