SEC Charges Public Companies with Misleading Cyber Disclosures – Husch Blackwell

On October 22, 2024, the Securities and Exchange Commission (SEC) announced its charges against four companies for misleading disclosures related to cybersecurity risks and intrusions. One of the companies is facing additional charges for violations in disclosure controls and procedures. It’s important to note that these charges are based on conduct that happened before the new cybersecurity disclosure rules came into effect in 2023.

The SEC found that the companies downplayed the severity of the SolarWinds cyberattack-related intrusions in different ways, such as describing risks as hypothetical even after the incident had occurred, not disclosing specific details about the cyber risks faced, failing to disclose the nature and extent of data accessed during the incident, and minimizing the impact of the intrusion. In response to these allegations, the companies agreed to pay civil penalties ranging from $990,000 to $4,000,000 to settle the charges.

What does this mean for you?

This enforcement action by the SEC reflects a growing trend of holding public companies accountable for accurate and comprehensive cybersecurity incident disclosures. It emphasizes the importance of providing disclosures that reflect all material details, including in the context of the new cybersecurity rules. It’s worth noting that the SEC’s actions were dissented by commissioners Hester M. Peirce and Mark T. Uyeda, who argued that the charges were based on immaterial details and second-guessing the companies’ materiality determinations.

Despite the dissent, public companies should consider the following key points:

– Review and update risk factor disclosures related to cybersecurity incidents, avoiding hypothetical disclosures and using specific language to describe known risks.
– Update cybersecurity-related disclosures after experiencing a material incident.
– Assess existing disclosure controls and procedures to ensure timely and accurate reporting of cybersecurity-related information.
– Provide detailed and accurate disclosures of any material cybersecurity incidents in Form 8-K Item 1.05 and periodic reports.

As we continue to monitor the SEC’s approach to cybersecurity incident disclosures, our team at Husch Blackwell is available to address any questions or concerns you may have. Feel free to reach out to Craig Adoor, Steve Barrett, Robert Joseph, Victoria Sitz, Andrew Spector, Annorah Harris, or your Husch Blackwell attorney for guidance.