Who We Serve

Services

About

Resources

SEC Targets Misleading Cybersecurity Disclosures with Enforcement Actions

All Fintech

Cybersecurity

October 31, 2024

The Case

The United States Securities and Exchange Commission (SEC) has charged four companies, both current and former public entities, with making materially misleading disclosures regarding cybersecurity risks and intrusions, resulting in nearly $7 million in total penalties. The proceedings fall into two categories: Disclosing but omitting material information about cyberattacks and failing to update risk factors following a cyberattack. 

The SEC emphasized that public companies downplaying the extent of a cybersecurity breach “further victimize their shareholders or other members of the investing public by providing misleading disclosures.”

Regulatory Implications

The SEC’s recent enforcement actions highlight the agency’s increasing focus on cybersecurity disclosures and the importance of accurate, transparent reporting. Companies found to have minimized or omitted key details about cybersecurity incidents now face steep penalties, sending a clear message about disclosure expectations. Key takeaways include:

Materiality in Cybersecurity Disclosures:

  • Companies must thoroughly evaluate and disclose material cybersecurity incidents, balancing qualitative and quantitative factors.

  • Misrepresenting or omitting the extent or impact of a breach can cause regulatory penalties and shareholder lawsuits.

Evolving Regulatory Standards:

  • Although the incidents predated the 2023 Cybersecurity Rule, the SEC’s actions emphasize its broader expectation for detailed, accurate disclosures, especially when cybersecurity risks evolve post-incident.

Enhanced Governance and Processes:

  • Failures at the governance level, such as inadequate escalation procedures and poor communication between cybersecurity teams and disclosure decision-makers, were cited as critical issues. These breakdowns led to delays in reporting and inaccurate disclosures.

Practical Guidance for Firms

To avoid regulatory pitfalls, public companies must refine their cybersecurity disclosure processes and governance frameworks. Proactive actions to consider include:

Streamline Disclosure Practices:

  • Develop clear procedures for escalating cybersecurity incidents to decision-makers responsible for evaluating materiality.

  • Create robust protocols to ensure timely and accurate updates to SEC filings when new information emerges about previously disclosed incidents.

Strengthen Risk Factors:

  • Align cybersecurity risk factors with real-world incidents, avoiding generic language or hypothetical framing.

  • Include insights from internal and external investigations for a comprehensive view of potential vulnerabilities.

Bolster Governance:

  • Ensure board-level cybersecurity oversight is clear, assigning responsibilities to specific committees and updating charters as necessary.

  • Provide boards with regular, detailed updates on cybersecurity risks, incident response, and governance readiness.

Focus on Incident Response Readiness:

  • Revise incident response plans to incorporate regulatory considerations, particularly timelines for assessing and disclosing materiality.

  • Conduct simulations to test the effectiveness of these plans under real-world scenarios.

Invest in Comprehensive Compliance Support:

  • Review disclosure controls and processes to prevent lapses in accuracy or timing.

  • Collaborate with legal and compliance experts to draft disclosures that balance technical details with regulatory expectations.

Subscribe for Compliance Insights
Subscribe for Compliance Insights
Subscribe for Compliance Insights

All Fintech

The SEC has recently taken a series of enforcement actions against financial firms for failing to maintain and preserve electronic communications, particularly those conducted through off-channel methods like personal devices.

Broker-Dealers

Cash sweep programs, which automatically transfer uninvested cash in brokerage accounts to higher-interest accounts, are facing increased scrutiny from regulators like the SEC and FINRA, and investors.

Broker-Dealers

The North American Securities Administrators Association (NASAA) is requesting public comments on proposed revisions to NASAA’s broker-dealer conduct rule entitled Dishonest or Unethical Business Practices of Broker-Dealers and Agents (“Conduct Rule”).

LinkedIn Innreg
X InnReg
Quora Innreg
Blog Innreg

© 2024 InnReg LLC

1101 Brickell Avenue
South Tower, 8th Floor
Miami, FL 33131

LinkedIn Innreg
X InnReg
Quora Innreg
Blog Innreg

© 2024 InnReg LLC

1101 Brickell Avenue
South Tower, 8th Floor
Miami, FL 33131