SEC Proposes New Requirements to Address Cybersecurity Risks to the U.S. Securities Markets
The Securities and Exchange Commission proposed new cybersecurity requirements for Market Entities to address growing digital threats and protect investor confidence.
The SEC proposed new rules mandating Market Entities implement reasonably designed cybersecurity policies, conduct annual reviews, and report significant incidents. Covered Entities must also publicly disclose material cybersecurity incidents to enhance market transparency. The proposal aims to mitigate systemic risks arising from interconnected systems and human or third-party errors.
The Securities and Exchange Commission proposed new cybersecurity requirements for Market Entities, including broker-dealers, clearing agencies, swap dealers, and exchanges, to address growing digital threats and protect investor confidence. The rules mandate that these entities implement reasonably designed cybersecurity policies, conduct annual reviews of their effectiveness, and report significant incidents to the SEC. Covered Entities must also publicly disclose material cybersecurity incidents to enhance market transparency. The proposal aims to mitigate systemic risks arising from interconnected systems and human or third-party errors, aligning with the SEC’s mission of investor protection and market integrity. The proposed requirements are designed to promote investor protection and orderly markets by improving cybersecurity practices among Market Entities. Public comments will be accepted for 60 days after the proposal’s Federal Register publication.
Exhibits & Attached Documents (2)
Extracted insights
- person cybersecurity risk
- person cybersecurity risks
- person data access
- company errors of employees, service providers, or business partners
- person federal register
- person gary gensler
- company information systems
- person market entities
- person proposing release
- agency Securities and Exchange Commission
- person threat actors
- SEC Proposed Requirements For Market Entities
- Gary Gensler Supports Proposal
- Cybersecurity Risks Have Grown Significantly
- Investors, Issuers, and Market Participants Would Benefit From Protections
- Market Entities Rely On Information Systems
- Threat Actors May Seek Data Access
- Errors of Employees, Service Providers, or Business Partners Can Cause Cybersecurity Risk
- Interconnectedness of Market Entities Increases Risk of Systemic Harm
- Proposal Would Require Market Entities to Implement Policies
- Proposal Would Improve Commission's Ability to Obtain Information
- New Public Disclosure Requirements Would Improve Transparency
- Proposing Release Will Be Published In Federal Register
The Securities and Exchange Commission today proposed requirements for broker-dealers, clearing agencies, major security-based swap participants, the Municipal Securities Rulemaking Board, national securities associations, national securities exchanges, security-based swap data repositories, security-based swap dealers, and transfer agents (collectively, “Market Entities”) to address their cybersecurity risks. “I am pleased to support this proposal because, if adopted, it would set standards for Market Entities’ cybersecurity practices,” said SEC Chair Gary Gensler. “The nature, scale, and impact of cybersecurity risks have grown significantly in recent decades. Investors, issuers, and market participants alike would benefit from knowing that these entities have in place protections fit for a digital age. This proposal would help promote every part of our mission, particularly regarding investor protection and orderly markets.” Market Entities increasingly rely on information systems to perform their functions and provide their services and thus are targets for threat actors who may seek to disrupt their functions or gain access to the data stored on the information systems for financial gain. Cybersecurity risk also can be caused by the errors of employees, service providers, or business partners. The interconnectedness of Market Entities increases the risk that a significant cybersecurity incident can simultaneously impact multiple Market Entities causing systemic harm to the U.S. securities markets. The proposal would require all Market Entities to implement policies and procedures that are reasonably designed to address their cybersecurity risks and, at least annually, review and assess the design and effectiveness of their cybersecurity policies and procedures, including whether they reflect changes in cybersecurity risk over the time period covered by the review. The proposal — through new notification requirements applicable to all Market Entities and additional reporting requirements applicable to Market Entities other than certain types of small broker-dealers (collectively, “Covered Entities”) — would improve the Commission’s ability to obtain information about significant cybersecurity incidents affecting these entities. Further, new public disclosure requirements for Covered Entities would improve transparency about the cybersecurity risks that can cause adverse impacts to the U.S. securities markets. The proposing release will be published in the Federal Register. The public comment period will remain open until 60 days after the date of publication of the proposing release in the Federal Register.
The Securities and Exchange Commission today proposed requirements for broker-dealers, clearing agencies, major security-based swap participants, the Municipal Securities Rulemaking Board, national securities associations, national securities exchanges, security-based swap data repositories, security-based swap dealers, and transfer agents (collectively, “Market Entities”) to address their cybersecurity risks. “I am pleased to support this proposal because, if adopted, it would set standards for Market Entities’ cybersecurity practices,” said SEC Chair Gary Gensler. “The nature, scale, and impact of cybersecurity risks have grown significantly in recent decades. Investors, issuers, and market participants alike would benefit from knowing that these entities have in place protections fit for a digital age. This proposal would help promote every part of our mission, particularly regarding investor protection and orderly markets.” Market Entities increasingly rely on information systems to perform their functions and provide their services and thus are targets for threat actors who may seek to disrupt their functions or gain access to the data stored on the information systems for financial gain. Cybersecurity risk also can be caused by the errors of employees, service providers, or business partners. The interconnectedness of Market Entities increases the risk that a significant cybersecurity incident can simultaneously impact multiple Market Entities causing systemic harm to the U.S. securities markets. The proposal would require all Market Entities to implement policies and procedures that are reasonably designed to address their cybersecurity risks and, at least annually, review and assess the design and effectiveness of their cybersecurity policies and procedures, including whether they reflect changes in cybersecurity risk over the time period covered by the review. The proposal — through new notification requirements applicable to all Market Entities and additional reporting requirements applicable to Market Entities other than certain types of small broker-dealers (collectively, “Covered Entities”) — would improve the Commission’s ability to obtain information about significant cybersecurity incidents affecting these entities. Further, new public disclosure requirements for Covered Entities would improve transparency about the cybersecurity risks that can cause adverse impacts to the U.S. securities markets. The proposing release will be published in the Federal Register. The public comment period will remain open until 60 days after the date of publication of the proposing release in the Federal Register.