The SEC staff issued CF Disclosure Guidance: Topic No. 2 – Cybersecurity on Oct. 13, 2011. This guidance is intended to provide the views of the SEC's Division of Corporation Finance regarding disclosure obligations relating to cybersecurity risks and cyber incidents. While the statements in this CF Disclosure Guidance represent the views of the staff of the Division of Corporation Finance, this guidance is not a rule, regulation, or statement of the Securities and Exchange Commission. Nonetheless, given the role of the staff of the Division of Corporation Finance in reviewing public company disclosure, the Guidance provides helpful insight into what the staff will be looking for when reviewing filings.
The Guidance observes that a public company that depends on digital technologies to conduct some or all of its business may be exposed to risks or liabilities arising out of what it terms "cyber incidents". Therefore, the staff believes that it may be necessary for such a company to consider adding disclosure to its periodic filings regarding its experience with respect to cyber incidents and with respect to cybersecurity in general.
The Guidance suggests that cybersecurity disclosure may be relevant in a number of places in an affected issuer's filings, including:
- Risk Factors;
- Management's Discussion and Analysis of Financial Condition and Results of Operations (MD&A);
- Description of Business;
- Legal Proceedings;
- Financial Statements; and
- Disclosure Controls and Procedures.
The Guidance, which is relatively brief, is available on the SEC's website at: http://www.sec.gov/divisions/corpfin/guidance/cfguidance-topic2.htm .
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.






