On Sept. 20, SEC Chairman John Clayton announced that Wall Street’s watchdog, the Securities and Exchange Commission (SEC), was the victim of a cyber hack in 2016. In what ironically amounts to the SEC’s first significant disclosure of its own cybersecurity risks, Clayton stated: "In certain cases, threat actors have managed to access or misuse our systems." According to Clayton, “[i]n August 2017, the Commission learned that an incident previously detected in 2016 may have provided the basis for illicit gain through trading." Hackers apparently exploited a weakness in the SEC’s Electronic Data Gathering, Analysis and Retrieving (EDGAR) system. EDGAR houses financial records for all of the companies listed on stock exchanges in the United States – including domestic and foreign securities issuers and some companies with publicly traded debt. Such data, says cybersecurity expert Morgan Wright, could have allowed hackers to manipulate markets and put upwards of $1 trillion in assets at risk by manipulating markets. The SEC’s announcement is particularly ironic in light of the fact that, in 2011, the SEC’s Division of Corporation Finance (Corp Fin) issued guidance to registrants regarding the need for, and how to think about, risk disclosures arising from cyberattacks. According to Corp Fin, as of 2011, the SEC had “observed an increased level of attention focused on cyber attacks that include, but are not limited to, gaining unauthorized access to digital systems for purposes of misappropriating assets or sensitive information.” Based on this, the risks associated with such attacks (particularly to businesses with a significant online presence), and the costs associated with defending against and remediating the impact of cyberattacks, Corp Fin prescribed certain measures intended to ensure that the investing public understands the true costs of cyber crime. Corp Fin predicated its guidance on the idea that “registrants should consider the probability of cyber incidents occurring and the quantitative and qualitative magnitude of those risks, including the potential costs and other consequences resulting from misappropriation of assets or sensitive information, corruption of data or operational disruption.” In plain English, the higher the probability of a cyberattack that would have significant affects on a business, the greater the certainty that a registrant should disclose that information to its investors. And, the greater the likelihood that the registrant should be spending money (and disclosing the magnitude of such expenses, if material) to address those cyber risks. Under appropriate circumstances, Corp Fin recommended that registrants consider a disclosure of the “aspects of the registrant’s business or operations that give rise to material cybersecurity risks and the potential costs and consequences” and even “[r]isks related to cyber incidents that may remain undetected for an extended period.” It also noted that this assessment should be ongoing, particularly in light of increased risk from ever-changing cyberattacks. Corp Fin’s guidance may be nothing more than varnish on Regulation S-K, which provides an in-depth analysis of what registrants need to include when filing forms under the Securities Act of 1933, the Exchange Act of 1934, and the Energy Policy and Conservation Act of 1975. But, because 2017 has seen an inordinate number of cyberattacks, details of which can be read in USA Today, The New York Times and Wired, now may be a good time for any company (whether a registrant with the SEC or not) to revisit its cybersecurity conventions. Indeed, in the past several weeks, Equifax, one of the “big three” credit reporting agencies, also announced that its site had been hacked. The cyberattack at Equifax exposed 124 million people’s personal identifying information to misappropriation. And, yet, Equifax waited nearly five weeks to disclose the hack to the public – potentially in violation of Reg S-K and the Corp Fin guidance. To compound matters, after the hack was discovered, several Equifax executives sold Equifax stock before the issue was disclosed, a typical no-no under the securities laws. Is the SEC investigating Equifax? Given the appearance of insider trading, it is quite likely. Will the Equifax issue put more scrutiny on the work registrants are doing to protect from cyberattacks? Most certainly. In the wake of the Equifax breach and the SEC’s own humiliating data breach, it is time for SEC registrants (and other companies with an internet presence and a general concern for business continuity) to consider taking a closer look at their cybersecurity measures. This is particularly true given that both Equifax and the SEC had been at risk for months before the breach was identified. And, now, if for no other reason than to deflect from its own troubles, the SEC is most certainly watching.
RELATED ARTICLES
How the SEC Widens Net Over Ethereum
October 14, 2022 | The GEE Blog, SEC
Digital Asset Businesses Amp Up Their Compliance Measures to Avoid Insider Trading Actions
August 26, 2022 | The GEE Blog, Department of Justice, SEC
Is Crypto a Security? Insider Trading Case Leads to DOJ, SEC Scrutiny
July 27, 2022 | The GEE Blog, SEC, Insider Trading
Fifth Circuit Holds That SEC Administrative Law Courts Are Unconstitutional
May 23, 2022 | The GEE Blog, SEC
Will SEC Become the ‘Securities and Environment Commission?’
March 30, 2022 | Environmental, Enforcement, The GEE Blog, SEC
How the SEC Widens Net Over Ethereum
October 14, 2022 | The GEE Blog, SEC
Digital Asset Businesses Amp Up Their Compliance Measures to Avoid Insider Trading Actions
August 26, 2022 | The GEE Blog, Department of Justice, SEC
Is Crypto a Security? Insider Trading Case Leads to DOJ, SEC Scrutiny
July 27, 2022 | The GEE Blog, SEC, Insider Trading
Fifth Circuit Holds That SEC Administrative Law Courts Are Unconstitutional
May 23, 2022 | The GEE Blog, SEC
Will SEC Become the ‘Securities and Environment Commission?’
March 30, 2022 | Environmental, Enforcement, The GEE Blog, SEC
The Enforcement Climate is Changing for ESG Disclosures
January 26, 2022 | Environmental, The GEE Blog
SEC Proposes Amendments to the Requirements of Rule 10b5-1 Trading Plans
December 22, 2021 | The GEE Blog, SEC, Financial Regulation, Insider Trading
SEC Announces FY2021 Results With 7 Percent Increase in New Enforcement Actions
November 30, 2021 | The GEE Blog, SEC
How Will the SEC Drive ESG Progress? First, We Measure
August 2, 2021 | Environmental, Environmental News, SEC
ESG Investing Guidance from the U.S. Securities and Exchange Commission
July 29, 2021 | The GEE Blog, SEC
Whistleblower Awards from the U.S. Securities and Exchange Commission
May 24, 2021 | The GEE Blog, SEC
SEC Emerges as Main Regulator of Cryptocurrency
May 14, 2021 | The GEE Blog, Financial Regulation, SEC
SEC Whistleblower Program Continues Record-breaking Performance Amid New Chair's Support
April 28, 2021 | The GEE Blog, SEC
Gary Gensler to Lead SEC
April 16, 2021 | The GEE Blog, SEC
Half a Loaf: Congress Extends the Statute of Limitations on Some SEC Remedies
January 14, 2021 | The GEE Blog, SEC
SEC Again Highlights Risks of Investing in Chinese Securities
December 3, 2020 | The GEE Blog, SEC, Financial Regulation
SEC Steps Up Enforcement for Unsuitable Sales of Complex ETPs
November 18, 2020 | The GEE Blog, Financial Regulation, SEC
President’s Working Group Attempts to Increase Transparency in Chinese Investments
September 2, 2020 | The GEE Blog, SEC
SEC Highlights COVID-Related Risks Facing Broker-Dealers and Investment Advisers
August 31, 2020 | The GEE Blog, SEC, Financial Regulation
SEC Adopts Rule Amendments Regarding Proxy Voting Advice
July 29, 2020 | The GEE Blog, SEC
SEC Hosts Roundtable to Discuss Risks Associated With U.S.-Listed Chinese Companies
July 14, 2020 | The GEE Blog, SEC, Financial Regulation
Supreme Court Misses Its Chance To Define Limits of SEC’s Enforcement Authority
June 30, 2020 | The GEE Blog, SEC
Cybersecurity: CFTC Brings Enforcement Action For Faulty IT System
February 19, 2018 | Privacy, The GEE Blog
First-Time Supreme Court Advocate Appointed to Argue the SEC’s Case in Lucia
January 23, 2018 | SEC, The GEE Blog
SEC’s Appointments Clause Dilemma Gets Worse
January 16, 2018 | SEC, The GEE Blog
SEC Scrutiny Brings Sanity to Hot ICO Market
November 9, 2017 | SEC, The GEE Blog
Don't Let DOJ Defections Fool You: Corporate Conduct Still in the Crosshairs
September 6, 2017 | Department of Justice, The GEE Blog
Corporate Law Alert - SEC Issues Guidance on Initial Coin Offerings and Cryptocurrencies
August 2, 2017 | The GEE Blog, SEC
SEC Chairman Announces 8 Core Principles
July 31, 2017 | SEC, The GEE Blog
U.S. Supreme Court Delivers Blow Limiting SEC Disgorgement Power
June 12, 2017 | SEC, The GEE Blog
The SEC’s Appointments Clause Dilemma
January 24, 2017 | Case to Watch, SEC, The GEE Blog
SEC Changes Some of Its Procedural Rules After Constitutional Challenges
September 7, 2016 | SEC, The GEE Blog
D.C. Circuit Affirms Constitutionality of SEC’s In-House Tribunals
September 2, 2016 | SEC, The GEE Blog
Accounting Fraud Getting Increased Attention from the SEC and Class Action Counsel
April 29, 2016 | SEC, The GEE Blog
SEC Completes Municipal Underwriter “Enforcement Sweep”
February 8, 2016 | SEC, The GEE Blog
Can the Government Unlock My Cell Phone?
February 1, 2016 | Government Investigations, The GEE Blog
SEC Reduces Dodd-Frank Whistleblower Award for "Unreasonable Delay," Announces Policy of "More Heavily" Punishing Delay After Award Program's Implementation
November 16, 2015 | SEC, The GEE Blog
Regulation S-P Violation: Are You Prepared For A Cyber-Security Breach?
October 8, 2015 | SEC, The GEE Blog
Insider Trading and Administrative Courts – More on Two Hot Topics That Have Now Converged
September 28, 2015 | Insider Trading, SEC, The GEE Blog
WHY NEWMAN MIGHT NOT BE HEADED TO THE SUPREME COURT
August 11, 2015 | Insider Trading, The GEE Blog
NINTH CIRCUIT SLAPS BACK REMOTE TIPPEE’S NEWMAN DEFENSE
July 15, 2015 | Insider Trading, The GEE Blog
THE BENEFITS OF COOPERATION – HYPERDYNAMICS AVOIDS INDICTMENT
May 29, 2015 | FCPA, The GEE Blog
The SEC Explains Its Rationale in Forum Selection in Contested Cases
May 26, 2015 | SEC, The GEE Blog
The SEC Explains Its Rationale in Forum Selection in Contested Cases
May 22, 2015 | SEC, The GEE Blog
Self-Reporting: A Wise Strategy or Chasing Unicorns?
April 28, 2015 | SEC, The GEE Blog
Recent Enforcement Trends in the Commodity Markets (Part 1)
April 13, 2015 | Financial Regulation, The GEE Blog
Uniform Fiduciary Standards on the Horizon for Brokers and RIAs
April 10, 2015 | SEC, The GEE Blog
“HELLO, NEWMAN” -- GOVERNMENT CONTINUES TO LITIGATE REVERSED INSIDER TRADING CONVICTIONS
March 9, 2015 | Insider Trading, The GEE Blog
M&A DUE DILIGENCE FAILURES: FCPA & GOODYEAR
February 27, 2015 | FCPA, SEC, The GEE Blog
PART I - CORRUPTION ENFORCEMENT IN BRAZIL: WHAT DOES IT LOOK LIKE?
February 23, 2015 | SEC, The GEE Blog
Chasing the Gatekeepers
January 22, 2015 | SEC, The GEE Blog
DODD-FRANK WHISTLEBLOWER ACTIVITY GETTING EVEN HOTTER
September 23, 2014 | SEC, The GEE Blog
NASAA: State Securities Regulators’ Views on Top Emerging Enforcement Issues
September 19, 2014 | Financial Regulation, The GEE Blog
DODD-FRANK WHISTLEBLOWER LITIGATION HEATING UP
September 10, 2014 | SEC, The GEE Blog
Foreign Corrupt Practices Act - Keeping the Wolf at Bay
September 5, 2014 | FCPA, The GEE Blog
Regulators And Prosecutors Discuss Securities and Commodities Enforcement Priorities
August 15, 2014 | SEC, The GEE Blog
JUDGE RAKOFF CONTINUES TO QUESTION ADEQUACY OF JUDICIAL OVERSIGHT OF SEC
August 7, 2014 | SEC, The GEE Blog
Reader Responds to Recent Law Judge Blog Post
July 21, 2014 | The GEE Blog, SEC
The Gabelli Effect: How the Supreme Court’s Decision is Impacting Enforcement Actions
July 16, 2014 | SEC, The GEE Blog
REDUCING THE COST OF FCPA MONITORING
June 11, 2014 | Bank Securities Fraud, The GEE Blog
BELATED VINDICATION FOR THE SEC’S (PRIOR) SETTLEMENT POLICY
June 6, 2014 | Bank Securities Fraud, The GEE Blog
“Gatekeepers” Beware: A New Tool of the SEC
June 4, 2014 | Bank Securities Fraud, Financial Regulation, The GEE Blog
CYBERCRIME & YOUR COMPANY – FAILING TO PREPARE = PREPARING TO FAIL, Part 2
May 27, 2014 | Privacy, The GEE Blog
District Court Bolsters the Five-Year Statute of Limitations Defense to SEC Civil Enforcement Actions
May 20, 2014 | Bank Securities Fraud, The GEE Blog
Disgorgement in the Second Circuit: Equitable Relief or Punishment?
April 15, 2014 | Bank Securities Fraud, The GEE Blog
Alert: SEC creates team to examine private equity and hedge funds
April 9, 2014 | The GEE Blog
Heightened SEC/DOJ FCPA Standards Offer Risks and Opportunities to Companies and Their Lawyers
March 18, 2014 | Financial Regulation, The GEE Blog
Is the FTC The Latest Weapon of Aggressive Short Sellers?
March 17, 2014 | Government Investigations, The GEE Blog
Top 10 Takeaways from ABA White Collar Crime Conference 2014 (Part 2 of 2)
March 13, 2014 | Government Investigations, The GEE Blog
Top 10 Takeaways from ABA White Collar Crime Conference 2014 (Part 1 of 2)
March 12, 2014 | Government Investigations, The GEE Blog
SEC’s New Priorities Continue to Come into Focus: Admissions of Liability
March 11, 2014 | Bank Securities Fraud, The GEE Blog
The SEC and Its “Strange Bedfellows” Argue Against Investors Seeking Damages for Fraud – Are Rebuffed by the Supreme Court
March 3, 2014 | Bank Securities Fraud, The GEE Blog
The CFTC: Armed and Dangerous
February 13, 2014 | Financial Regulation, Government Investigations, The GEE Blog
SEC Continues to Struggle in Insider Trading Jury Trials
February 7, 2014 | Insider Trading, The GEE Blog
Securities Regulators’ Increasing Use of Real-Time Monitoring Systems - Is Skynet Next?
January 31, 2014 | Financial Regulation, Government Investigations, Insider Trading, The GEE Blog
Going South: What U.S. Companies Need to Know About the FCPA and Doing Business in Latin America
January 30, 2014 | Criminal Procedure, Government Investigations, The GEE Blog
Welcome to The GEE Blog
January 18, 2014 | The GEE Blog
Let the Light of Day Shine
January 18, 2014 | Financial Regulation, The GEE Blog
Barnes & Thornburg Legal Alert - Government Regulators Continue to Make Insider Trading a Trial Priority
January 16, 2014 | Financial Regulation, The GEE Blog
SEC Highlights 2013 Accomplishments and Outlines 2014 Enforcement Priorities
January 2, 2014 | Financial Regulation, The GEE Blog
RELATED PRACTICE AREAS
Subscribe
Do you want to receive more valuable insights directly in your inbox? Visit our subscription center and let us know what you're interested in learning more about.
View Subscription Center