The U.S. Securities and Exchange Commission (SEC) has issued over $150 million in fines in Q2 2026 for violations of its cybersecurity disclosure rules, signaling a significant escalation in enforcement activity. Companies have been cited for inadequate incident reporting timelines, misleading risk factor statements, and incomplete board oversight disclosures.
The SEC's Division of Enforcement has dedicated a specialized cyber unit that is actively reviewing public company filings for compliance with the 2023 cyber disclosure rules. The rules require companies to report material cybersecurity incidents within four business days and disclose their cyber risk management strategy and governance annually.
Legal experts advise companies to conduct thorough reviews of their SEC filings, ensure incident response plans include disclosure workflows, and document board-level cybersecurity oversight with greater detail.