News

US associations urge SEC to cancel it cyberattack disclosure rule

Tuesday 27 May 2025 11:31 CET | News

The American Bankers Association (ABA) has joined the Bank Policy Institute and three other associations in urging the SEC to rescind its cyber incident disclosure rule.

 

ABA and the other associations said that the rule puts companies that fall victim to cyberattacks at greater risk. The law was adopted in 2024 and requires businesses to publicly disclose a data breach or other cyber attack within four business days of determining whether the incident is material. The exception to this rule applies when the Justice Department determines that the publishing of the cyberattack would threaten national security and public safety.

ABA and other associations urge SEC to cancel new rule

 

Associations want new SEC rule cancelled

In their letter, the associations raised concerns regarding the rule requiring public companies to prematurely disclose cyber incidents, even when their vulnerability is ongoing and unresolved. ABA and the other organisations mentioned that a situation like this could offer criminals another tool for extortion, with at least one ransomware group reporting its own victim to the SEC. They also believe that this strains national security and law enforcement resources, creating market confusion and limiting international communication, as employees fear creating litigation risk.

The association mentioned that the requirements impose additional risks, costs, and complexity on SEC registrants, undermining the SEC’s mission to facilitate capital formation, and to generate the type of decision-useful information which would advance the SEC’s mission to protect investors. Registrants were and will be forced to publicly disclose an incident even if it is ongoing, the company’s investigation is not complete, and the incident is not fully remediated.

The letter also mentions that the rule is unhelpful to investors, as the premature disclosure harms registrants and fails to provide the market with meaningful or actionable information. The rule has been met with confusion about whether to file under Item 1.05, 8.01 or neither. The SEC’s attempts to clarify had not changed the situation.


Source: Link


Free Headlines in your E-mail

Every day we send out a free e-mail with the most important headlines of the last 24 hours.

Subscribe now

Keywords: regulation, cybersecurity, cybercrime, banks
Categories: Banking & Fintech
Companies: SEC
Countries: United States
This article is part of category

Banking & Fintech

SEC

|
Discover all the Company news on SEC and other articles related to SEC in The Paypers News, Reports, and insights on the payments and fintech industry:





Industry Events