Public companies will shoulder the potentially costly burden of a new federal rule giving them just four days to report a cybersecurity incident—a nightmare for firms lacking a sound framework for managing data security.