Skip to main content
Privacy and Cybersecurity Update

SEC Chair: Sweeping New Cybersecurity Rules Are Coming Soon

February 8, 2022

On Monday, January 24, 2022, in a speech at the Northwestern University Pritzker School of Law annual Securities Regulation Institute conference, Gary Gensler, Chair of the U.S. Securities and Exchange Commission (SEC), announced that he has asked SEC staff to provide sweeping rulemaking recommendations to modernize and expand the agency’s rules relating to cybersecurity.1 Stressing that cybersecurity is a matter of national security, Chair Gensler signaled that new guidance or proposed rules would enhance or expand public company cybersecurity programs and risk disclosures; cybersecurity program requirements and breach notification obligations for SEC regulated entities under Reg S-P; and the scope of registrants covered under Regulation Systems Compliance and Integrity (Reg SCI). He also signaled the SEC’s continued focus on enforcement and cooperation with other law enforcement agencies.2

These SEC rules could broadly affect cybersecurity requirements across the U.S. securities markets, including for public securities issuers, SEC registrants (such as broker-dealers, investment advisers, investment companies, self-regulatory organizations (SROs), and alternative trading systems (ATSs)), and service providers to issuers and SEC-registered entities.

Given the potential scope and reach of the new rules, firms should monitor these developments and begin to consider how they may wish to comment on the SEC’s proposals and advocate with the agency to ensure that the SEC adopts final rules that are well informed, are harmonious with other relevant and well-developed cybersecurity compliance regimes, and will not impose inappropriate costs and compliance burdens. Below, we summarize the areas of SEC focus and identify related considerations, including certain guidance and best practices regarding existing SEC cybersecurity requirements. 

律师广告—Sidley Austin LLP 是一家全球性律师事务所。我们的地址及联系方式可在 www.sidley.com/en/locations/offices 查阅。

Sidley 提供本信息仅作为向客户及其他友好人士提供的服务,且仅供教育目的使用。本信息不应被解释或依赖为法律意见,亦不构成律师与客户关系。读者在未寻求专业顾问意见之前,不应依据本信息采取任何行动。Sidley 和 Sidley Austin 指 Sidley Austin LLP 及其关联合伙实体,详见 www.sidley.com/disclaimer

© Sidley Austin LLP