Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable Blog

Subscribe

The Era of Responsible Cybersecurity Finally Arrives

The Era of Responsible Cybersecurity Finally Arrives

The SEC’s proposed rule on cybersecurity promotes transparency and encourages free market forces.

The days of cyber negligence are numbered. While nobody can expect perfect cybersecurity, a vast supermajority of the painful breaches we learn about are the result of known vulnerabilities, lackadaisical security practices and poor cyber hygiene -- things that could have been avoided with diligence and care. It's an attitude that exudes fiduciary negligence and a blatant disregard for shareholders, partners, and customers.

The Securities and Exchange Commission's proposed rule on Cybersecurity Risk Management, Strategy, Governance and Incident Disclosure will trigger dramatic and long-overdue changes in how businesses disclose their cybersecurity policies, procedures, oversight and governance. It will force leaders to treat cybersecurity risk as a business risk -- something responsible executives started doing a long time ago -- and provide shareholders, customers, partners and the public with essential information needed to make responsible decisions.

The proposed rule requires public companies to disclose their policies and procedures for identifying and managing cybersecurity risks. It also requires disclosure of the oversight role and cybersecurity expertise of public companies’ leadership and board of directors over their cybersecurity risk assessment program. 

Before even reading the comments, I can hear all of those trying to shirk their responsibilities go on and on about the invasiveness of these draconian measures and the ill effects of government interference in corporate affairs and free markets. But free markets cannot work without transparency and informed decision making. Such measures will root out secrecy in the disclosure process and help us all understand which organizations are respecting the duty of care that they owe their customers and stakeholders. 

Cybersecurity breaches damage a company’s financial position. In addition to the costs of remediation and loss of customers, revenue and reputation, there are risks of shareholder lawsuits, customer lawsuits, increases in insurance premiums and increased scrutiny from auditors and regulators, distraction of management, and significant expenses. 

Former NSA Director Keith Alexander called cyber espionage, “the greatest transfer of wealth in history.” Cyber crime costs the US economy over $100 billion per year, and cost estimates of intellectual property theft surpass $250 billion per year. This is a real-world risk, and investors have a right to know whether or not a public company has robust cybersecurity risk assessment practices and policies in place so they can factor that risk into their investment decisions.

Today’s threat landscape is highly dynamic and requires organizations to continuously assess and defend against new tactics, techniques and procedures used by threat actors and cyber criminals. Continuous cyber risk assessments must be a foundational and strategic function. It is to the benefit of companies and shareholders to ensure that adequate cybersecurity controls and defenses are implemented. Requiring greater transparency of cyber risk practices and oversight promotes stronger cybersecurity governance and accountability among corporate leaders and boards and, ultimately, will produce a healthier market equilibrium.

While there are still details to be ironed out, the SEC’s proposed rule is an enormous step in the right direction and I hope the SEC doesn’t get derailed by those advocating for status quo.

Related Articles

Cybersecurity News You Can Use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Try Tenable Web App Scanning

Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.

Your Tenable Web App Scanning trial also includes Tenable Vulnerability Management and Tenable Lumin.

Buy Tenable Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

5 FQDNs

$3,578

Buy Now

Try Tenable Lumin

Visualize and explore your exposure management, track risk reduction over time and benchmark against your peers with Tenable Lumin.

Your Tenable Lumin trial also includes Tenable Vulnerability Management and Tenable Web App Scanning.

Buy Tenable Lumin

Contact a Sales Representative to see how Tenable Lumin can help you gain insight across your entire organization and manage cyber risk.

Try Tenable Nessus Professional Free

FREE FOR 7 DAYS

Tenable Nessus is the most comprehensive vulnerability scanner on the market today.

NEW - Tenable Nessus Expert
Now Available

Nessus Expert adds even more features, including external attack surface scanning, and the ability to add domains and scan cloud infrastructure. Click here to Try Nessus Expert.

Fill out the form below to continue with a Nessus Pro Trial.

Buy Tenable Nessus Professional

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Tenable Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy a multi-year license and save. Add Advanced Support for access to phone, community and chat support 24 hours a day, 365 days a year.

Select Your License

Buy a multi-year license and save.

Add Support and Training

Try Tenable Nessus Expert Free

FREE FOR 7 DAYS

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional?
Upgrade to Nessus Expert free for 7 days.

Buy Tenable Nessus Expert

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Select Your License

Buy a multi-year license and save more.

Add Support and Training