- videocam On-Demand Webinar
- signal_cellular_alt Intermediate
- card_travel Corporate Law
- schedule 90 minutes
SEC's New Mandatory Cybersecurity Disclosure Rules: Maintaining Compliance and Avoiding Enforcement Risks
Enhanced Disclosures Regarding Cybersecurity Risk Management, Strategy, Governance and Incident Reporting
Welcome to BARBRI, the trusted global leader in legal education. Continue to access the same expert-led Strafford CLE and CPE webinars you know and value. Plus, explore professional skills courses and more.
About the Course
Introduction
This CLE webinar will discuss the SEC's recent adoption of rules requiring public companies to more immediately disclose cybersecurity incidents and provide annual disclosures regarding the company's cybersecurity risk management strategy and cybersecurity governance. The panel will examine the new rule's requirements and provide practical guidance for maintaining compliance and avoiding enforcement risks.
Description
On July 26, 2023, the SEC adopted final rules that generally require public companies to disclose material cybersecurity incidents within four business days after determining the incident was material. Also, companies must now provide information regarding their cybersecurity risk management, strategy, and governance on an annual basis. The final rules are effective Sept. 5, 2023.
Since 2011, the SEC has encouraged public companies to file a Form 8-K upon the occurrence of a material cybersecurity incident. The final rules turn the guidance into a mandate for Form 8-K. Foreign private issuers (FPIs) already have an obligation to disclose material information on Form 6-K that they disclose offshore, on a stock exchange, or to their security holders, and the new rules simply add material cybersecurity incidents to the list of material information included in the form.
Under the new rules, public companies and FPIs will be required to include additional cybersecurity risk management disclosures in Forms 10-K and 20-F. As part of these disclosures, companies must describe: their processes for assessing, identifying, and managing material risks from cybersecurity threats; the board of directors' oversight of risks from cybersecurity threats; management's cybersecurity expertise and its role in assessing and managing material risks from cybersecurity threats; and whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the registrant, including its business strategy, results of operations, or financial condition.
Listen as our authoritative panel provides an overview of the new rules and practical guidance for implementing policies and procedures to comply with the new requirements. The panel will also address the potential compliance and enforcement implications of the new rules.
Presented By
Mr. Desai is a cybersecurity, data privacy, and white collar defense and government investigations attorney. He has extensive experience in handling cyber intrusions and data breaches, trade secret thefts, emerging technology matters and complex white collar investigations. With a computer science and physics background, Mr. Desai is highly skilled and knowledgeable to advise companies on novel issues at the intersection of law, technology and data privacy. He is also a Certified Information Privacy Professional in the United States (CIPP/US) with the International Association of Privacy Professionals (IAPP). Mr. Desai is a former federal prosecutor in the Cyber and National Security Section and the Economic Crimes Section at the U.S. Attorney's Office for the Western District of Pennsylvania.
Mr. Koesters draws on more than a decade of experience with the Department of Justice (DOJ) and Department of Defense (DOD) to help clients navigate the full lifecycle of government scrutiny – from discovery and self-disclosure to parallel civil and criminal proceedings. He leads sensitive internal investigations involving alleged violations of state and federal law, corporate governance concerns, and cybersecurity compliance risks arising from regulatory oversight. He has defended health care systems, defense contractors, and critical infrastructure organizations facing traditional and novel theories of liability under the False Claims Act (FCA) brought by DOJ's Civil-Cyber Fraud Initiative and Health Care Fraud Units, as well as qui tam relators. In addition to his FCA work, Mr. Koesters leads clients through all stages of managing cybersecurity risk, from the development and implementation of policies and procedures to incident response operations and regulatory reporting. His practice integrates a litigation-ready approach – combining technical fluency with investigative insight – to protect clients in high-stakes disputes and enforcement actions.
-
This 90-minute webinar is eligible in most states for 1.5 CLE credits.
-
Live Online
On Demand
Date + Time
- event
Tuesday, October 24, 2023
- schedule
1:00 p.m. ET./10:00 a.m. PT
- Overview of the SEC's new cybersecurity disclosure rules
- Cybersecurity incident disclosure requirement in Form 8-K or Form 6-K
- Updates on previously reported cybersecurity incidents required in amended Form 8-K or Form 20-F
- New cybersecurity governance disclosure requirements in annual reports on Form 10-K and Form 20-F
- Compliance deadlines
- Practical guidance and takeaways for implementing policies and procedures to address the new rules
- Potential implications of the public disclosure of a company's cybersecurity incidents
The panel will address these and other key issues:
- What are the new Form 8-K filing requirements?
- What are the new cybersecurity governance disclosure requirements for annual reports on Forms 10-K and 20-F?
- What are the changes to Regulation S-K and how should companies disclose their processes for assessing, identifying, and managing material risks from cybersecurity threats?
- What are the corporate governance matters relating to the board of directors' and management's oversight of cybersecurity matters?
- What are the implications of these new rules on how companies will respond to future cyber incidents?
Unlimited access to premium CLE courses:
- Annual access
- Available live and on-demand
- Best for attorneys and legal professionals
Unlimited access to premium CPE courses.:
- Annual access
- Available live and on-demand
- Best for CPAs and tax professionals
Unlimited access to premium CLE, CPE, Professional Skills and Practice-Ready courses.:
- Annual access
- Available live and on-demand
- Best for legal, accounting, and tax professionals
Unlimited access to Professional Skills and Practice-Ready courses:
- Annual access
- Available on-demand
- Best for new attorneys
Related Courses
Corporate Authority Fundamentals: Delegation, Signing Authority, Approval Matrices, and Unauthorized Commitments
Thursday, November 5, 2026
1:00 PM ET/10:00 AM PT
DOJ Whistleblower Rewards Program and AI Compliance: Implications for Corporate Compliance Programs
Thursday, November 12, 2026
1:00 PM ET/10:00 AM PT
New DOJ Compliance Guidance: Incentives and Penalties, Cooperation Credits
Available On-Demand
Recommended Resources
BARBRI's Lega AI Builder Lab Brings Parker Poe Attorneys and Clients Together to Build AI Tools
- Legal Technology
Moving Quickly on AI, Onboarding, and Mentoring with Arnall Golden Gregory
- Learning & Development