New SEC regulations will force any public games company in the US to disclose ‘material’ hacks within four days-

Last week, we reported on a Roblox data breach that first happened in 2020, and was apparently shared in some nefarious places in 2021, but only became widely known about when the leak was posted again on July 18. There was a wealth of identifying information about individuals who attended the Roblox Developer’s Conference in this hacked data, and some might find the length of time between the hack happening and Roblox Corporation acknowledging it pretty surprising. 

Gaming companies are hardly alone in being targets for bad actors, with cybercrime now an omnipresent threat in every business sector. And no matter how good the defences get, we’ll be reading about successful hacks on high-profile targets for the rest of our lives. The US Security and Exchanges Commission clearly thinks so and as reported by The Register has voted to adopt new requirements, first proposed in March 2022, that any public company suffering a computer crime that’s likely to cause any kind of a “material” hit will now have a four-day time limit in which to disclose the incident. A material hit is basically anything investors should be concerned about.

Given that the vast majority of the big gaming companies in the US are publicly traded, this means the new rule (which comes into effect in 30 days) will apply to companies such as: Activision Blizzard, Electronic Arts, Microsoft, Nexon, Nintendo, Paradox Interactive, Riot Games, Roblox Corporation, Sony, and Take-Two Interactive. Nested within those are plenty of other famous studios like Blizzard, Bungie, Rockstar, and Zynga.

Any company that’s suffered a cybersecurity incident that could have a material impact now has to determine whether it should be disclosed “without reasonable delay” and, if it should, immediately has to submit a Form 8-K report which now has a new cybersecurity section. This will see the company declare what it believes to be the “nature, scope, and timing” of the breach and what it thinks the impact on the business will be. These 8-K forms are made public by the SEC.

There are some exemptions that probably won’t apply to gaming companies, such as risks to national security or public safety, and the disclosure rules come alongside a new reporting requirement, whereby public companies have to outline their processes for identifying and managing cyber-threats. Foreign companies doing business in the US will not be exempt and similar rules are being applied to their set of forms (6-K and 20-F, fact fans).

The focus here is on investors rather than the little people, but the outcome should be a public good. The exact definition of the word “material” is going to become pretty important, and there are of course a multitude of different possible cyber crimes that this rule will cover, but the example of customer data being compromised feels like something that should be disclosed as soon as it’s known about.

Helpfully, the SEC agrees, saying in the rules that: “By way of illustration, harm to a company’s reputation, customer or vendor relationships, or competitiveness may be examples of a material impact on the company.”

US state laws already require companies to notify users whose data may have been compromised, so this new regulation is additive rather than entirely novel, another layer of compliance that may catch unreported breaches. It may also illuminate the details of breaches which don’t involve user data, such as last year’s GTA 6 hack, which companies are usually buttoned-up about. Not everyone is a fan of these new rules, with some pointing out that publicity can be the last thing you want in the wake of a potentially disastrous hack. But the new rules have exemptions baked-in for just such eventualities, and fast public disclosure feels well worth the try.

Related Posts

PSU scrips bear brunt of record fall

Shares of state-owned companies bore the brunt of the uncertainty around election results on Tuesday as vote counting showed a slim victory margin for the BJP-led NDA…

Realty Firm Kalpataru files Rs 1,590 crore IPO draft papers to SEBI to reduce debt

Mumbai-based real estate company Kalpataru has filed a draft red herring prospectus (DRHP) with the Securities and Exchange Board of India (SEBI) to launch an initial public…

Share Market Highlight- Markets end higher! Nifty closes below 21,500, Sensex above 71,050; Media and Metal stocks gains

Share Market News Today | Sensex, Nifty, Share Prices Highlights: The benchmark equity indices closed in the positive territory. The NSE Nifty 50 closed 215.15 points or…

Sebi asks brokers to inform most important terms and conditions to clients

For ease of understanding, capital markets regulator Sebi on Monday asked brokers to inform a standard “most important terms and conditions” to the clients, which will be…

Street Fighter 6 For PC Is Nearly 50% Off Today, Comes With Free Game

Street Fighter 6 is one of the best fighting games in recent memory and one of 2023’s standout games in general. It garnered stellar reviews from fans…

The Best Fortnite Merch In 2022

Fortnite continues to be one of the most popular games in the world. Since launching in 2017, the battle royale has seen no shortage of wild collaborations,…