Cybersecurity risks are increasing as cloud computing and IT usage grows. There is currently no single obligatory framework for cybersecurity disclosure. Existing frameworks provide some guidance but lack specificity and enforceability. This document analyzes existing disclosure guidelines and frameworks like NIST, HIPAA, and CF DG 2. It finds that most disclosures are boilerplate and that industries with frameworks have more disclosures. The recommendation is to transition to a rules-based framework developed jointly by regulators and firms to standardize disclosures and reduce information asymmetry for shareholders. An implementation plan proposes expanding NIST internationally and incorporating it into SEC rules over time.