critical infrastructure sectors “whose assets, systems, and networks, whether physical or
The U.S. SEC proposed a rule to require Market Entities to strengthen cybersecurity protections and report incidents, not to penalize fraud, as part of a regulatory framework under public comment with no charges or monetary penalties involved.
The U.S. Securities and Exchange Commission proposed a new rule to mandate cybersecurity policies and incident reporting for Market Entities, including broker-dealers, exchanges, and clearing agencies. Covered Entities must conduct risk assessments, implement protective controls, immediately notify the SEC of significant cyber incidents, and publicly disclose summaries of risks and incidents via Form SCIR. No fraud, charges, or financial penalties are alleged—this is a preventive regulatory proposal under a 60-day public comment period before potential adoption.
The U.S. Securities and Exchange Commission proposed a new rule to enhance cybersecurity protections across critical U.S. securities market infrastructure, targeting entities such as broker-dealers, exchanges, clearing agencies, and transfer agents. These Market Entities must establish, maintain, and annually review written cybersecurity policies reasonably designed to address evolving threats. Covered Entities face additional obligations, including conducting documented risk assessments, implementing access controls, monitoring systems, detecting and remediating vulnerabilities, and responding to incidents with detailed documentation. Upon a reasonable belief of a significant cybersecurity incident, Covered Entities must immediately notify the SEC electronically and file Part I of Form SCIR with incident details. They are also required to publicly disclose on Part II of Form SCIR a summary of their cybersecurity risks and incidents from the current or prior year, posting it on their website and providing it to customers. The rule does not allege any fraud, misconduct, or financial penalties—it is a forward-looking regulatory framework designed to mitigate systemic risk to financial markets. The proposal is currently under public comment for 60 days after Federal Register publication and will not take effect until finalized.
Extracted insights
- person covered entities
- agency the securities and exchange commission
- agency the u.s. securities and exchange commission
- The U.S. Securities And Exchange Commission Proposed A New Rule, Form, And Related Amendments
- The U.S. Securities And Exchange Commission Require Entities That Perform Critical Services To Support The Fair, Orderly, And Efficient Operations Of The U.S. Securities Markets To Address Their Cybersecurity Risks
- Proposed New Rule 10 Require All Market Entities To Establish, Maintain, And Enforce Written Policies And Procedures That Are Reasonably Designed To Address Their Cybersecurity Risks
- All Market Entities Review And Assess The Design And Effectiveness Of Their Cybersecurity Policies And Procedures, Including Whether They Reflect Changes In Cybersecurity Risk Over The Time Period Covered By The Review
- All Market Entities Give The Commission Immediate Written Electronic Notice Of A Significant Cybersecurity Incident Upon Having A Reasonable Basis To Conclude That The Significant Cybersecurity Incident Had Occurred Or Is Occurring
- The Securities And Exchange Commission Proposed A New Rule, Form, And Related Amendments
- The New Requirements Apply To Broker-Dealers, The Municipal Securities Rulemaking Board, Clearing Agencies, Major Security-Based Swap Participants, National Securities Associations, National Securities Exchanges, Security-Based Swap Data Repositories, Security-Based Swap Dealers, And Transfer Agents (Collectively, Market Entities)
- Market Entities—Other Than Certain Types Of Small Broker-Dealers Be Subject To Additional Requirements Under Proposed New Rule 10 As Covered Entities
- The Proposed Rule Require Covered Entities To Adopt Policies And Procedures To Address Cybersecurity Risks Would Need To Specifically Include The Following
- Covered Entities Include Periodic Assessments Of Cybersecurity Risks Associated With The Covered Entity’s Information Systems And Written Documentation Of The Risk Assessments
- Covered Entities Include Controls Designed To Minimize User-Related Risks And Prevent Unauthorized Access To The Covered Entity’s Information Systems
- Covered Entities Include Measures Designed To Monitor The Covered Entity’s Information Systems And Protect The Covered Entity’s Information From Unauthorized Access Or Use, And Oversee Service Providers That Receive, Maintain, Or Process Information Or Are Otherwise Permitted To Access The Covered Entity’s Information Systems
- Covered Entities Include Measures To Detect, Mitigate, And Remediate Any Cybersecurity Threats And Vulnerabilities With Respect To The Covered Entity’s Information Systems
- Covered Entities Include Measures To Detect, Respond To, And Recover From A Cybersecurity Incident
Warning: TT: undefined function: 32 FACT SHEET Addressing Cybersecurity Risks to the U.S. Securities Markets U.S. SECURITIES AND EXCHANGE COMMISSION PAGE 1 OF 2 Why This Matters The U.S. securities markets are part of the Financial Services Sector, one of the sixteen critical infrastructure sectors “whose assets, systems, and networks, whether physical or virtual, are considered so vital to the United States that their incapacitation or destruction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof,” according to the Cybersecurity and Infrastructure Security Agency. The Financial Services Sector increasingly is being attacked by cyber threat actors who use constantly evolving and sophisticated tactics, techniques, and procedures to cause harmful cybersecurity incidents. This poses a serious risk to the U.S. securities markets. The proposal is designed to address and mitigate this risk by requiring Market Entities to take measures to protect themselves and investors from the harmful impacts of cybersecurity incidents. How This New Rule and Form Would Apply Proposed new Rule 10 would require all Market Entities to establish, maintain, and enforce written policies and procedures that are reasonably designed to address their cybersecurity risks. All Market Entities also, at least annually, would be required to review and assess the design and effectiveness of their cybersecurity policies and procedures, including whether they reflect changes in cybersecurity risk over the time period covered by the review. All Market Entities also would need to give the Commission immediate written electronic notice of a significant cybersecurity incident upon having a reasonable basis to conclude that the significant cybersecurity incident had occurred or is occurring. The Securities and Exchange Commission proposed a new rule, form, and related amendments to require entities that perform critical services to support the fair, orderly, and efficient operations of the U.S. securities markets to address their cybersecurity risks. The new requirements would apply to broker-dealers, the Municipal Securities Rulemaking Board, clearing agencies, major security-based swap participants, national securities associations, national securities exchanges, security-based swap data repositories, security-based swap dealers, and transfer agents (collectively, “Market Entities”). FACT SHEET | Addressing Cybersecurity Risks to the U.S. Securities Markets U.S. SECURITIES AND EXCHANGE COMMISSION Page 2 of 2 Market Entities—other than certain types of small broker-dealers—would be subject to additional requirements under proposed new Rule 10 as “Covered Entities.” First, the proposed rule would require Covered Entities to adopt policies and procedures to address cybersecurity risks would need to specifically include the following: • Periodic assessments of cybersecurity risks associated with the Covered Entity’s information systems and written documentation of the risk assessments; • Controls designed to minimize user-related risks and prevent unauthorized access to the Covered Entity’s information systems; • Measures designed to monitor the Covered Entity’s information systems and protect the Covered Entity’s information from unauthorized access or use, and oversee service providers that receive, maintain, or process information or are otherwise permitted to access the Covered Entity’s information systems; • Measures to detect, mitigate, and remediate any cybersecurity threats and vulnerabilities with respect to the Covered Entity’s information systems; and • Measures to detect, respond to, and recover from a cybersecurity incident and procedures to create written documentation of any cybersecurity incident and the response to and recovery from the incident. Second, after providing immediate written electronic notice of a significant cybersecurity incident, Covered Entities would need to report to the Commission and update information about the significant cybersecurity incident by filing Part I of proposed Form SCIR. The form would elicit information about the significant cybersecurity incident and the Covered Entity’s efforts to respond to and recover from the incident. Third, the proposal would require Covered Entities to publicly disclose summary descriptions of their cybersecurity risks and the significant cybersecurity incidents they experienced during the current or previous calendar year on Part II of proposed Form SCIR. A Covered Entity would need to file the form with the Commission and post it on its website. Covered Entities that are carrying or introducing broker-dealers would also need to provide the form to customers at account opening, when information on the form is updated, and annually. Additional Information: The public comment period will remain open until 60 days after the date of publication of the proposing release in the Federal Register.
FACT SHEET Addressing Cybersecurity Risks to the U.S. Securities Markets U.S. SECURITIES AND EXCHANGE COMMISSION PAGE 1 OF 2 Why This Matters The U.S. securities markets are part of the Financial Services Sector, one of the sixteen critical infrastructure sectors “whose assets, systems, and networks, whether physical or virtual, are considered so vital to the United States that their incapacitation or destruction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof,” according to the Cybersecurity and Infrastructure Security Agency. The Financial Services Sector increasingly is being attacked by cyber threat actors who use constantly evolving and sophisticated tactics, techniques, and procedures to cause harmful cybersecurity incidents. This poses a serious risk to the U.S. securities markets. The proposal is designed to address and mitigate this risk by requiring Market Entities to take measures to protect themselves and investors from the harmful impacts of cybersecurity incidents. How This New Rule and Form Would Apply Proposed new Rule 10 would require all Market Entities to establish, maintain, and enforce written policies and procedures that are reasonably designed to address their cybersecurity risks. All Market Entities also, at least annually, would be required to review and assess the design and effectiveness of their cybersecurity policies and procedures, including whether they reflect changes in cybersecurity risk over the time period covered by the review. All Market Entities also would need to give the Commission immediate written electronic notice of a significant cybersecurity incident upon having a reasonable basis to conclude that the significant cybersecurity incident had occurred or is occurring. The Securities and Exchange Commission proposed a new rule, form, and related amendments to require entities that perform critical services to support the fair, orderly, and efficient operations of the U.S. securities markets to address their cybersecurity risks. The new requirements would apply to broker-dealers, the Municipal Securities Rulemaking Board, clearing agencies, major security-based swap participants, national securities associations, national securities exchanges, security-based swap data repositories, security-based swap dealers, and transfer agents (collectively, “Market Entities”). FACT SHEET | Addressing Cybersecurity Risks to the U.S. Securities Markets U.S. SECURITIES AND EXCHANGE COMMISSION Page 2 of 2 Market Entities—other than certain types of small broker-dealers—would be subject to additional requirements under proposed new Rule 10 as “Covered Entities.” First, the proposed rule would require Covered Entities to adopt policies and procedures to address cybersecurity risks would need to specifically include the following: • Periodic assessments of cybersecurity risks associated with the Covered Entity’s information systems and written documentation of the risk assessments; • Controls designed to minimize user-related risks and prevent unauthorized access to the Covered Entity’s information systems; • Measures designed to monitor the Covered Entity’s information systems and protect the Covered Entity’s information from unauthorized access or use, and oversee service providers that receive, maintain, or process information or are otherwise permitted to access the Covered Entity’s information systems; • Measures to detect, mitigate, and remediate any cybersecurity threats and vulnerabilities with respect to the Covered Entity’s information systems; and • Measures to detect, respond to, and recover from a cybersecurity incident and procedures to create written documentation of any cybersecurity incident and the response to and recovery from the incident. Second, after providing immediate written electronic notice of a significant cybersecurity incident, Covered Entities would need to report to the Commission and update information about the significant cybersecurity incident by filing Part I of proposed Form SCIR. The form would elicit information about the significant cybersecurity incident and the Covered Entity’s efforts to respond to and recover from the incident. Third, the proposal would require Covered Entities to publicly disclose summary descriptions of their cybersecurity risks and the significant cybersecurity incidents they experienced during the current or previous calendar year on Part II of proposed Form SCIR. A Covered Entity would need to file the form with the Commission and post it on its website. Covered Entities that are carrying or introducing broker-dealers would also need to provide the form to customers at account opening, when information on the form is updated, and annually. Additional Information: The public comment period will remain open until 60 days after the date of publication of the proposing release in the Federal Register. Why This Matters How This New Rule and Form Would Apply Additional Information: