Technically, the clock doesn't start ticking on the four-day window for reporting until companies have determined a breach is material.
It's not all breaches. In fact, because this is the SEC, it's about financial impact, not privacy or security.
It's a good start, but I worry that a financial impact based approach creates the wrong incentive.