Securities Regulation and Corporate Governance


Division of Corporation Finance Issues Interpretive Guidance on the SEC’s Cybersecurity Incident Reporting Requirements

​As discussed in our previous client alert, on December 18, 2023, new rules went into effect requiring companies to report material cybersecurity incidents on Form 8-K within four business days of the company's determination that the cybersecurity incident is material. In the last several weeks the staff of the Division of Corporation Finance (the “Staff") of the Securities and Exchange Commission (the “SEC") has provided guidance regarding incident reporting in the form of a May 21 statement and a June 20 announcement from the Division of Corporation Finance Director Erik Gerding and, most recently, more formal Compliance and Disclosure Interpretations (“C&DIs") on June 24.

Recent Guidance from the Director of the Division of Corporation Finance

Announcement Regarding Selective Disclosure. On June 20, 2024, Division of Corporation Finance Director Erik Gerding clarified in an announcement that “[n]othing in Item 1.05 prohibits a company from privately discussing a material cybersecurity incident with other parties or from providing information about the incident to such parties beyond what was included in an Item 1.05 Form 8-K."  Gerding noted that sharing information with commercial counterparties, such as vendors and customers, as well as other companies that may be impacted by, or at risk from, the same incident or threat actor may assist with remediation, mitigation, or risk avoidance efforts and may facilitate those parties' compliance with their own incident disclosure and reporting obligations.

Statement Regarding Use of Item 1.05 vs. 7.01/8.01.  Previously, on May 21, 2024, Gerding released a statement setting forth certain of his views with respect to when it is appropriate to use Item 1.05 of Form 8-K, as opposed to Item 7.01 or Item 8.01, to report a cybersecurity incident. More details on Gerding's statement can be found in our previous blog post.

New Compliance and Disclosure Interpretations

On June 24, 2024, the Staff issued five new C&DIs related to Item 1.05, all of which address ransomware. We believe that the Staff may be concern...

Preparing for CDP’s New Sustainability Reporting Platform

Earlier this month, CDP (formerly known as the Carbon Disclosure Project) announced the launch of a new environmental disclosure platform. CDP is a non-profit that scores and assesses participating companies and cities, states, and regions on climate, deforestation, and water security topics. According to CDP, over 23,000 companies (representing two-thirds of global market capitalization) disclosed through CDP in 2023.

Platform Updates. The new platform brings two important changes to CDP's voluntary environmental questionnaire system that are intended to ease participants' reporting burdens and better harmonize global reporting standards. First, it replaces CDP's separate questionnaires regarding climate change, forests, water, biodiversity, and plastics with one integrated questionnaire covering these issues. Second, the new integrated questionnaire aligns with the International Sustainability Standards Board's climate standard (“IFRS S2") and incorporates other global standards like the Taskforce on Nature-related Financial Disclosures (“TNFD") and the European Sustainability Reporting Standards (“ESRS").

According to CDP, while the questionnaire format may look different, the information requested and CDP scoring system have not fundamentally changed. There will still be questions and scores specific to particular environmental issues, and companies will continue to be scored separately on climate change, forests, and water security.

Reporting Considerations. The CDP reporting window opened on June 4, 2024. All responding entities must submit their responses by CDP's scoring deadline on September 18, 2024 in order to be scored. Responses submitted after the scoring deadline but on or before October 2, 2024 will not be scored, but will be made available to certain stakeholders and in CDP data analytics.

Companies intending to complete a CDP questionnaire this year should consider the following:

  • CDP Changes May Impact Scores and Responses. Before jumping in, companies may benefit from reviewing the key changes to the CDP questionnaire and considering how these changes might impact their scoring and disclosures. Summaries of cha...
Updated Summary of Director Education Opportunities Now Available

Gibson Dunn's summary of director education opportunities has been updated as of June 2024. A copy is available at this link. Boards of Directors of public and private companies find this a useful resource as they look for high quality education opportunities. 

This quarter's update includes a number of new opportunities as well as updates to the programs offered by organizations that have been included in our prior updates. Some of the new opportunities are available for both public and private companies' boards. ​

Thank you to associates Caroline Bakewell and Ben Blefeld and summer associate Fumin Li, all in our Houston office, for their assistance with this quarter's update.

Reminder to 13G Filers on Upcoming Phase-In of SEC Amendments to Beneficial Ownership Filing Deadlines

​As previously noted in our client alert, certain of the SEC amendments to beneficial ownership reporting rules adopted in October 2023 will go into effect on September 30, 2024. As a quick reminder, for Passive Investors (i.e., those reporting on Schedule 13G pursuant to Rule 13d-1(c) who beneficially own less than 20%) and Qualified Institutional Investors (“QIIs") (i.e., those reporting on Schedule 13G pursuant to Rule 13d-1(b) such as registered investment advisers, investment companies, banks, etc.), there are a few upcoming changes to be aware of, particularly with respect to amendment obligations to disclose material changes. 

Under the beneficial ownership rules currently applicable to Passive Investors and QIIs, reporting persons must file an annual amendment within 45 days of year-end if there is any change in the information previously disclosed in their filing (other than percentage ownership figures that might fluctuate as a result of changes in the total number of shares outstanding). Both categories of 13G reporting persons are subject to an accelerated amendment obligation when their reported beneficial ownership changes by more than 5%. In this situation, Passive Investors must file a 13G amendment “promptly," which is generally understood and treated in practice as requiring an amendment within two to three business days, and QIIs must file a 13G amendment within ten business days of the relevant month-end.

Under the amended beneficial ownership reporting rules that go into effect as of September 30, material changes to prior disclosures (i.e., 1% or greater changes in beneficial ownership) will trigger a 13G amendment obligation for both Passive Investors and QIIs on a quarterly basis, with filings due within 45 days of quarter-end (beginning September 30).  As such, the first quarterly 13G amendment will be due no later than November 14, 2024. For greater than 5% changes in beneficial ownership, Passive Investors must file an amendment within two business days, and QIIs must file an amendment within five business days of the relevant month-end. In practice, the amended deadline of two business days for Passive Investors is no different than the current standard of “promptly," but the filing deadline is now memorialized directly in the rules leaving less room for error.

Thus, as the second phase of implementation of the SEC's be...

Eighth Circuit Establishes Briefing Schedule for SEC Climate Disclosure Rules Litigation

​On May 20, 2024, the U.S. Court of Appeals for the Eighth Circuit issued an order establishing the briefing schedule for the consolidated litigation challenging the Securities and Exchange Commission's (“SEC") final climate disclosure rules.

The order set the following deadlines for the upcoming summer and early fall:

  • June 14, 2024: Petitioners' opening brief
  • June 24, 2024: Briefs by supporting intervenors or amici
  • August 5, 2024: Respondent's consolidated response brief
  • August 15, 2024: Briefs by supporting intervenors or amici
  • September 3, 2024: Petitioners' reply brief

Oral arguments could occur before the end of 2024.

The climate disclosure rules, described in more detail in our client alert, are not currently in force. As we previously reported, in response to lawsuits by the U.S. Chamber of Commerce and others, the SEC voluntarily stayed implementation of the final rules in April 2024 pending the completion of judicial review of the consolidated Eighth Circuit cases. In addition, the SEC stated in a subsequent court filing that its voluntary stay eliminates the harms challengers had asserted that compliance with the rule would impose, including in the form of costs incurred to prepare for compliance with the rule,  and that “[t]he Commission will publish a document in the Federal Register at the conclusion of the stay addressing a new effective date for the [final climate disclosure rules]." While the SEC has not specified the duration of the further implementation period if the rules survive the litigation, it thus has confirmed that a new implementation period will be provided.

In the interim, companies may prefer to monitor the litigation and delay significant compliance investments until the litigation is resolved. A complete delay in preparing for climate-reporting may not be feasible, however, for companies who are additionally preparing to address climate and other sustainability-related disclosure obligations under other reporting regimes, such as the European Union's Corporate Sustainability Reporting Directive.

*  *  *

Thank you to associates Lauren Assaf-Holmes and Antony Nguyen from our Orange County office for their assistance with this update.

SEC Division of Corporation Finance Director Erik Gerding Offers Guidance on Form 8-K Disclosure of Cybersecurity Incidents

​As detailed in our client alert, the SEC adopted cybersecurity disclosure rules on July 26, 2023 that require disclosure of material cybersecurity incidents under new Item 1.05 of Form 8-K. If a company determines that a cybersecurity incident is material, it is required to disclose the incident within four (4) business days of such determination. In addition, such determination is required to be made “without unreasonable delay after discovery of the incident."  Item 1.05 states companies must describe the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the company, including on its financial condition and results of operations. If any of the required information is not determinable or unavailable at the time of the initial filing, companies must provide updated disclosure in a Form 8-K amendment.   

Companies have often encountered challenges in reaching a materiality determination with respect to cybersecurity incidents due to the often tedious process of evaluating the nature and scope of an incident, the extent of unknown information, and the difficulty of assessing future consequences, particularly in the context of an evolving situation. Since the new rules went into effect, companies now must conduct an on-going reassessment of whether the incident has crossed the tipping point to become, in some aspect, material to investors, based on the known state of information and assessment of potential impacts.  As such, companies facing potential scrutiny for not making timely disclosure have opted to voluntarily disclose cybersecurity incidents before reaching a definitive materiality determination, with many disclosing under Item 1.05 and others under Item 8.01 or 7.01. In fact, as of May 22, 2024, 17 companies have disclosed cybersecurity incidents under Item 1.05 over the course of 26 filings (inclusive of 8-K amendments) whereas 7 companies reported cybersecurity incidents under Item 7.01 or 8.01.  Of those 17 companies reporting events under Item 1.05, with some companies disclosing material operational impact while the incident was ongoing or material impact on financial quarterly results, most of these companies disclosed no material impact on their operations and also generally disclosed (either as part of original filing or by amendment) that the cyber incidents have not had, or were not expected to have, a material impact on such companies' overall financial condition or results of operations (or that companies have not yet made a materiality determination).

On May 21, 2024, Division of Corporation Finance Director Erik Gerding released a

Send Comment to EditorSend comment to Editor
Reminder: Securities Settlement Cycle Transitions to T+1 on May 28, 2024

​​As previously reported on our Securities Regulation and Corporate Governance Monitor (available here and here), on May 28, 2024, the standard settlement cycle for most broker-dealer transactions will be shortened from “T+2" to “T+1," subject to certain exceptions.  The SEC approved this change in its rule amendments to Rule 15c6-1(a) under the Exchange Act adopted on February 15, 2023.  SEC Chair Gary Gensler today issued a statement (available here) noting that the amendments will “make our market plumbing more resilient, timely, and orderly."  Similar amendments have been approved by the Canadian Securities Administrators and will come into effect in Canada on May 27, 2024. 

What is T+1?

  • Under the new “T+1" settlement cycle, all applicable securities transactions from U.S. financial institutions will settle within one business day of their transaction date. 
  • For example, trades subject to the “T+2" settlement cycle made on Friday, May 24, 2024 and the “T+1" settlement cycle made on Tuesday, May 28, 2024 will both settle on Wednesday, May 29, 2024.

What Securities Will This Impact?

  • The “T+1" settlement cycle will apply to the same securities transactions currently covered by the “T+2" settlement cycle prior to the amendments. 
  • These include transactions for stocks, bonds, exchange-traded funds, certain mutual funds and limited partnerships that trade on an exchange.

Certain Exceptions

  • For a firm commitment underwritten registered offering priced after 4:30 p.m. Eastern Time, the standard settlement cycle will be “T+2," unless the parties agree to a longer settlement cycle (Rule 15c6-1(c)).  For example, a trade subject to this exception made on Tuesday, May 28, 2024 after 4:30 p.m. Eastern Time will settle on Thursday, May 30, 2024.
  • The issuer and the managing underwriter in a firm commitment offering may expressly agree to an alternate date for settlement (Rule 15c6-1(d)).
  • Additional exceptions include exempted securities, government securities, municipal securities, commercial paper, bankers' acceptances, commercial bills, contracts to purchase limited partnership interests that are not listed on an exchange and security-based swaps.
  • ...
Reminder For Resource Extraction Issuers: Form SD Due September 2024

​As previously reported on our Securities Regulation and Corporate Governance Monitor on December 16, 2020 (available here), the Securities and Exchange Commission (the “SEC") adopted the final rule (available here) requiring additional disclosures by public companies that engage in the commercial development of oil, natural gas or minerals. Under the final rule, domestic or foreign “resource extraction issuers" are required to annually disclose information about certain payments made to foreign governments or the U.S. federal government on Form SD.

The final rule became effective on March 16, 2021 allowing for a two-year transition period after the effective date, with initial Form SD filings due no later than 270 calendar days after the end of an issuer's next completed fiscal year (e.g., September 26, 2024 for issuers with a December 31, 2023 fiscal year end). While the adopting release specifically referred to September 30, 2024 as the due date for a company with a fiscal year end of December 31, 2023 (274 days after year end), we recommend filing the Form SD by September 26, 2024 to ensure timely compliance with the rule's deadline. We note that for 2025, 2026 and 2027, the form will be due by September 27 for companies with a December 31 fiscal year end (270 days after the fiscal year end in non-leap years), unless September 27 is a Saturday, Sunday or holiday, in which case the deadline is the next business day.

What kind of information is required to be disclosed?

The final rule implements Section 13(q) of the Securities Exchange Act of 1934, as amended, which requires disclosure of company-specific, project-level information on Form SD (available here and on page 212 of the adopting release), including the:

  • type and total amount of payments made for each project of the resource extraction issuer relating to the commercial development of oil, natural gas or minerals;
  • type and total amount of such payments for all projects made to a government, as well as the country in which each such government is located;
  • currency used and the fiscal year in which the payments were made;
  • fiscal year in which the payments were made;
  • business segment of the issuer that made the payments;
  • specific projects to which such payments relate and the resources that are being developed;
  • method of extraction used in the project and the major subnational political jurisdiction of each project; and
  • payments made...
Updated Summary of Director Education Opportunities Available

Gibson Dunn's summary of director education opportunities has been updated as of April 2024. A copy is available at this link.

Boards of Directors of public and pre-IPO companies find this a useful resource as they look for high quality education opportunities.

This quarter's update includes a number of new opportunities as well as updates to the programs offered by organizations that have been included in our prior updates.

Thank you to associates Ben Blefeld, Caroline Bakewell and Mariana Lozano from our Houston office for their assistance with this quarter's update.

SEC Stays Climate Disclosure Rule Following Consolidation of Litigation in the Eighth Circuit

On March 21, 2024, the Judicial Panel on Multidistrict Litigation randomly selected the U.S. Court of Appeals for the Eighth Circuit to hear all cases challenging the Securities and Exchange Commission's final climate disclosure rule.  Within the first ten days after the rule's issuance, nine petitions were filed, in six different circuits, challenging the rule.  The Second, Fifth, Sixth, Eighth, Eleventh, and D.C. Circuits received at least one petition each.  Pursuant to 28 U.S.C. § 2112, the Judicial Panel on Multidistrict Litigation randomly selected the one circuit in which all cases will be consolidated.

On March 22, 2024, the courts of appeals began to transfer the challenges to the Eighth Circuit.  In its transfer order, the Fifth Circuit dissolved the administrative stay it had previously issued.  All future proceedings, including any litigation regarding a stay, will occur in the Eighth Circuit.

Subsequently, on April 4, 2024, the SEC issued an Order pausing the implementation of its rules available here. The Order notes the stay is limited to the final rules challenged in the litigation consolidated in the Eighth Circuit and does not stay any other Commission rules or guidance.  

Our March 8 client alert on the new rule is available here.


1 - 10 Next
Current thoughts on development and trends in securities regulation, corporate governance and executive compensation published by Gibson Dunn.

© Copyright 2019 Gibson, Dunn & Crutcher LLP.
Attorney Advertising. Prior results do not guarantee a similar outcome. All information provided on this site is for informational purposes only, does not constitute legal advice, is not confidential, and does not create an attorney-client relationship. Statements and content posted to this site do not represent the opinion of Gibson Dunn & Crutcher LLP ("Gibson Dunn"). Gibson Dunn makes no representations as to the accuracy, completeness, currentness, suitability, or validity of any information on this site and will not be liable for any errors or omissions therein, nor for any losses, injuries, or damages arising from its display or use.