On the recordMarch 17, 2021
today I am reintroducing the Cybersecurity Disclosure Act along with three members of the Select Committee on Intelligence, Chairman Warner and Senators Collins and Wyden, in addition to Senators Cortez Masto and Cramer, who serve with me on the Senate Banking Committee. In response to serious data breaches of various companies, our legislation asks each publicly traded company to include--in Securities and Exchange Commission (SEC) disclosures to investors--information on whether any member of the Board of Directors is a cybersecurity expert, and if not, why having this expertise on the Board of Directors is not necessary because of other cybersecurity steps taken by the publicly traded company. To be clear, the legislation does not require companies to take any actions other than to provide this disclosure to its investors. As EY, also known as Ernst & Young, noted in an August 2020 publication, ``Public disclosures can help build trust by providing transparency and assurance around how boards are fulfilling their cybersecurity risk oversight responsibilities.'' Investors and customers deserve a clear understanding of whether publicly traded companies are prioritizing cybersecurity and have the capacity to protect investors and customers from cyber related attacks. Our legislation aims to provide a better understanding of these issues through improved SEC disclosures.…
Source
govinfo.gov




