Impact of SEC Regulations on Public Companies with PwC’s Matt Gorham
Matt Gorham, leader of the Cyber & Privacy Innovation Institute for PwC, dives into the impact the latest cybersecurity regulations from the Securities and Exchange Commission (SEC) will have on public companies.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Matt Gorham, who is leader of the Privacy Innovation Institute at PWC, and we're talking about these new SEC rules that were implemented at the close of last year and going into 2024 and what they mean for everybody.
Matt, welcome to the show. Glad to be here. I think initially everybody looked at these rules and said, my God, we're gonna hold all these people personally accountable.
And then they got tempered at the end there, kind of a last minute reprieve for some folks, but they're still pretty, um, comprehensive, shall we say. So what's your take so far as you kinda look at where we are now and versus where we were when everybody was first talking about this? I think when the proposal came out, I think there was a lot of concern.
And, and so the comments reflected that. And so if you kind of think about the proposal in three buckets, uh, of disclosure, one around incident disclosure, material incident disclosure, one around your risk, uh, strategy, cybersecurity strategy risk management, and one around board governance. I think, um, the, the final rule addressed, uh, each of the, the concerns that were brought up during the proposal maybe didn't go as far as some folks wanted in terms of, um, moving, uh, some of the, uh, disclosure up a level, but it's certainly the, the SEC addressed those concerns.
So what is the biggest impact so far as it really just on the incident reporting or what is it that organizations need to change that they hadn't been doing before? Yeah, I think there, there are two, um, two areas. One around the material incident disclosure and second around the risk management.
The, the 10 K I'd say, I would say on the, um, material incident disclosure. First and foremost, if you think about that, uh, incident disclosure at three levels, one escalation procedure. So that is escalating from the CISO organization to the disclosure committee.
That is who's responsible for the material, uh, materiality, determination. Um, the second is the determination itself, and third being the actual disclosure. I think, I think that's where a lot of the initial work, um, by companies was focused.
That is at the, uh, escalation level. Have you baked materiality considerations into that escalation? Do you have the ability, uh, with incidents that are related, that is same actor, same vulnerability to aggregate and track them over time and escalate them up in aggregate for a determination?
And lastly, how do you treat information that comes in, uh, months later that may change that determination, and how do you marry that up with the original incident and then escalate it? I think at the disclosure, uh, determination itself, it's, it's really about do you have, well-documented process that contemporaneously evidences that determination. So when the SEC comes back and says, you made a determination that this was not a material incident, explain your math.
I think you wanna have that documentation with the weight of something that was done contemporaneously. And then lastly, it's, it's about can you, from the point you make that materiality determination, get that, uh, drafted wordsmithed and approved and out the door in the four days? So that was the initial focus.
I think more recently it's really been around the 10 K risk management cybersecurity strategy. And I think that's a, a function of, in looking at, um, the disclosure, because you're gonna, you're gonna pull some things outta your risk factors, some things outta your proxy statement, write some net new. I think the, the primary question or two primary questions that, that, um, companies are asking, or one, is it sufficient to disclose to the markets?
And if we validated the accuracy of everything in it, but secondly, it's around have we undersold the risk and oversold our capability and making sure that what you disclose is indicative of what you actually know to be the case. So do you think cybersecurity professionals are cheering this or are they looking at it with a certain amount of dread because there's just a lot more paperwork? You know, I, I think both.
Uh, I think some, some look at it, uh, and are concerned about and understanding what the CISO role is. Uh, and I think in, in many ways, the CISO position has been elevated as a result of this disclosure, you're certainly going to need to have a more proactive role, uh, in the disclosure process. For example, on the 10 K, oftentimes we see CISO providing information on the front end.
But I think now, given the concerns around how you describe the, the capability of your organization and the risks threat, uh, therefore risk of your organization, I think having the CISO on the back end of that disclosure and making sure they're approving it after it's gone through all the, the, uh, wordsmithing, I think is, uh, an elevation in, in some respects, the same is true with, uh, the material, uh, incident determinations. Where is the CISO in that process? How is it providing input?
And I think, you know, the companies that are, are really wrestling with it and doing the best. If you imagine a triangle and you had the CISO CIO on one corner, the general counsel on one corner, uh, and, and the, uh, CFO comptroller in, in the other, it's really about shrinking the size of that triangle and bringing those organizations closer together. So while there's a, there is additional work, while there is additional concern on the part of CISOs, I do think overall, I think it'll elevate the stature of the CISO position over the course of this year.
Do you think security people are gonna be more likely or less likely or maybe neutral in terms of their desire to work for a public company because there are more, uh, rules and rings to deal with? There Are, there, there are certainly challenges and, and, um, there are concerns, and I've, I've heard those reflected back, but at the same time, I think it's a, an opportunity for CISOs to kind of elevate the game, uh, and participate in something that, um, I think it, they'll find rewarding overall, uh, in the end. And so I think it's both.
There's a little bit of apprehension about what this means for a ciso, uh, but it's also a golden opportunity for the CISO to stand up, uh, and really be part of the business, um, as opposed to merely, uh, securing the business. Do you think there's an opportunity to apply AI to this? Because it seems like there's just a lot of reports and, uh, reports to me these days equals generative ai, so maybe we can figure out some way to automate all this.
Some of it certainly can be, be automated. I think there, there are parts of the information that you would develop as part of the disclosure, the controls around it, they're certainly open. Uh, and then opportunities for generative ai, um, and AI machine learning in general.
Uh, at the same time, I think that the, the understanding and nuance of, of a, a human is required, particularly when it comes to determinations around materiality, when it comes to really kinda giving that final check on, Hey, have we undersold, uh, our, the risk and oversold our capability? I think those are things that are gonna require the human touch. Uh, so I do think there's, there's opportunities, but there're certainly gonna be, uh, the need to have humans.
Uh, at the end of the day, Some of this kind of sounds like the codification of best practices. A lot of people have been doing this in various forms. So as the SEC just really turned around and said to everybody, you know, we wanna raise the bar to something that y'all should be doing in the first place.
They've set a, um, they've set a framework that allows for that. But, but remember, the SEC has not, uh, promulgated any type of best practices. That is even on the cybersecurity risk management process.
You're not required to have one, but you're required to disclose one if you do. And so I think it will lift all boats as a result of everybody putting their best foot forward. Um, but it's not, uh, prescriptive in terms of what those best practices are.
Um, it's really about being transparent about what you do have. Uh, and so I do think that will have an overall uplift, uh, over time. How much of this is an advisory versus a requirement?
Are we gonna see the SEC level fines on this in the coming year? Uh, I, I do think we're gonna, um, we're going to see interest. The SEC has increased the size of its, uh, oversight, uh, um, unit, um, in terms of enforcement around the cyber rule.
That said, I think on the 10 KI think all reflections are, it's gonna be a year of transition. Uh, companies are gonna have to figure out what that looks like, uh, on the new form. Um, so I do think, um, we'll see some indication after that first full 10 K cycle a year of where the SEC wants to, to really explore.
I do think there's gonna be continued interest, however, on the eight Ks. And so making sure that material incidents are disclosed, uh, and they're disclosed in a timely, uh, comparable way, uh, so that investors can make good decisions about the, the, uh, the investments they make. To that point, do you think that these reports will impact the valuation of companies?
Will investors look at that or is it just another box that people are checking ultimately? Or will it materially impact the price of a stock? Um, remains to be seen, but I think when you think about particularly the, uh, the material incident disclosures, um, you know, companies, I'll use ransomware as an example.
'cause I think it's illustrative of what we've seen. Um, if you go back a couple years, reputationally, companies are very concerned about being the victim of a ransomware incident today. Maybe companies are less concerned about being the victim and more concerned reputationally about how they responded to, uh, the, the, uh, the incident.
And so you're seeing companies be much more transparent. Um, you're seeing eight Ks that have been filed, uh, prior to the rule being, uh, into effect that weren't material eight kss, uh, but they were used, uh, to describe the nature, scope and timing of the incident. Again, I think in an attempt to be very transparent, so I do think, um, you know, you can look at where stocks go as a result of that incident and, and do they bounce back or not.
And I think that's something over the course of the next year that, that everyone's gonna be paying close attention to and see what is the relationship between an incident where you, you're very transparent and respond, uh, in a way that, uh, is transparent and those that maybe, uh, responded less effectively. And, and what the difference between, uh, the impact on stock looks like. How should cybersecurity people insert themselves into this conversation?
For many years now, they've been asking to have some sort of relationship with the board, but that seems to be uneven at best because they're still talking different languages. So how do I kind of broach this in a way that everybody understands what we're talking about? I think, I think that's key, and that's that really the third bucket of disclosure around governance and board.
And so I think that goes to a few things. One, if you go back a number of years, CISO's maybe met with the board once a year, certainly more and more today. That's quarterly.
We're even seeing some boards have executive session with the ciso. And I think that's a function of exactly as you mentioned. How do you translate technical cyber risk into business risk language?
And, and, you know, I think that goes to how do you elevate the totality of the board, uh, in terms of digital acumen so that the board feels comfortable doing that translation or having that translation done for them, and do they have the right information? And so that goes to the periodicity of the, the, the, uh, interaction with the ciso. It goes to describing that technical cyber risk in a way that they understand in terms of business impact.
And I think that's bringing the ciso uh, and the board closer together, again, both in the number of interactions and the type of interactions so that the board feels they're getting sufficient information to understand what risk is being bought down, uh, as a result of the program and really understanding how that functions. And so I think that's a, another really good opportunity for the CISO over the course of this year to elevate, uh, the game. In terms of that interaction.
It seems to me it's unlikely that board members are gonna learn a whole lot more about cybersecurity. They may understand risk 'cause well, that's what they're trained for, but, uh, is the onus really gonna be on the cybersecurity people to learn the language of the board versus the other way around? It doesn't seem to me like there's hope for the former, so it must be the latter.
I think it's a little bit of both. Um, and, and what I mean by that is, you know, certainly the best CISOs are able to translate that technical cyber risk into business risk language, and they, and they're very effective at describing the impact, the business impact, uh, of the program and any incident they have. And so there's a significant lift on the part of, uh, the CISO to, to do that.
At the same time, I do think, um, you know, in the proposal they talked about, uh, board expertise, um, in terms of cyber, that was shifted over onto management. And so it's not a, it's not part of the rule, but I do think it goes to what does board education look like? How do you keep board members current on cyber challenges?
How do you elevate their digital acumen so that they can, uh, take that information and feel like they have what they need to do that oversight? And so I think it's, it's on both sides. I think significant lift on the part of, uh, the CISOs to engage with the board in a way that is productive.
Uh, at the same time, I do think, uh, overall lifting that dig digital acumen of boards, boards, having access to independent cyber expertise when they need it, uh, I think that's part of the, the, uh, the solution as well. All right. So ultimately, what's your best advice to folks as we're in a brand new year?
How do they start this process? Do I, uh, take a board member to lunch? Do I go hang out and play golf with them?
How do I kind of get this conversation going? Well, I think it, it goes to what, what is that? Uh, um, what does the board cycle look like?
So what are you doing on a quarterly basis? Do you have a governance program that, for example, if you do a NTA CSF assessment, you know, do what's the, how do you report that back out to the board? Um, what, in terms of education, what does that schedule look like?
I think if you take the year, look at it, see what interactions you're gonna have with the board over the course of that year, and really ensure that those are, uh, you've thought through those, um, you can schedule that out for the entirety of the year and, and really focus on giving the board what it needs sometimes that, that's gonna take the, uh, the form of a discussion, uh, initially, uh, asking the questions of here's what we have, what is it that would be useful to you, uh, to understand this risk. And so that the, the more that interaction takes place, I think the more comfortable boards will be. Um, and I think that it will serve the, the CISOs, um, CISOs cause as well.
All right, folks, I think you heard it here. Matt just pretty much gave us all a list of New Year's resolutions for ciso. So get cracking.
Hey Matt, thanks for being on the show. Good to be here. All right, and back to you guys in the studio.