SEC is Not Accepting Half-Truths
2024-10-24 00:22:0 Author: securityboulevard.com(查看原文) 阅读量:2 收藏

The SEC has fined four major companies for materially misleading investors regarding cyberattacks.

Tech in Trouble

Regulatory actions have been brought against Unisys, Avaya, Check Point, and Mimecast for their purposeful decisions to not clearly inform customers and shareholders of the attacks and breaches they suffered as part of the SolarWinds cyberattack.

The SEC concluded that these companies were purposely vague by framing their cybersecurity risk factors hypothetically or discussing them in generic terms, even after knowing the issues were present and material.

AWS

AWS Hub

Reporting material issues to shareholders is a requirement for public companies, so investors will have the same information to make decisions as the insiders of the company.

Jorge G. Tenreiro, acting chief of the Crypto Assets and Cyber Unit, warned that “downplaying the extent of a material cybersecurity breach is a bad strategy”.

The result of this investigation is that Unisys Corporation is fined $4 million as a civil penalty for misleading disclosures and a failure to maintain proper controls over its public statements. Check Point, Avaya, and Mimecast were fined close to $1 million each for similar reasons.

Message to CISOs

The message to boards, C-suites, and especially Chief Information Security Officers (CISOs) is clear — report material breaches as required by the governing regulations. Misleading or false statements are not acceptable.

Sanjay Wadhwa, Acting Director of the SEC’s Division of Enforcement, stated “…while public companies may become targets of cyberattacks, it is incumbent upon them to not further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered”

Security must be seen as a center of trust. Ethical representations of risks and impacts are the foundation. This includes messages and formal notifications to shareholders and customers. CISOs must recognize their new responsibilities and actively navigate conflicts of interest they experience, and honor their duties.

SEC Press Release: https://www.sec.gov/newsroom/press-releases/2024-174

*** This is a Security Bloggers Network syndicated blog from Information Security Strategy authored by Matthew Rosenquist. Read the original post at: https://infosecstrategy.blogspot.com/2024/10/sec-is-not-accepting-half-truths.html


文章来源: https://securityboulevard.com/2024/10/sec-is-not-accepting-half-truths/
如有侵权请联系:admin#unsafe.sh