As the Trump 2.0 era approaches, uncertainty looms over SEC cybersecurity enforcement
Legal analysts note that in the first year of the U.S. Securities and Exchange Commission (SEC) implementing its "material" cybersecurity breach disclosure rule, most public filings have been vague and of limited value to investors. With Trump returning to the White House and Paul Atkins nominated to succeed as SEC chair, the rule faces the risk of being repealed or scaled back.

Legal analysts say that in the first year of the U.S. Securities and Exchange Commission (SEC) implementing "material" cybersecurity breach disclosure rules, most public company filings were vague and confusing, providing little value to investors.
They noted that the lack of Republican support for the rule within the SEC, coupled with doubts about its actual enforcement effectiveness, leaves the rule at risk of being repealed or at least scaled back after President-elect Donald Trump takes office.
"As a rule designed to provide information to investors, it has failed," said Scott Kimpel, a partner at Hunton Andrews Kurth, in an interview. "Whether the agency will bother to try to repeal it in the future remains to be seen."
Trump has vowed to significantly cut regulations across the federal government.
Earlier this month, he announced the selection of business consultant and cryptocurrency industry lobbyist Paul Atkins to serve as the next SEC chair. If confirmed, Atkins is widely expected to help advance Trump's vision of providing regulatory relief to businesses.
However, Kimpel said that with a range of controversial issues facing the SEC in the next administration—including cryptocurrency and climate change—it remains unclear whether repealing the cybersecurity rule will be a priority.
A 'balancing act' in breach disclosure
The SEC's cybersecurity rule requires disclosure to the agency within four days of determining a "material" breach. According to the SEC, the rule aims to provide investors with timely and "decision-useful" cybersecurity information, but as Kimpel observed, many companies provide minimal details about breaches in their filings.
"Very few filings tell you anything interesting or useful about the incident, other than that the company experienced an incident, had a temporary operational disruption, and has remediated it," he said. "That doesn't seem to be information that is material or decision-useful to investors."
Matthew Richardson, a partner at Brown Rudnick, expressed a similar view.
"There needs to be a balance, and I'm afraid the current approach isn't striking it correctly," he told CFO Dive.
According to Richardson, the cybersecurity rule puts public companies in a dilemma. On one hand, investors need to understand risks related to breaches; on the other, companies worry that disclosed details could be exploited by hackers.
Kimpel also noted that beyond insufficient details in many cases, some filings have also caused confusion among investors.
In early disclosures, some companies—such as Microsoft, Hewlett Packard Enterprise, and Prudential Financial—reported breaches they deemed immaterial after initial investigations. This prompted the SEC to issue guidance in May clarifying that its new breach reporting rule was not intended to cover immaterial incidents.
Republican opposition
The SEC adopted the rule last summer as part of a broader package of cybersecurity requirements. The rule passed on a 3-2 party-line vote, with Republican commissioners Hester Peirce and Mark Uyeda voting against it.
The breach disclosure provision was one of the most controversial aspects of the rulemaking. According to a fact sheet, the provision requires companies to determine the materiality of an incident "without unreasonable delay" after discovery, and if deemed material, generally to file an Item 1.05 Form 8-K within four business days of such determination.
The package also requires public companies to annually describe in Form 10-K the board's oversight of cybersecurity risks.
Wednesday (December 18) marked the one-year anniversary of the breach disclosure mandate taking effect.
An analysis by BreachRx, a cybersecurity incident management software provider, found that as of November 18, a total of 47 companies had filed 71 Form 8-Ks disclosing breaches.
"The results reveal confusion and caution among companies about whether and when to file, as well as a general failure to provide sufficient information to effectively protect companies from future SEC enforcement actions," said a report on the findings.
Less than half of the filings in the sample (48%) provided specific insight into the organization's incident response procedures. The remaining 52% offered only "boilerplate information," the report said.
SolarWinds lawsuit
Before these rules took effect, the SEC's cybersecurity enforcement program was governed by agency guidance.
In a high-profile case—filed in October 2023, after the rules were adopted but before they took effect—the SEC sued Austin, Texas-based software provider SolarWinds and its chief information security officer, Timothy Brown, alleging they defrauded investors by misrepresenting the company's cybersecurity practices before a major breach discovered in December 2020. The company denied the allegations.
In a July ruling, most of the lawsuit was dismissed. However, the core allegations remain.
The SEC's cybersecurity rule itself has not yet led to any enforcement actions. In October, the agency announced it had agreed to settle with four companies over allegations of misleading disclosures related to the 2020 SolarWinds hack, but the rule did not apply to those cases.
"These cases involve companies that experienced cybersecurity incidents before the new cybersecurity incident disclosure requirements took effect," said Lenin Lopez, a lawyer specializing in corporate governance and securities law at insurance brokerage Woodruff Sawyer, in an email.
Lopez said that given the rule has only been in effect for a year, the lack of cases directly stemming from it is not surprising. He also noted that the agency has clearly been closely monitoring how companies disclose cybersecurity incidents, at least based on comment letters responding to filings and guidance issued earlier this year.
"As for the outlook for 2025, while some speculate that the cyber disclosure rule will be scaled back or fully repealed, both outcomes would take time, and companies would be best served by operating without regard to those possibilities," Lopez said.
Michael Diver, a partner at Katten Muchin Rosenman, said the SEC could relax some cybersecurity reporting obligations, but full repeal is unlikely.
"The likelihood of the rule being rescinded is low because the stakes are too high for companies that experience cyber incidents," he said in an email.