The Role of the SEC in Cybersecurity Regulations with Matt Gorham
Matt Gorham discusses the evolving role of the SEC in cybersecurity regulations. He also highlights the importance of assessing materiality and trends that indicate improved collaboration in cybersecurity governance, enhancing board members’ awareness of risks.
Transcript
This is Textron tv. Hey guys. Thanks for the throw.
We're here with Matt Gorham, who is senior managing director for the Cyber and Privacy Innovation Institute at PWC. And we're talking about the SEC roles at year on. Matt, welcome to the show.
Thanks for having me. Nice. So, what's your sense of, where are we with these rules?
I think when they first came out, everybody was, shall we say, uh, you know, a sense of terror. Somebody thought that the sheriff was in town and everybody was gonna have to have all these new rules and regulations. Is that how it played out or has it been more of a slow role?
What's your assessment of what's going on here? Yeah, I think, I think what we've seen from the, um, and I, I'll break it into two pieces. The first around the material incident disclosure, the second around the annual disclosure, so things around cybersecurity strategy, process, and governance.
I'd say there's a lot of concern initially on the, uh, material incident disclosure. Uh, I think it was mainly focused around the four day time period after you made the determination around materiality. But I think what we've seen play out is, uh, the companies were already required to make those material disclosures prior.
And so it was about the, the documentation in the process internally and making sure that it was sufficient to meet that four day, uh, requirement. We've seen some things, um, shift, but I'm not entirely sure there as a result of the SEC role. And, and what I, and what I'd highlight here is incidents that have been disclosed on eight Ks that were actually non-material incidents.
We started to see that immediately before the rule was put into place. 05, which is the Cyber eight K version. 01, which is that, that other category, uh, to document those.
There is some thought that that was a reaction to, uh, or a response to, uh, from companies to be more transparent, to kind of get those out in a prophylactic way prior to an incident becoming material. But it's just as likely, I think in my estimation, that's a result of the changing view of being the victim of a ransomware attack. What I mean by that is, if you go back a couple years, companies are very concerned about the reputational impact of being the victim of a ransomware attack.
Today, companies are less just given the volume, given less concerned about being the victim and more concerned reputationally about how they respond. And so you've seen companies be much more transparent around that response. And so if you look at those non-material eight Ks, I think they were, you could look at them much more as kind of holding strategic comms documents rather than a, a required disclosure.
But in any event, we've seen the SEC come back and say, if you're gonna voluntarily disclose something that's not material, either 'cause you haven't gotten to the materiality threshold or because you just want to get this out voluntarily, use the other form. Don't, don't do it under the cyber rule. I, I think if I go to the 10 KI think what we've seen is, um, a shift, um, to putting information all in one form that is, companies had to pull from their proxy statement and the risk factors and, and write some net new, but it's really about putting that all in one place in a format that would allowed investors to compare, uh, and, and see that in, and we're in the final stages of that year.
Right? So we're, we're getting ready to start seeing the, the, uh, nine 30 filers, uh, which will be the first time they've had to file the new, uh, 10 K. Um, but we've seen some consistency across, but again, not, not in a way that, uh, is earth shattering and, and some of the kind of, uh, for the the worry, uh, what before the rule was implemented, Do we have a handle on what defines a material incident these days?
'cause I think people are still kind of having that conversation a little bit. Yeah. Look, materiality is a legal concept that requires a legal judgment.
And so you use the Supreme Court definition. Uh, what's gonna be, um, of interest to, to the investor, the reasonable investor. I think it's both a qualitative and quantitative side.
So it's not just a, a number threshold, a financial threshold that you can point to, but it's also that qualitative assessment of the incident. So it's things like, how does this impact our competition? How does it impact our competitiveness?
How does it impact our reputation, our third party relationships? Uh, those are all things that need to be considered. And so there's not a, a black and white, um, answer to, it's an incidents material.
It's a, it's a quantitative and qualitative assessment, which is principles based. Right? It's applying those principles to the specific facts and circumstances that you have there.
And again, that's not a change from where they, uh, were prior to the rule because they were required to, um, disclose those prior to the rule being implemented as well. The differences today, it has the, the force and impact of a rule, and you have to do it within that four day period. Once you make that determination, I think most companies have have looked at that and, and maybe they made some refinements around that, that process of how they're documenting it, how they're making, uh, that determination.
But again, they, they already had to do it. And so we haven't seen a, a great change, uh, despite the, the very concerning comments that you saw early on. Mm-Hmm.
Isn't getting easier to build the reports 'cause it's still early days in the age of ai, but it seems like just about everything involving a report is getting easier to do. So is that becoming less onerous? Yeah, I think you, you still need to go through and, and validate that disclosure.
And so there, there are still manual processes involved in that, but there are certainly tools and, and the capability exists to collect some of that data up in a, in a, uh, quicker, more automated way. And, and companies are valuing themselves of that, but at the end of the day, you need to validate the, those concerns or, or those disclosures. And so you still need to, to have the human touch on the backend As we go forward.
Um, a lot of folks are watching this whole, uh, Supreme Court ruling involving Chevron and how that applies to the various agencies. What's your sense of what will be the role of the SEC going forward and how will the relationship change? What should people be looking for?
Yeah, I, I think I would answer it specifically on the cyber rule. 'cause I, I, I wouldn't wanna admir myself as an expert on all things SEC, but the Chev chevron decision and, and what we see with respect to the cyber rule, I think it's very much a, a, uh, principles based approach to the materiality disclosure. And what I mean by that is it is well within the, the norm of disclosure when it comes to, um, the, the f or the cyber rule, it's not a descriptive, uh, requirement to have certain things in place.
Me meaning some regulatory regimes, um, particularly at the state level, are very prescriptive. They say you need to do these following things. That's not what the SEC cyber rule says.
It says, in fact, doesn't require you to have a cyber program. What it tells you you must do is accurately disclose the one that you do have. And so again, that's a, that's a, uh, well within, I think the, the traditional view of, of regulatory action.
And so I don't know, I don't expect significant changes with respect to the cyber rule on the SEC moving forward. Now, might we see changes in terms of enforcement, um, down the road? We may, um, but in terms of the, the rule itself, I I, I see that kind of standing the test of time As you kind of think this through a year ago, people were forecasting things like, you know, fewer companies would go public because the rules were too stringent and or that other companies would go private as a result of that.
I'm not quite clear that we've seen any of that in the last year, but what's your assessment? Yeah, I, I haven't, and I can't point to anything that would indicate fewer companies going public or, or for that matter, uh, a significant market impact when a, when a uh, company has, um, done a notification around a cyber incident, I don't think we've seen that kind of mid to long term impact. Certainly there's impact, um, it in the short term, but I have not seen significant market consequence as a result of that.
And I think some of that goes to what, what is the purpose of the rule? Uh, and, and, and that really the rule was designed to give investors a kind of timely, comparable single place to go look at information regarding, uh, that company. And I think by that standard, we see that information out there and we see consistency among many of the followers that we've looked at thus far.
I think, you know, in terms of a changing cybersecurity hygiene, kind of raising the bar of cybersecurity, that's, that's not the in intent of the rule. And, and we haven't seen that again, because it's not a prescriptive type of regulation, it doesn't tell you what you must do. It tells you to accurately describe what you do.
Do. As we go along here, um, security compliance, governance and a lot of these organizations has been, um, separate. Is that all starting to converge more as a result of all this, or what's driving that trend?
Yeah, I think we, we see certainly closer working relationships. I think with the SEC rule in particular, um, I think, you know, three particular organizations, uh, really need to, um, come closer together in terms of working together. That's the CISO CIO organization, that, that's the CFO controller, and the third is the gc.
So if you think about those three organizations as corners on a triangle, it's about shrinking the size of that triangle to get them working more closely together, have a common common understanding of, of what each bring to the table with regard to this, to have a common vocabulary to discuss cyber issues. And I think, you know, that that trend of working together around, uh, cyber is something that, um, we'll continue to see. It's the nature of cyber.
We're, we're so interconnected as a result of the way we've architected the digital world, that it requires all of those players to come together, have a common understanding and, and work together. It's not a, you know, if you think about cyber as a, as a risk, it's not a, a single standalone risk. It it is in, in one sense, but it's also the kind of the central nervous system or the rails that many other risks ride over.
And so you need to think about cyber more broadly than a, than a, uh, risk in isolation. And, and I, you know, I I would say too, that's, that's reflected in some of the 10 Ks that we've looked at. I mean, 80% of the, the first 208 Ks that we looked at, um, had cyber risk integrated into their ERM.
And so I think it's, it's recognized, uh, across the industry that that's something that that's essential. I think there was some concern early on about, um, just how accountable c-level execs would be on this. And I think we kind of stepped back a little bit on that, but in your assessment as a result of all this, is the board more cybersecurity savvy these days?
Are there more cybersecurity folks on those boards? Yeah, you know, in, in the proposed rule, not the final rule, that there was a requirement to disclose board expertise around cyber. And that was kind of lifted and shifted over onto management in, in the final rule.
And so, um, companies need to disclose that cyber expertise, uh, around the program in management. I think in, in terms of board, um, cyber expertise, um, I haven't seen significant shifts in the expertise, but what I have seen and I think is more promising, is a lift of, uh, digital acumen across boards. And so I think sometimes it's a, uh, the most difficult thing to do from a CISO tool board is the translation of technical cyber risk into business risk language, something the board is very comfortable with.
And so what we see is closing that gap between the CISO organization and the board in terms of lifting the entire board's, uh, digital acumen to a point where they can take a look at that cyber risk, understand the business impact of, of that risk, and then conduct the oversight that they need to as a result of that. And so it manifests in a number of ways. Board education is one, uh, increasing frequency of cis o uh, engagement with the board.
We see some boards doing executive session with the ciso, again, to build that relationship, to get better at that translation from technical cyber risk to business risk. And so, you know, are we where we need to to be over the long term? I would say no, we always have, have room to grow, but we're going in the right direction when it comes to board, uh, understanding of the, the cyber risk.
Of course, there's risk in everything we do. Is it your assessment that boards and business people in general have a better understanding of exactly what the cybersecurity risk is and are, are able to make a better judgment today than they were a year ago? Yeah, look, I think if we look at it in those terms, are we better than we were a year ago?
The answer's yes, are are we where we need to be over the long term? I, I would say the answer is no. I mean, I use ransomware as the example, 'cause I, I deal with ransomware quite a bit.
I think there's a, there's a shift in understanding and, and the most mature organizations immediately know that a ransomware attack is not an IT or a cybersecurity issue. It's a business issue. 'cause the impact is a business issue.
And if it's a business issue, it requires a business solution. And so we see that, um, it manifested in ways that, um, or oftentimes, uh, played out, whether it's in a real incident or an exercise, uh, at that, uh, senior executive leadership team level and having conversations around the incident itself. What is the business impact?
Again, it's not a cybersecurity or IT issue, it's a business issue. And so what is, what is the executive team with, does management need to do to resolve that issue? And what are they trying to avoid in terms of business impact?
And I think there's a, there's a recognition that that's the case today, um, in a way that's more mature than we were a year ago. Still have a long way to go. And it's not, um, it, it's not universal.
Uh, but I think again, I think we're going just like we are with the boards in the right direction. Um, we just have a longer journey to, to, to, uh, move through. Nice.
And then what's your best advice to the CISOs and the security people out there as they try to have this conversation? I feel like some of them got access to the boards and the senior level executives, but the conversation isn't quite on the same, uh, are and cadence with each other. Yeah, I, I think I, I'll go back to something I said before, and it is one of the most difficult things for CISOs, particularly CISOs, that have grown up in the tech stack to translate that technical cyber risk into business risk to show that business impact.
And so I would say the most successful CISOs I see are the ones that can make that translation. So, you know, having the relationships with the business, ensuring that you understand what impact the business would have for certain types of incidents that may occur, and having those relationships and those discussions ahead of time. Um, the more you can do to, um, to craft your, your, um, your, just your conversations with the board, your conversations with management to the business impact, um, I think the more effective that you will be.
I mean, you can't just, you know, talk about the technical, uh, things that you wanna do and expect that translation to, to take place on its own. You need to be actively engaged, building those relationships, making sure you can translate that into business risk. And again, most successful CISOs that I know are able to do that very, very well.
And oftentimes the ones that are struggling, they're struggling because they haven't been able to make that connection. All right, folks, Sharon and here, business executives are comfortable with risk. Everything they do involves risk.
It's just, you gotta put it in terms they can understand. Hey Matt, thanks for being on the show. Happy to be here.
Nice to see you again. And back to you guys on the.