Microsoft filed this late today with the SEC[1] just before they stopped accepting new filings for the day under their new Cybersecurity Incident disclosure rule[2]. FWIW, two other publicly traded companies disclosed[3] their breaches since the rule went into affect last month. [1] https://www.sec.gov/Archives/edgar/data/789019/0001193125240... [2] https://www.sec.gov/news/press-release/2023-139 [3] https://last10k.…
If folks are interested in this space, I just got the mailing list [2] running last night and you can see a list of all the current incidents on my Incident Tracker [3].
I have many more data points I plan on tracking as well as adding 10-K GRC items to the list (potentially helpful for CISOs, other risk managers and investors to eval a companies risk management maturity).
Welcome any feedback!
[1] https://www.board-cybersecurity.com/incidents/tracker/202401...