2023-03-15 SEC Press pdf 246 KB 5,217 chars

critical infrastructure sectors “whose assets, systems, and networks, whether physical or

summary

The U.S. SEC proposed a rule to require Market Entities to strengthen cybersecurity protections and report incidents, not to penalize fraud, as part of a regulatory framework under public comment with no charges or monetary penalties involved.

paragraph

The U.S. Securities and Exchange Commission proposed a new rule to mandate cybersecurity policies and incident reporting for Market Entities, including broker-dealers, exchanges, and clearing agencies. Covered Entities must conduct risk assessments, implement protective controls, immediately notify the SEC of significant cyber incidents, and publicly disclose summaries of risks and incidents via Form SCIR. No fraud, charges, or financial penalties are alleged—this is a preventive regulatory proposal under a 60-day public comment period before potential adoption.

narrative

The U.S. Securities and Exchange Commission proposed a new rule to enhance cybersecurity protections across critical U.S. securities market infrastructure, targeting entities such as broker-dealers, exchanges, clearing agencies, and transfer agents. These Market Entities must establish, maintain, and annually review written cybersecurity policies reasonably designed to address evolving threats. Covered Entities face additional obligations, including conducting documented risk assessments, implementing access controls, monitoring systems, detecting and remediating vulnerabilities, and responding to incidents with detailed documentation. Upon a reasonable belief of a significant cybersecurity incident, Covered Entities must immediately notify the SEC electronically and file Part I of Form SCIR with incident details. They are also required to publicly disclose on Part II of Form SCIR a summary of their cybersecurity risks and incidents from the current or prior year, posting it on their website and providing it to customers. The rule does not allege any fraud, misconduct, or financial penalties—it is a forward-looking regulatory framework designed to mitigate systemic risk to financial markets. The proposal is currently under public comment for 60 days after Federal Register publication and will not take effect until finalized.

Enriched metadata

Scheme
unclassified
Classified unclassified. No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
covered entitiesthe securities and exchange commissionthe u.s. securities and exchange commission
Keywords
cybersecuritycovered entitycybersecurity riskscybersecurity incidentcoveredentitiessecuritiesmarket entitiessignificant cybersecurityentity informationsecurities marketscovered entitiesinformation systemsinformationsystems

Extracted insights

Entities 3
  • person covered entities
  • agency the securities and exchange commission
  • agency the u.s. securities and exchange commission
Triples 14
  • The U.S. Securities And Exchange Commission Proposed A New Rule, Form, And Related Amendments
  • The U.S. Securities And Exchange Commission Require Entities That Perform Critical Services To Support The Fair, Orderly, And Efficient Operations Of The U.S. Securities Markets To Address Their Cybersecurity Risks
  • Proposed New Rule 10 Require All Market Entities To Establish, Maintain, And Enforce Written Policies And Procedures That Are Reasonably Designed To Address Their Cybersecurity Risks
  • All Market Entities Review And Assess The Design And Effectiveness Of Their Cybersecurity Policies And Procedures, Including Whether They Reflect Changes In Cybersecurity Risk Over The Time Period Covered By The Review
  • All Market Entities Give The Commission Immediate Written Electronic Notice Of A Significant Cybersecurity Incident Upon Having A Reasonable Basis To Conclude That The Significant Cybersecurity Incident Had Occurred Or Is Occurring
  • The Securities And Exchange Commission Proposed A New Rule, Form, And Related Amendments
  • The New Requirements Apply To Broker-Dealers, The Municipal Securities Rulemaking Board, Clearing Agencies, Major Security-Based Swap Participants, National Securities Associations, National Securities Exchanges, Security-Based Swap Data Repositories, Security-Based Swap Dealers, And Transfer Agents (Collectively, Market Entities)
  • Market Entities—Other Than Certain Types Of Small Broker-Dealers Be Subject To Additional Requirements Under Proposed New Rule 10 As Covered Entities
  • The Proposed Rule Require Covered Entities To Adopt Policies And Procedures To Address Cybersecurity Risks Would Need To Specifically Include The Following
  • Covered Entities Include Periodic Assessments Of Cybersecurity Risks Associated With The Covered Entity’s Information Systems And Written Documentation Of The Risk Assessments
  • Covered Entities Include Controls Designed To Minimize User-Related Risks And Prevent Unauthorized Access To The Covered Entity’s Information Systems
  • Covered Entities Include Measures Designed To Monitor The Covered Entity’s Information Systems And Protect The Covered Entity’s Information From Unauthorized Access Or Use, And Oversee Service Providers That Receive, Maintain, Or Process Information Or Are Otherwise Permitted To Access The Covered Entity’s Information Systems
  • Covered Entities Include Measures To Detect, Mitigate, And Remediate Any Cybersecurity Threats And Vulnerabilities With Respect To The Covered Entity’s Information Systems
  • Covered Entities Include Measures To Detect, Respond To, And Recover From A Cybersecurity Incident
Text layers
Extracted body text (5,217c)
Warning: TT: undefined function: 32

FACT SHEET
Addressing
Cybersecurity Risks
to the U.S. Securities
Markets

U.S. SECURITIES AND EXCHANGE COMMISSION  PAGE 1 OF 2

Why This Matters
The  U.S.  securities  markets  are  part  of  the  Financial  Services  Sector,  one  of  the  sixteen
critical  infrastructure  sectors  “whose  assets,  systems,  and  networks,  whether  physical  or
virtual,  are  considered  so  vital  to  the  United  States  that  their  incapacitation  or  destruction
would have a debilitating effect on security, national economic security, national public health
or  safety,  or  any  combination  thereof,”  according  to  the  Cybersecurity  and  Infrastructure
Security  Agency.  The  Financial  Services  Sector  increasingly  is  being  attacked  by  cyber
threat  actors  who  use  constantly evolving  and  sophisticated  tactics,  techniques,  and
procedures to cause harmful cybersecurity incidents. This poses a serious risk to the U.S.
securities markets. The proposal is designed to address and mitigate this risk by requiring
Market  Entities  to  take  measures  to  protect  themselves  and  investors from  the  harmful
impacts of cybersecurity incidents.

How This New Rule and Form Would Apply
Proposed new Rule 10 would require all Market Entities to establish, maintain, and enforce
written policies and procedures that are reasonably designed to address their cybersecurity
risks. All Market Entities also, at least annually, would be required to review and assess the
design and effectiveness of their cybersecurity policies and procedures, including whether
they  reflect  changes  in  cybersecurity  risk  over  the  time  period  covered  by  the  review.  All
Market Entities also would need to give the Commission immediate written electronic notice
of a significant cybersecurity incident upon having a reasonable basis to conclude that the
significant cybersecurity incident had occurred or is occurring.

The Securities and Exchange Commission proposed a new rule, form, and related amendments
to require entities that perform critical services to  support the fair, orderly, and efficient operations
of the U.S. securities markets to address their cybersecurity risks. The new requirements would
apply  to  broker-dealers,  the  Municipal  Securities  Rulemaking  Board, clearing  agencies,  major
security-based   swap   participants, national   securities   associations,   national   securities
exchanges,  security-based  swap  data  repositories,  security-based  swap  dealers,  and  transfer
agents (collectively, “Market Entities”).

FACT SHEET | Addressing Cybersecurity Risks to the U.S. Securities Markets

U.S. SECURITIES AND EXCHANGE COMMISSION  Page 2 of 2
Market  Entities—other  than  certain  types  of  small  broker-dealers—would  be  subject  to
additional requirements under proposed new Rule 10 as “Covered Entities.”
First, the proposed rule would require Covered Entities to adopt policies and procedures to
address cybersecurity risks would need to specifically include the following:
• Periodic  assessments  of  cybersecurity  risks  associated  with  the  Covered  Entity’s
information systems and written documentation of the risk assessments;

• Controls designed to minimize user-related risks and prevent unauthorized access to the
Covered Entity’s information systems;

• Measures designed to monitor the Covered Entity’s information systems and protect the
Covered  Entity’s  information  from  unauthorized  access  or  use,  and  oversee  service
providers  that  receive,  maintain,  or  process  information  or  are  otherwise  permitted  to
access the Covered Entity’s information systems;

• Measures to detect, mitigate, and remediate any cybersecurity threats and vulnerabilities
with respect to the Covered Entity’s information systems; and

• Measures  to  detect,  respond  to,  and  recover  from  a  cybersecurity  incident  and
procedures  to  create written  documentation  of  any  cybersecurity  incident  and  the
response to and recovery from the incident.
Second, after  providing  immediate  written  electronic  notice  of  a  significant  cybersecurity
incident, Covered Entities would need to report to the Commission and update information
about the significant cybersecurity incident by filing Part I of proposed Form SCIR. The form
would elicit information about the significant cybersecurity incident and the Covered Entity’s
efforts to respond to and recover from the incident.
Third, the proposal would require Covered Entities to publicly disclose summary descriptions
of  their  cybersecurity  risks  and  the  significant  cybersecurity  incidents  they  experienced
during the current or previous calendar year on Part II of proposed Form SCIR. A Covered
Entity would need to file the form with the Commission and post it on its  website. Covered
Entities that are carrying or introducing broker-dealers would also need to provide the form
to customers at account opening, when information on the form is updated, and annually.

Additional Information:
The public comment period will remain open until 60 days after the date of publication of the proposing release
in the Federal Register.
OCR text (5,167c · tika · 95% conf)
FACT SHEET 
Addressing 
Cybersecurity Risks 
to the U.S. Securities 
Markets 

 

U.S. SECURITIES AND EXCHANGE COMMISSION  PAGE 1 OF 2 

 

 
Why This Matters 
The U.S. securities markets are part of the Financial Services Sector, one of the sixteen 
critical infrastructure sectors “whose assets, systems, and networks, whether physical or 
virtual, are considered so vital to the United States that their incapacitation or destruction 
would have a debilitating effect on security, national economic security, national public health 
or safety, or any combination thereof,” according to the Cybersecurity and Infrastructure 
Security Agency. The Financial Services Sector increasingly is being attacked by cyber 
threat actors who use constantly evolving and sophisticated tactics, techniques, and 
procedures to cause harmful cybersecurity incidents. This poses a serious risk to the U.S. 
securities markets. The proposal is designed to address and mitigate this risk by requiring 
Market Entities to take measures to protect themselves and investors from the harmful 
impacts of cybersecurity incidents. 

 

How This New Rule and Form Would Apply 
Proposed new Rule 10 would require all Market Entities to establish, maintain, and enforce 
written policies and procedures that are reasonably designed to address their cybersecurity 
risks. All Market Entities also, at least annually, would be required to review and assess the 
design and effectiveness of their cybersecurity policies and procedures, including whether 
they reflect changes in cybersecurity risk over the time period covered by the review. All 
Market Entities also would need to give the Commission immediate written electronic notice 
of a significant cybersecurity incident upon having a reasonable basis to conclude that the 
significant cybersecurity incident had occurred or is occurring. 

 

 
The Securities and Exchange Commission proposed a new rule, form, and related amendments 
to require entities that perform critical services to support the fair, orderly, and efficient operations 
of the U.S. securities markets to address their cybersecurity risks. The new requirements would 
apply to broker-dealers, the Municipal Securities Rulemaking Board, clearing agencies, major 
security-based swap participants, national securities associations, national securities 
exchanges, security-based swap data repositories, security-based swap dealers, and transfer 
agents (collectively, “Market Entities”). 
 



FACT SHEET | Addressing Cybersecurity Risks to the U.S. Securities Markets 
 

U.S. SECURITIES AND EXCHANGE COMMISSION  Page 2 of 2 

Market Entities—other than certain types of small broker-dealers—would be subject to 
additional requirements under proposed new Rule 10 as “Covered Entities.” 

First, the proposed rule would require Covered Entities to adopt policies and procedures to 
address cybersecurity risks would need to specifically include the following: 

• Periodic assessments of cybersecurity risks associated with the Covered Entity’s 
information systems and written documentation of the risk assessments; 
 

• Controls designed to minimize user-related risks and prevent unauthorized access to the 
Covered Entity’s information systems; 
 

• Measures designed to monitor the Covered Entity’s information systems and protect the 
Covered Entity’s information from unauthorized access or use, and oversee service 
providers that receive, maintain, or process information or are otherwise permitted to 
access the Covered Entity’s information systems; 
 

• Measures to detect, mitigate, and remediate any cybersecurity threats and vulnerabilities 
with respect to the Covered Entity’s information systems; and 
 

• Measures to detect, respond to, and recover from a cybersecurity incident and 
procedures to create written documentation of any cybersecurity incident and the 
response to and recovery from the incident. 

Second, after providing immediate written electronic notice of a significant cybersecurity 
incident, Covered Entities would need to report to the Commission and update information 
about the significant cybersecurity incident by filing Part I of proposed Form SCIR. The form 
would elicit information about the significant cybersecurity incident and the Covered Entity’s 
efforts to respond to and recover from the incident. 

Third, the proposal would require Covered Entities to publicly disclose summary descriptions 
of their cybersecurity risks and the significant cybersecurity incidents they experienced 
during the current or previous calendar year on Part II of proposed Form SCIR. A Covered 
Entity would need to file the form with the Commission and post it on its website. Covered 
Entities that are carrying or introducing broker-dealers would also need to provide the form 
to customers at account opening, when information on the form is updated, and annually. 

 

Additional Information: 
The public comment period will remain open until 60 days after the date of publication of the proposing release 
in the Federal Register.  


	Why This Matters
	How This New Rule and Form Would Apply
	Additional Information: