Careers Form

" " indicates required fields

First name* 
Last name* 
This field is hidden when viewing the form
Max. file size: 256 MB.
Max. file size: 256 MB.
Untitled

We're committed to protect your privacy. C2A Security uses the information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy .

Office Administrator

  • Products
    • EVSec Platform
    • EVSec Analysis
    • EVSec BOM & Vulnerability Management
    • EVSec Attacker
    • EVSec Network & Endpoint Protection
    • EVSec SOC Enrichment & Analytics
    • EVSec AutoSynth AI
  • Use Cases
    • Medical and Healthcare
  • Integrations
  • Blog
  • Company
    • About
    • Events
    • Careers
  • Contact
  • Schedule a Demo
  • Products
    • EVSec Platform
    • EVSec Analysis
    • EVSec BOM & Vulnerability Management
    • EVSec Attacker
    • EVSec Network & Endpoint Protection
    • EVSec SOC Enrichment & Analytics
    • EVSec AutoSynth AI
  • Use Cases
    • Medical and Healthcare
  • Integrations
  • Blog
  • Company
    • About
    • Events
    • Careers
  • Contact
  • Schedule a Demo

New SEC Rules Require US-listed car makers to Reveal Cyber Attacks Within 4 Days

  • Category: Cybersecurity Regulation, Risk Assessment
  • July 31, 2023
Publicly traded companies must now comply with new SEC rules that mandate the disclosure of significant cybersecurity incidents within a tight timeframe of just 4 days. Issak Davidovich, our CTO, details what you need to know about the new rules and how they impact OEM’s risk management processes.

By Issak Davidovich, CTO

SEC Announces New Cyber Incident Disclosure Rules

The Securities and Exchange Commission (SEC) unveiled new regulations on Wednesday that will compel publicly traded companies to promptly disclose cyberattacks and data breaches. In a bid to enhance transparency and accountability, publicly-traded companies must now report significant cybersecurity incidents on Form 8-K within four business days of confirming an attack has taken place.

For the automotive industry, these new disclosure requirements may shed more light on cybersecurity practices as vehicles become increasingly connected. With reports of data breaches, CAN injections, EV charging stations being compromised, and more,  investors and consumers alike will gain more visibility into how automakers address potential vulnerabilities in their products, systems, sub-systems, and components.

Transparency and Accountability in Incident Reporting

Under the new regulations, companies must furnish comprehensive information regarding the nature, scope, and timing of the attack, along with any affected data or business operations. Additionally, ongoing efforts to rectify the situation must be disclosed. However, it is important to note that companies are not obliged to disclose specific details that might jeopardize their security or response capabilities.

Here’s the detailed information that must be disclosed on Form 8-K (if available at the time):

1. The date of discovery and status of the incident (ongoing or resolved).

2. A concise description of the incident’s nature and extent.

3. Any data that may have been compromised, altered, accessed, or used without authorization.

4. The impact of the incident on the company’s operations.

5. Information about ongoing or completed remediation efforts by the company.

Smaller companies (companies with less than $100 million in annual revenues) have been given a generous 180-day extension before they are required to comply with the new 8-K disclosures. However, it is important to note that these rules have a clear objective: to enhance transparency regarding cyber risks and empower investors to make well-informed decisions.

SEC Chair Gary Gensler suggests that companies and investors would greatly benefit from disclosing information in a consistent, comparable, and decision-useful manner.

Improvements in Cybersecurity Risk and Defense

While challenging for some, the new disclosure requirements are a step toward better informing investors and holding companies accountable for cybersecurity risk management. As Lesley Ritter of Moody’s Investors Service noted, increased transparency should ultimately “spur improvements in cyber defenses.”

The rules come more than a year after the SEC first proposed mandated cyber incident reporting in March 2022. Their adoption follows rising concerns over cyberattacks aimed at critical infrastructure and growing data breach threats impacting organizations of all types and sizes.

Frequently Asked Questions

1. In the automotive industry, we tend to separate IT incidents and the OEM’s “Products” (vehicles) incidents – are the new rules relevant for Vehicle Cyber Incidents?

Cyber incidents on connected vehicles have a major impact on the company. For example, during the TARA work, EVSec Platform guides the assessor to focus not only on the impact on the ‘road users’ but also on the brand and the business. So it’s our understanding that vehicle incidents are included.

2. As a car maker, how am I expected to understand the impact of a vehicle’s cyber incident in 4 days? This process alone usually takes weeks.

This very good question reveals the gaps between IT security, incident response and Vehicle incident response. Leveraging a CSMS (Cyber Security Management System) platform with BOM, HBOM, and vulnerability management built-in, including advanced risk assessment capabilities and automation, can improve response times from weeks to days.

3. What incidents require reporting, and what information must companies disclose?

Companies need to report cyber attacks and data breaches considered “material” – incidents shareholders consider important for investment decisions. Companies must disclose information regarding cybersecurity incidents, including the nature, scope, and timing of the attacks and any affected data or business operations. They also need to report on their ongoing or planned remediation efforts.

4. Can cybersecurity incident disclosures be delayed?

Yes. The SEC may allow delays if the Attorney General determines immediate disclosure would pose a national security or public safety risk.

5. Is anyone exempt from the new rule?

Smaller companies have been given a 180-day compliance extension before needing to adhere to the new 8-K disclosure requirements.

6. When will the new rules go into effect?

The final rules, adopted at a Commission open meeting on July 26, 2023, will become effective 30 days following the publication of the adopting release in the Federal Register. The Form 8-K and Form 6-K disclosures will be due beginning the later of 90 days after the date of publication in the Federal Register or December 18, 2023.

More articles that might interest you:
John Chenoweth, Chief Product Security Officer

C2A Security Announces Agreement with Elekta to Enhance Cybersecurity and Global Compliance

May 20, 2025
Industrial Robots at a factory

The Importance of Cybersecurity in Industrial Robotics: Protecting the Smart Manufacturing Floor

May 8, 2025

Critical Care: 2025 Hospital Cybersecurity Readiness Against Increased Medical Device Management Systems (MDMS) Threats

April 28, 2025

Follow Us

  • linkedin hover LinkedIn
  • Twitter
  • Facebook
Join our newsletter
  • linkedin hover LinkedIn
  • Twitter
  • Facebook
  • © 2025 All rights reserved C2A-SEC LTD 
  • Privacy Policy
Facebook-f Linkedin
  • Products
    • EVSec Platform
    • EVSec Analysis
    • EVSec BOM & Vulnerability Management
    • EVSec Attacker
    • EVSec Network & Endpoint Protection
    • EVSec SOC Enrichment & Analytics
    • EVSec AutoSynth AI
  • Use Cases
    • Medical and Healthcare
  • Integrations
  • Blog
  • Company
    • About
    • Events
    • Careers
  • Contact
  • Schedule a Demo
  • Products
    • EVSec Platform
    • EVSec Analysis
    • EVSec BOM & Vulnerability Management
    • EVSec Attacker
    • EVSec Network & Endpoint Protection
    • EVSec SOC Enrichment & Analytics
    • EVSec AutoSynth AI
  • Use Cases
    • Medical and Healthcare
  • Integrations
  • Blog
  • Company
    • About
    • Events
    • Careers
  • Contact
  • Schedule a Demo