Blog
CRQ in action

Are you ready to report on your cyber risk?

Published on
July 18, 2023

Cyber security threats aren’t going away. 

If anything, as we evolve our use of technology through continued digitisation, they’ll grow. 

Acknowledging this escalating risk to public companies and investors, the U.S. Securities and Exchange Commission (SEC) has proposed a new set of Cybersecurity rules aimed at Public Companies that aim to bolster cybersecurity risk management, strategy, governance, and incident disclosure reporting.  

These rules are intended to provide more consistent, comparable and decision-useful information so that investors can better evaluate a company’s exposure to cybersecurity risks and incidents; and develop strategies to mitigate those risks and incidents.  

Once the rules take effect, publicly listed companies will be required to

  • Provide clarity in current reporting relating to material cybersecurity incidents. 
  • Conduct periodic reporting on previously reported cybersecurity incidents.  
  • Undertake periodic reporting about policies and procedures to identify and manage cybersecurity risks. 
  • Provide information around the board of directors' oversight of cybersecurity risk; and management’s role and expertise in assessing and managing cybersecurity risk, policies and procedures implementation.  
  • Report annually about the board of directors’ cybersecurity expertise. 

This ruling is expected to be finalised imminently, which means that now is a good time to get prepared. It’s time to ensure your company can communicate cyber risk with your stakeholders in an effective way that also aligns with the SECs proposed requirements.  

One way to approach this is by using ‘Cyber risk quantification’ as it provides a quantitative view of your company’s cyber risk exposure. Going one step further, an effective cyber risk quantification program should help you achieve the following objectives and answer the following key questions: 

Express risk quantitatively: What’s our risk exposure in financial terms to a cyber-attack, and how does this compare against our risk appetite?  

Prioritise Investments: What cyber capabilities should we prioritise investment in to optimise our protection against the threats we face? 

Demonstrate cost benefit analysis: If we invest £XM in cyber next year, what benefit, in terms of reduced cyber related losses, will this deliver to the business? 

Optimise cyber insurance:
 Do we have appropriate cyber insurance coverage given the threats we face? 

Optimise capital investments: Do we have proportionate capital reserves in the event we suffer a widespread cyber incident? 

The SECs proposed ruling on cyber risk reporting has likely come at the most relevant time, but an increasing cybersecurity regulatory landscape does mean additional work for many. Have you quantified your organisations cyber risk exposure in the context of the threats faced and capabilities in place?  

Author
Alex Lightfoot
Head of Customer Success
Alex is the Head of Customer Success at CRI. With a strong focus on helping customers extract maximum value from the product, Alex is dedicated to enhancing customer satisfaction, understanding customer needs, and fostering long-term partnerships. Based in Manchester, Alex advocates for customers internally, driving continual improvement of the product.
Our blog

Latest Insights

The latest from the CRI community.
Resilience

The Future of MDR: From reactive monitoring to intelligence-led attack disruption

In today’s threat landscape, where attacks span identity, cloud, endpoint, data and third-party ecosystems, metrics such as alerts triaged, tickets closed and response times are no longer enough. What matters is whether an organisation can identify the threats that matter, disrupt them before they become business events, and use that insight to make better risk decisions.
Salil Shukla
June 2, 2026
4 min read
Resilience

Reinventing cyber budgeting: From legacy spend to quantified risk

Cyber risk is rising while budgets remain constrained. Investment in cyber has plateaued, yet the threat landscape continues to expand in frequency, sophistication, and impact. Despite this, many organisations continue to budget in the same way – rolling forward prior spend, adjusting incrementally, and reinforcing existing control environments. How is CRQ helping leaders prioritise investment, strengthen resilience, and stay ahead of a rapidly evolving threat landscape?
Martin Tyley
May 27, 2026
4 min read
Resilience

APT campaigns and their ripple effect on cyber risk

Advanced Persistent Threat groups are not typical cyber adversaries. Often nation-state sponsored, they operate with scale, sophistication, and patience. Their objectives extend well beyond financial gain – from espionage and intellectual property theft to preparing the ground for future disruption. See how organisations are using CRQ to understand the real impact of advanced threats—and prioritise investment accordingly.
Callum Wilson
May 26, 2026
4 min read

See CRI in action

Book a personalised demo and discover how CRI can help you make smarter cyber risk decisions.