SEC Delays Finalized Cyber Rules Until October 2023

MF
Morrison & Foerster LLP

Contributor

Known for providing cutting-edge legal advice on matters that are redefining industries, Morrison & Foerster has 17 offices located in the United States, Asia, and Europe. Our clients include Fortune 100 companies, leading tech and life sciences companies, and some of the largest financial institutions. We also represent investment funds and startups.
Based on updates to its rulemaking agenda that were released last week, the U.S. Securities and Exchange Commission (SEC) has delayed approval of two cybersecurity rules until at least October 2023.
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

Based on updates to its rulemaking agenda that were released last week, the U.S. Securities and Exchange Commission (SEC) has delayed approval of two cybersecurity rules until at least October 2023. Both proposed rules were released by the agency in early 2022.

Cyber Rules for Public Companies

In March 2022, the SEC proposed rules on cybersecurity risk management, governance, and incident disclosure by public companies. If adopted, this proposed rule, which was subject to two comment periods, would require enhanced cybersecurity disclosures regarding cybersecurity incidents and risk management. To learn more about the proposed public company cyber rules, read our March 2022 Client Alert. Final action is not expected on this proposed rule until at least October 2023, as opposed to April 2023 as previously announced.

Cyber Rules for Registered Investment Advisers, Registered Investment Companies, and Business Development Companies

One month earlier, in February 2022, the SEC proposed rules for cybersecurity risk management for registered investment advisers (RIAs), registered investment companies, and business development companies. This proposed rule was also subject to two comment periods. If adopted, the proposed rule would impose on RIAs and other entities within its purview a duty to implement bespoke cybersecurity policies and procedures, to review these policies and procedures at least annually, and to prepare a written report documenting their review, among other things. To learn more about these proposed cybersecurity rules, read our February 2022 Client Alert. Final action is not expected on this proposed rule until at least October 2023.

Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Morrison & Foerster LLP. All rights reserved

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More