December 18, 2023 is SEC Reporting Day and the FBI is ready!

For those of us who have been tracking the SEC’s Cybersecurity reporting requirements that were issued this summer, they go into effect for all large publicly traded companies on Monday, December 18.

In anticipation of that deadline, the FBI released a Policy Notice on Friday, December 8 that sets forth the steps that companies will need to follow in the narrow set of national security circumstances when a company seeks to delay the SEC’s public notification of the incident. It’s helpful to see the FBI’s process, because (1) it highlights that this is a limited-in-time delay for national security purposes only as determined by the Department of Justice; (2) it sets out the process companies must follow – in an extremely short time frame – to provide data to both the SEC and the FBI; and (3) it gives insights into how the FBI and DOJ processes will work, once a submission is received and accepted.

Attorneys and Incident Response teams should be looking at the Policy Notice now. Before an incident hits, IR teams and their lawyers will need to:

  1. Ensure that appropriate executive and legal personnel are trained and ready to sign off on materiality decisions.
  2. Train IR and legal teams to issue-spot for items that may be material – and not material to the company, but material to an investor.
  3. Have experienced personnel that are able to identify national security issues and that have appropriate clearances to discuss national security issues and concerns in advance of an incident if your company anticipates that national security could potentially be implicated due to incidents involving your products or services.
  4. Develop IR plans that begin documentation for the SEC (and potentially, the FBI) once an incident gathers sufficient momentum that it appears to be both material and have national security implications.

If your company is looking to modify its IR plans to ensure that it is prepared for SEC compliance and any of the FBI process requirements for national security notification delays, contact Advanced Cyber Law for assistance.

FBI Policy Notice:   https://www.fbi.gov/file-repository/fbi-policy-notice-120623.pdf/view 

SEC Cybersecurity Rule:  https://www.sec.gov/files/rules/final/2023/33-11216.pdf