TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

SEC now requires companies to disclose cyberattacks in 4 days

64 pointsby jdjdjdhhdalmost 2 years ago

5 comments

oxygen_crisisalmost 2 years ago
The cynic in me says this will incentivize execs to avoid starting the clock:<p>SRE: It looks like someone might be exfiltrating data from our network.<p>CISO: I doubt that. Look into it on Monday.<p>SRE: Today is Tuesday...<p>CISO: Look into it on Monday, we&#x27;ve got more important things to worry about. If you&#x27;ll excuse me, I need to call some old frat-mates about their trading portfolios.
评论 #36895483 未加载
CSMastermindalmost 2 years ago
I&#x27;m in favor of mandating disclosure. I wish they hadn&#x27;t limited it to the vague &#x27;has material impact&#x27; definition.<p>Under that rule if a company is being DDOSed constantly but their network is successfully mitigated against it presumably they wouldn&#x27;t need to disclose it.<p>But it would be in the general good of the public to be able to track these events, what their source is, etc.<p>At least this is a step in the right direction.
评论 #36888428 未加载
评论 #36888625 未加载
评论 #36903062 未加载
评论 #36890751 未加载
badrabbitalmost 2 years ago
This isn&#x27;t as good of a thing as you think. Instead of focusing on finding out the scope of the compromise and making sure the threat actors are contained and can&#x27;t easily compromise again, incident responders will ger pressures to focus on answering questions about who gets notified. They should be given enough time to thoroughly respond to it and then notify everyone that needs notifying.<p>Having to dedicate resources to scour through compromised data for pii instead of for forensic evidence before you even contain&#x2F;eradicate a threat only helps threat actors. The public does not benefit from bad or inefficient incident response.<p>I am sure HN crowd will get that this isn&#x27;t something you can just throw manpower&#x2F;bodycount at either to get a faster response. It takes as long as it has to take.
评论 #36892680 未加载
评论 #36903075 未加载
nubinetworkalmost 2 years ago
See also <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36881061">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36881061</a> <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36881188">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36881188</a>
Dracophoenixalmost 2 years ago
It seems that &quot;cyberattack&quot; will eventually replace &quot;hacking&quot; as the go-to word for every computer problem faced by a C-Suite sexagenarian.