The Securities and Exchange Commission’s proposed cybersecurity disclosure rules, which would allow investors for the first time to make apples-to-apples comparisons of companies’ cyberattack vulnerabilities and defenses, actually could have the unintended consequence of giving bad actors artillery to do more harm.

That was among the common themes in letters that companies, trade groups and other interested parties submitted to the SEC in response to the March rollout of the proposed rules.