Remove 2003 Remove Application Remove Mitigation Remove Risk Management
article thumbnail

Statutory Cyber Incident Reporting in the USA

Plan B Consulting

The first state to have this type of law was California in 2003 and all states have, on the whole, followed the basic tenets of their law. I haven’t seen anything which covers any penalties for failure to report an applicable cyber incident. Securities and Exchange Commission (SEC) Proposed Rules.

Banking 40