Last month, Paul Hastings released its first SEC Cybersecurity Incident Disclosure Report, which analyzed 75 disclosures issued by 48 public companies that disclosed cybersecurity incidents between Dec. 18, 2023, and Oct. 31, 2024.

The report was published one year after the U.S. Securities Exchange Commission enacted requirements around businesses' cybersecurity disclosures, which ordered public companies to disclose all "material" cybersecurity incidents—including the nature, scope and timing of the incidents and their impact on the companies, their finances and their operations—within four days of assessing them.