The proposed rule would force public companies to notify regulators of a breach within four days of determining the breach is “material.”
With the rule, CISOs would have to talk with the board no later than a day or two after finding out about a breach to decide whether it is "material." This would help the company stay in the SEC’s good graces.