corporate cyber disclosure News

Congress Approves Cyber Attack Reporting Requirement for U.S. Companies

Companies critical to U.S. national interests will now have to report when they’re hacked or they pay ransomware, according to new rules approved by Congress. The rules are part of a broader effort by the Biden administration and Congress to …

New U.S. Rule Requires Banks to Promptly Report Cyber Incidents

U.S. banking regulators on Thursday finalized a rule that directs banks to report any major cybersecurity incidents to the government within 36 hours of discovery. Separately, the banking industry said it had successfully completed a massive cross-industry cyber security drill …

U.S. to Require Cyber Disclosure, Security Plans From ‘High Risk’ Air, Rail Companies

The Transportation Security Administration will introduce regulations that compel the most important U.S. railroad and airport operators to improve their cybersecurity procedures, Homeland Security Secretary Alejandro Mayorkas said on Wednesday. The upcoming changes will make it mandatory for “higher-risk” rail …

Washington Debates What to Do About Ransomware Payments, Cyber Reporting

More transparency is needed into what kind of cash payments are made after ransomware attacks, a top Democrat said, following a recent spate of cyber-attacks aimed at U.S. companies. Mark Warner, chairman of the Senate Intelligence Committee, spoke days after …

Companies That Are Open About Cyber Risks Fare Better With Investors

Research finds that when one company experiences a cybersecurity breach, other companies in the same field also become less attractive to investors. However, companies that are open about their cybersecurity risk management fare significantly better than peers that don’t disclose …

Express Scripts Fight Over Cyber Disclosure Reaches SEC

The U.S. Securities and Exchange Commission will review a dispute between Express Scripts Holding Co. and New York State Comptroller Thomas DiNapoli over his effort to force the prescription-benefits manager to increase cyber-risk disclosures. Express Scripts told the SEC last …