# New SEC cybersecurity rules put more onus on the CISO, not so much on directors

DevFeed: [New SEC cybersecurity rules put more onus on the CISO, not so much on directors](<https://devfeed.tech/articles/new-sec-cybersecurity-rules-put-more-onus-on-the-ciso-not-so-much-on-directors-8026.md>)

Original publisher: [Read original article](<https://snyk.io/blog/new-sec-cybersecurity-rules-onus-on-ciso/>)

Author: Myke Lyons

Published: 2023-08-03T19:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Incident response](<https://devfeed.tech/topics/incident-response.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [breach](<https://devfeed.tech/tags/breach.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [executive](<https://devfeed.tech/tags/executive.md>), [incident](<https://devfeed.tech/tags/incident.md>), [management](<https://devfeed.tech/tags/management.md>), [pii](<https://devfeed.tech/tags/pii.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

The article examines SEC cybersecurity disclosure rules for public companies, focusing on how CISOs should interpret materiality, likely impact, and the four-business-day Form 8-K filing deadline.

## Source excerpt

With the SEC's adoption of new rules on cybersecurity risk management, strategy, governance, and incident disclosure by public companies, one thing is clear: better definitions are required.