News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
Business of Tech | New SEC Cyber Incident Rules: A Boost for MSPs in Client Compliance Assistance

I spotted this in CIO Dive.  With the new cyber incident disclosure rules from the Securities and Exchange Commission (SEC), managed security service providers (MSPs) are expected to play a critical role in helping clients meet these requirements. The new rules require public companies to file an 8-K form within four business days after determining that a cyber incident will have a material impact on their business. MSPs can support these disclosure processes by providing information and data relevant to materiality determinations, breach reporting, and threat mitigation strategies. They can also offer consulting expertise in governance and policies related to incident materiality. The 10-K reporting requirement associated with the SEC guidelines may significantly burden firms, and MSPs can assist in reporting on tight deadlines. Overall, the new SEC requirements present opportunities for MSPs to strengthen their cybersecurity approaches and offer additional analysis and oversight services to help clients adhere to the regulations.

The United States, Britain, and other countries have signed an international agreement to prioritize the security of artificial intelligence (AI) systems. The agreement emphasizes the need for AI to be “secure by design” and includes recommendations such as monitoring for abuse, protecting data, and vetting software suppliers. While non-binding, the agreement signifies a global recognition of the importance of AI safety. The framework also addresses concerns about AI technology being hijacked by hackers. However, it does not cover issues related to the appropriate use of AI or data collection.

Europe’s IT sector is concerned that the EU’s upcoming AI Act lacks tech neutrality and risk-based control. The strict approach towards General Purpose AI (GPAI) and foundation models is not aligned with the complexity of the AI value chain and is inconsistent with the intended risk-based regulation. The potential classification of these technologies as “highly capable” or having “high impact” is also questioned. Additionally, the sector representatives oppose additional requirements for using copyrighted data and believe it adds unnecessary legal complexity. Concerns have been raised by executives and the US about over-regulation stifling innovation and favoring big players.

The Biden administration is proposing a rule prohibiting cable and satellite companies from charging customers for canceling their services mid-contract. This is part of the administration’s efforts to eliminate hidden fees that increase consumer costs. The rule would also require companies to provide prorated credits or rebates for unused service days. The Federal Communications Commission is set to vote on the rule on December 13.

The Cybersecurity and Infrastructure Security Agency (CISA) and the U.K. National Cyber Security Centre (NCSC) have released joint guidelines on secure AI system development. The guidelines emphasized secure-by-design practices and the importance of security in operational practices and maintenance and were developed in collaboration with other ministries and cybersecurity agencies worldwide. This effort aligns with the Biden administration’s focus on cybersecurity and creating safeguards around the use of AI technology.

Why do we care?

Get out your legal pad and learn those forms!  For some customers, that will be part of your service offering.  

More frameworks for you to leverage for potential AI security and compliance offerings, and for my European listeners, start preparing them for the upcoming regulation.    CISA and NSCS have given you more tools to do so.  

 

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories