Significance of Strong Disclosure Controls Highlighted by Recent SEC Enforcement Actions

On October 22, 2024, the Securities and Exchange Commission (SEC) took action against multiple technology companies for not being upfront about cybersecurity risks and intrusions in their disclosures. One company even got in trouble for not having proper disclosure controls.

So, what can we learn from all of this? The SEC reminds companies to be extra careful about updating disclosures after a cybersecurity incident. If your risk profile changes because of an incident, make sure to share that with investors. It’s also crucial to have clear policies in place for reporting cybersecurity incidents promptly.

The SEC also wants companies to understand what counts as important information in their disclosures. They don’t want companies downplaying cybersecurity incidents in their reports. The penalties for these violations range from $990,000 to $4 million.

Interestingly, two SEC commissioners disagreed with these actions. They believe a new SEC administration might approach cyber-related enforcement differently.

Now, let’s dive deeper into what got these companies in trouble. The SEC found two main issues with the disclosures:

1. Omission of Material Information: Some companies left out important details about cybersecurity incidents, like who was responsible or how long the threat actor was in their systems.

2. Failure to Update Disclosures: Other companies didn’t adjust their disclosures to reflect new cybersecurity risks after an incident. This made their disclosures misleading.

So, what can companies learn from this? When deciding what to disclose about a cybersecurity incident, think about whether a reasonable shareholder would consider the information important. And after an incident, consider updating your risk-factor disclosures to reflect any changes in your cybersecurity risk profile.

It’s also a good time for companies to review their disclosure controls and procedures. Make sure your controls are strong enough to make timely and accurate disclosures about cybersecurity incidents. This might involve enhancing internal processes to identify, report, and escalate cybersecurity incidents.

In addition, two SEC commissioners dissented from these actions, indicating a potential shift in approach under a new SEC administration. They believe that the focus should be on the impact of cybersecurity incidents rather than minute details.

Overall, the key takeaway here is that transparency and accuracy in disclosing cybersecurity risks are paramount. Companies should take note of these enforcement actions as a clear signal from the SEC that cybersecurity disclosures must be thorough and reflective of true risks.