toppan merrill
  • Insights
  • About Us
  • Contact
  • Client Login

    Toppan Merrill Bridge™

    Content Control

    My Workspace

    Form N-MFP Online

    Toppan Merrill Document Delivery

    Toppan Merrill Insurance Solutions

    Section16Direct

    SEC Connect

    SOX Automation

  • EN

    English

    简体中文 (Simplified Chinese)

    繁體中文 (Traditional Chinese)

  •  
  • Capital Markets Transactions
    • Capital Markets Transactions

      Equity, Debt & IPO Offering Management Services

      M&A

       

       

       
       

      Capital Markets Transactions Resources

      Insights & Analysis

      Events

      SEC Resources

      EDGAR Resources

      XBRL Resources

       

       

      Capital Markets Transactions Products

      Bridge

      Built on the Microsoft® Office® platform, Bridge makes disclosure content management easier, faster and more accurate.

       

       

       

  • Regulatory Disclosure
    • Regulatory Disclosure for Corporations

      Annual Meeting & Proxy Solutions

      Annual Meeting & Proxy Consulting

      Periodic & Interim Reporting

      iXBRL and EDGAR for US-GAAP & IFRS Filers

      iXBRL for ESEF Filings

      SEDAR Filings

      Section 16 Filings

      Automated SOX Compliance

       

       

      Regulatory Disclosure for Investment Management

      Periodic & Interim Reporting and Prospectuses

      Component Content Management & Output

      Website Document Hosting

      Shareholder Preference Center

      Compliance Center for Variable Products

       

       

       

      Regulatory Disclosure Resources

      Insights & Analysis

      Events

      SEC Resources

      EDGAR Resources

      XBRL Resources

       

       

      Regulatory Disclosure Products

      Bridge

      Built on the Microsoft® Office® platform, Bridge makes disclosure content management easier, faster and more accurate.

       

       

      SOX Automation

      Intuitive SaaS technology that centralizes all business locations, processes, risks and controls delivering efficiency, transparency, and predictability of cost.

       

       

  • Sales & Marketing Communications
    • Sales and Marketing Communications

      Offerings

      Omni-channel communications

      Document Creation & Management

      Sales Enablement

      ADA Services

      Fulfillment & Distribution

      Printing Services

       

       

       

      Industries

      Financial Services

      Health Insurance

       

       

       

      Sales and Marketing Communications Resources

      Insights & Analysis

      Events

       

       

      Sales and Marketing Communications Products

      Connect

      Drive client engagement and streamline personalized, compliant communications from printing to leading-edge digital solutions.

       

       

       

  • Products
    TOPPAN MERRILL
    ConnectTM

    Connect helps drive client engagement and streamline personalized, compliant communications from printing to leading-edge digital solutions.

    TOPPAN MERRILL
    BridgeTM

    A seamless SaaS solution built on the Microsoft® Office® platform, Bridge is an intuitive technology that makes disclosure content management easier, faster and more accurate.

  • Resources
    •  
       

      Insights & Analysis

      Events

      SEC Resources

      XBRL Resources

      SEC EDGAR Resources, Definitions, and Processes

      Regulatory Compliance Glossary

       

       

       

toppan merrill
  • Capital Markets Transactions
    • Overview
    • Equity, Debt & IPO Offering Management Services
    • M&A
  • Regulatory Disclosure
    • For Corporations

      • Overview
      • Annual Meeting and Proxy Statement Solutions
      • Periodic & Interim Reporting
        • EDGAR & iXBRL for SEC Filings (US-GAAP & IFRS)
        • iXBRL for ESEF Filings
        • SEDAR Filings
        • Section 16 Filings
        • Automated SOX Compliance
    • For Investment

      • Overview
      • Prospectus for Investment Management
      • Periodic & Interim Reporting for Investment Management
        • Component Content Management & Output
        • Website Document Hosting
        • Shareholder Preference Center
        • Portfolio Specific Document Management for Variable Products
  • Sales & Marketing Communications
    • Overview
    • Offerings

      • Omni-Channel Communications
      • Document Creation & Management
      • Sales Enablement
      • ADA Services
      • Fulfillment & Distribution
      • Printing Services
    • Industries

      • Financial Services
      • Health Insurance
      • Dynamic Publishing for Health Insurance
  • Products
    • Connect
    • Bridge
    • SOX Automation
  • Resources
    • Insights & Analysis
    • Events
    • SEC Resources
    • SEC EDGAR Resources
    • XBRL Resources
    • glossary
  • Insights & Analysis
  • About Us
  • Contact
  • Client Login
    • Toppan Merrill BridgeTM
    • Content Control
    • My Workspace
    • Form N-MFP Online
    • Toppan Merrill Document Delivery
    • Toppan Merrill Insurance Solutions
    • Section16Direct
 

The Coming Cybersecurity/Climate Disclosure Rules: Time to Reevaluate Your Disclosure Controls?

By Perkins Coie on 27 February, 2023
1 min read | Industry Insights Insights Home

Shutterstock_1846345465 (1)

With the SEC’s final cybersecurity and climate disclosure rules just around the bend, and with increased scrutiny of disclosure already required under current rules, it’s fair to ask yourself whether it’s time to reevaluate your disclosure controls and procedures (DCPs). While the exact requirements of the final rules remain unknown, the picture has been painted with a broad enough brush that you can start thinking about reevaluating DCPs to ensure you aren’t caught unawares when the final rules are released.


The Exchange Act of 1934 requires public companies to maintain and periodically evaluate the effectiveness of their DCPs as they relate to financial and nonfinancial disclosures in SEC filings. For various reasons, companies commonly extend DCP to cover significant voluntary disclosures as well.


Given the expanded scope of required disclosures expected under the new rules, companies should reevaluate their DCPs to ensure cybersecurity and ESG matters are adequately captured. Here are five things that companies should keep in mind:


  1. Determine what data to collect. Companies must determine what data to capture, and until the exact parameters of the final rules are known, should focus on the data most material to their business and industry. Companies can consider industrywide standards or metrics and whether key investors have preferred reporting frameworks. For example, BlackRock asks companies to report using the framework developed by the TCFD, supported by industry-specific metrics, such as those identified by SASB. 

  2. Establish data-gathering procedures and systems. Companies need to establish procedures for how data will be collected, where it is sourced, and how it is stored. Company personnel will need to be assigned responsibility over newly implemented procedures and data collection. Depending on the size and complexity of the data to be gathered, automated data management systems offer advantages over manual collection and storage methods. If companies intend to seek third-party assurance over their data, the procedures and systems need to be of sufficient quality and formality to enable testing by third parties.

  3. Determine how data and resulting disclosures will be reviewed and verified.  Companies must put in place procedures to vet the completeness and accuracy of the data collected and resulting disclosures. For example, internal controls and segregation of duties should be implemented to prevent and detect data fraud; also, certification and/or sub-certification procedures can be established whereby company personnel review and certify disclosures pertaining to their respective areas of responsibility. At the end of the day, the data and disclosures should be comparable across time, across communication channels (e.g., Form 10-K vs CSR Report), and amongst peers.

  4. Talk with your outside auditors and/or consultants. Audit firms and consultants can help design internal controls and procedures or provide assurance services over data and disclosures. There are a growing number of technology providers to help companies collect climate-related data, as noted recently in this Reuters article.

  5. Determine the role of the disclosure committee. As cybersecurity and climate disclosures are incorporated into DCPs, companies should consider the role their existing disclosure committee will play in the DCP structure. Approaches vary from company to company; some opt to establish separate, stand-alone, subject-specific disclosure committees, while others simply expand the scope of their existing disclosure committee or create a subcommittee to capture the new disclosure topics.

    If the existing disclosure committee is tasked with overseeing new cybersecurity and climate disclosure topics, the disclosure committee will need to be informed on such topics.

    While a major overhaul of disclosure committee membership may be premature—as Broc recently blogged—disclosure lawyers and existing members of the disclosure committee will need to study up on cybersecurity and climate change. Cybersecurity and ESG experts within the company can still be tasked to review disclosures and otherwise provide help.

View the full article for all formatting, tables, footnotes, etc. >>

Share

Share on twitter Share on linkedin Share on facebook
Previous ArticleDecoding the SEC's Updates on Pay Versus Performance Rules
Next ArticleGuidance from the SEC for new Pay versus Performance tables

Subscribe

Subscribe

Subscribe

Subscribe

Perkins Coie



toppanmerrill.com


Show more posts from author

Capital Markets & Compliance; SEC updates;
 

Expert Support

The best-in-class partner for complex, secure communications. Contact Toppan Merrill today.

Contact Us

Subscribe to the Toppan Merrill Blog

Gain actionable insight on industry trends, best practices & successful strategies to help your business.

Subscribe

Blog Categories

  • Industry Trends
  • Shareholder Communications
  • 40 Act SEC Regulations
  • Digital Communications
  • Toppan Merrill Connect
  • Content Management
  • Print/Fulfillment

Blog Categories

  • Industry Trends
  • Shareholder Communications
  • 40 Act SEC Regulations
  • Digital Communications
  • Toppan Merrill Connect
  • Content Management
  • Print/Fulfillment

Blog Categories

  • Member Communications
  • Section 508 Compliance
  • Digital Communications
  • Toppan Merrill Connect

Blog Categories

  • Industry trends
  • Shareholder communications
  • 40 act SEC regulations
  • Digital communications
  • Toppan Merrill connect
  • Content management
  • Print/fulfillment

Most Popular Articles

Most Popular Articles

Most Popular Articles

Most Popular Articles

Regulatory Resources

  • SEC Resources
  • EDGAR Resources
  • XBRL Resources

Toppan Merrill Corporate Video

2023 Compliance Calendar

Toppan Merrill 2023 Compliance Calendar_DIGITAL_Page_01
Download

Interactive Digital Compliance Calendar

2022 Interactive Digital Compliance Calendar

View Calendar

Regulatory Resources

  • SEC Resources
  • EDGAR Resources
  • XBRL Resources

Toppan Merrill Corporate Video

2023 Compliance Calendar

Toppan Merrill 2023 Compliance Calendar_DIGITAL_Page_01
Download

Interactive Digital Compliance Calendar

2022 Interactive Digital Compliance Calendar

View Calendar
Toppan Merrill Corporate Video

Regulatory Resources

  • SEC Resources
  • EDGAR Resources
  • XBRL Resources

Toppan Merrill Corporate Video

2023 Compliance Calendar

Toppan Merrill 2023 Compliance Calendar_DIGITAL_Page_01
Download

Interactive Digital Compliance Calendar

2022 Interactive Digital Compliance Calendar

View Calendar

Latest Blogs

Latest Blogs

Latest Blogs

Latest Blogs

ToppanMerrill logo

Expand Possible.

twitter linkedin

Solutions

  • Capital Markets Transactions
  • Regulatory Disclosures for Corporations
  • Regulatory Disclosures for Investment Management Companies
  • Financial Services Marketing & Communications
  • Health Insurance Marketing & Communications
  • Election Services

Technologies

  • Toppan Merrill Connect™
  • Toppan Merrill Bridge™

Blog

  • Insights

About Toppan Merrill

  • About Toppan Merrill
  • Operating Principles
  • Careers

Get In Touch

  • Contact Us

TERMS OF USE | PRIVACY NOTICE | TOPPAN MERRILL SERVICES AGREEMENT | TOPPAN MERRILL SUPPLIERS | GLOSSARY

© Toppan Merrill 2022

ToppanMerrill logo
Expand Possible.
` twitter linkedin
Solutions
  • Capital Markets Transactions
  • Regulatory Disclosures for Corporations
  • Regulatory Disclosures for Investment Management Companies
  • Financial Services Marketing & Communications
  • Health Insurance Marketing & Communications
  • Election Services
Technologies
  • Toppan Merrill ConnecTM
  • Toppan Merrill BridgeTM
BLOG
  • Insights
About Toppan Merrill
  • About Toppan Merrill
  • Operating Principles
  • Careers
Get In Touch
  • Contact Us

TERMS OF USE | PRIVACY NOTICE | TOPPAN MERRILL SERVICES AGREEMENT | TOPPAN MERRILL SUPPLIERS | GLOSSARY

© Toppan Merrill 2019