On December 17, 2015, Senators Jack Reed (D-RI) and Susan Collins (R-Maine) introduced, S2410, the Cybersecurity Disclosure Act of 2015, which would require public companies to disclose what cybersecurity expertise their Board of Directors ("Board") possesses. If enacted, this bill would require the Securities and Exchange Commission to issue new rules mandating that public companies describe any cybersecurity experience or expertise held by the members of their Board in the companies' annual reports or proxy statements. If a company's Board does not have any members with cybersecurity expertise, the bill would require the company "to describe what other cybersecurity steps taken by the reporting company were taken into account" by nominating committees when selecting potential board members.
This bill would not require public companies to elect Board members with any cybersecurity expertise. If enacted (which is highly uncertain), it might lead shareholders to pressure companies to include cybersecurity experts on their Board, or to strengthen and clarify how the Board is advised and educated about cybersecurity threats. Even if the bill is not enacted into law, its introduction still may raise shareholder awareness about the need for Board members to better understand and address cybersecurity threats.