The SEC has fined four major companies for materially misleading investors regarding cyberattacks.
Tech in Trouble
Regulatory actions have been brought against Unisys, Avaya, Check Point, and Mimecast for their purposeful decisions to not clearly inform customers and shareholders of the attacks and breaches they suffered as part of the SolarWinds cyberattack.
The SEC concluded that these companies were purposely vague by framing their cybersecurity risk factors hypothetically or discussing them in generic terms, even after knowing the issues were present and material.
Reporting material issues to shareholders is a requirement for public companies, so investors will have the same information to make decisions as the insiders of the company.
Jorge G. Tenreiro, acting chief of the Crypto Assets and Cyber Unit, warned that “downplaying the extent of a material cybersecurity breach is a bad strategy”.
The result of this investigation is that Unisys Corporation is fined $4 million as a civil penalty for misleading disclosures and a failure to maintain proper controls over its public statements. Check Point, Avaya, and Mimecast were fined close to $1 million each for similar reasons.
Message to CISOs
The message to boards, C-suites, and especially Chief Information Security Officers (CISOs) is clear — report material breaches as required by the governing regulations. Misleading or false statements are not acceptable.
Sanjay Wadhwa, Acting Director of the SEC’s Division of Enforcement, stated “…while public companies may become targets of cyberattacks, it is incumbent upon them to not further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered”
Security must be seen as a center of trust. Ethical representations of risks and impacts are the foundation. This includes messages and formal notifications to shareholders and customers. CISOs must recognize their new responsibilities and actively navigate conflicts of interest they experience, and honor their duties.
SEC Press Release: https://www.sec.gov/newsroom/press-releases/2024-174
*** This is a Security Bloggers Network syndicated blog from Information Security Strategy authored by Matthew Rosenquist. Read the original post at: https://infosecstrategy.blogspot.com/2024/10/sec-is-not-accepting-half-truths.html