Cyber-attacks on US-listed companies will now need to be disclosed by the business within four days, a statement by the Securities and Exchange Commission (SEC) said.
Requirements for companies to disclose how they are managing cybersecurity risks have also been introduced by the US agency.
“Whether a company loses a factory in a fire — or millions of files in a cybersecurity incident — it may be material to investors,” said the SEC chair Gary Gensler.
Investors should be able to compare the difference in approaches between companies in a more “consistent and decision-useful way”, reckons Gensler.
Management and the board of directors will also be required to disclose their roles and expertise in managing digital threats in a company's annual report.
Hacks, particularly ransomware attacks, have surged in the last year, specifically by Russian-linked actors, and because there is very little governments can do in pursuing the criminals, the focus has switched to defence.
In the UK, organisations like Ofcom, BBC, British Airways and Capita all suffered cyber-attacks in 2023.