CLIENT ALERT: SEC Finalizes New Rules on Cyber Security Risk Management and Disclosure August 1, 2023On July 26, 2023, the Securities and Exchange Commission (SEC) announced that it had finalized new rules on cyber security risk management, strategy, governance, and incident disclosure by public companies.The new rules require public companies to disclose any cyber security incident that is determined to be material, as well as describe the aspects of the incident and its impact on the company. In the rule, the SEC defined information as being material “if there is a substantial likelihood that a reasonable shareholder would consider it important in making an investment decision, or if it would have significantly altered the ‘total mix’ of information made available.”The timeline for disclosure is four business days after the company designates the event as being material. However this disclosure may be delayed if the US Attorney General determines that the disclosure would pose a risk to national security or public safety. Most public companies will be required to start providing these 8-K and 6-K disclosures by December 18, 2023. Smaller companies will have an additional 180 days before they need to provide the 8-K disclosure going forward.Additionally, public companies will also be required to disclose on an annual basis material information regarding cyber security processes for assessing, identifying, and managing risks from cyber security threats, as well as the effect of risks from cyber security threats and previous incidents.Also required is information on board of directors’ oversight as it relates to risks from cyber security threats, and management’s role and expertise in assessing and managing those risks. These disclosures in Form 10-K or 20-F will be due for annual reports for fiscal years ending on or after December 15, 2023.“While these new disclosure regulations are intended to increase transparency for investors, there is concern that the disclosure of material impacts of breaches can be instructive to the threat actors perpetrating the breaches themselves.”CAC Specialty recommends that you reach out to your broker to discuss the impact of these new disclosure requirements, especially with regards to the following:Potential for increased personal liability for directors and officersPotential for increased exposure to shareholder derivative and class action litigationLimits considerations for D&O and Cyber insurance coveragesData and analytics tools available relative to cyber risk quantificationFor more information, please reach out to your CAC Specialty contact.Recommended for youCAC Group Names Johnathan Daniel as Chief Financial Officer to Support Next Phase of Strategic GrowthNewsDENVER – CAC Group, a leading insurance brokerage and risk advisory firm, today announced the appointment of Johnathan Daniel as Chief… – July 24, 2025 Read moreCAC Group receives the 2025 Spirit of Hope Award from Mile High United Way.AwardsCAC is honored to receive the 2025 Spirit of Hope Award from Mile High United Way. This recognition reflects our… – July 15, 2025 Read moreCAC Group Ranks #35 on BI 2025 Top 100 U.S. Brokers ListAwardsCAC Group is ranked #35 on the Business Insurance 2025 Top 100 largest U.S. brokers list – up one spot… – July 10, 2025 Read more
CAC Group Names Johnathan Daniel as Chief Financial Officer to Support Next Phase of Strategic GrowthNewsDENVER – CAC Group, a leading insurance brokerage and risk advisory firm, today announced the appointment of Johnathan Daniel as Chief… – July 24, 2025 Read more
CAC Group receives the 2025 Spirit of Hope Award from Mile High United Way.AwardsCAC is honored to receive the 2025 Spirit of Hope Award from Mile High United Way. This recognition reflects our… – July 15, 2025 Read more
CAC Group Ranks #35 on BI 2025 Top 100 U.S. Brokers ListAwardsCAC Group is ranked #35 on the Business Insurance 2025 Top 100 largest U.S. brokers list – up one spot… – July 10, 2025 Read more