SEC Cybersecurity Disclosure Rule Change Can Increase Your Cyber Risk
Summary
Alongside specifying details about the nature, scope and timeframe of the incident, these rules also require companies and their boards of directors to articulate their overall assessment and governance of cybersecurity risks.1 Just two weeks ago, the SEC charged SolarWinds – and alarmingly, its Chief Information Security Officer, Timothy Brown – alleging they defrauded and misled investors about its cybersecurity stature. The SEC alleged SolarWinds and Brown overstated their cybersecurity practices while downplaying known risks and exploits for several years. Allegations were also made that SolarWinds and Brown knew of various vulnerabilities but failed to address them adequately and disclose those vulnerabilities to investors.2 The SEC’s charges against SolarWinds highlight a hawkish stance that will likely be applied to the new cybersecurity disclosure rules and are a stark reminder to all companies — privately held and publicly traded — to exercise a heightened duty not just in evaluating but communicating cybersecurity risks. By leveraging this platform to review existing cybersecurity controls, organizations can better understand potential gaps and learn how to supplement existing controls with vulnerability scans of their network’s perimeter, peer benchmarking data, disaster scenario models, and a digital asset inventory. • US SEC charges SolarWinds and its CISO for alleged cybersecurity misstatements and controls failures, Norton Rose Fulbright Data Protection Report, 2023. https://www.dataprotectionreport.com/2023/11/us-sec-charges-solarwinds-and-its-ciso-for-alleged-cybersecurity-misstatements-and-controls-failures/