If you’ve ever attended the SEC Speaks conference, you know that the official program is an intensely uninteresting collection of short speeches by SEC officials who don’t have a lot of incentives to say groundbreaking things. But occasionally there are exceptions. I think Deputy Director Stephanie Avakian’s discussion of cybersecurity cases on Friday was one of those.
Avakian broke those cases down into three categories.
- Failures of registered entities to safeguard information. She cited the R.T. Jones Capital Equities Management case from September of last year as an example of those.
- Electronic thefts of material nonpublic information, and illicit securities trading following the thefts. Avakian cited the Dubovoy case filed in the District of New Jersey last August and updated on Thursday as an example of these.
- Cyber-related disclosure failures by public companies. The SEC hasn’t brought any cases in this category yet, and much of Avakian’s discussion focused on why that is the case and how the SEC might get to the point of bringing one.
Assuringly for companies that are investing resources in cybersecurity and trying to do the right things for its customers and shareholders, Avakian said, “A company that has been a victim of an intrusion is just that: a victim.” She also said in several different ways that the Division understands that when attacks happen, critical facts can change and develop very quickly. These developing facts can make any necessary disclosures a moving target. Along these lines, the Enforcement Division will appreciate the difficulty of the circumstances, Avakian says. She added that the SEC is not looking to second guess well thought decisions in this area.
With all of that said, the Enforcement Division very much wants companies that are victims of cyber attacks to involve appropriate law enforcement authorities as quickly as they reasonably can. It will also examine (1) whether companies have policies and procedures that are reasonably designed to protect customer information; and (2) whether companies with potential liability have self-reported issues to the Division. Regarding the second factor, the SEC’s Seaboard Report from 2001 continues to include the guideposts the Division will consider.
While no cases have yet been brought against public companies in this third category, Avakian can imagine circumstances in which the Commission does file a case to penalize inadequate cybersecurity disclosures. I can, too. Be careful out there.
Add a comment
Archives
- January 2022
- June 2021
- March 2020
- August 2019
- March 2019
- October 2018
- July 2016
- June 2016
- May 2016
- February 2016
- November 2015
- September 2015
- July 2015
- April 2015
- March 2015
- February 2015
- January 2015
- December 2014
- November 2014
- October 2014
- July 2014
- March 2014
- July 2013
- June 2013
- April 2013
- March 2013
- October 2012
- September 2012
- August 2012
- April 2012
- March 2012
- February 2012
- January 2012
- November 2011
- September 2011
- June 2011
- May 2011
- April 2011
- February 2011
- January 2011
- December 2010
- October 2010
- September 2010
- August 2010
- July 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2006
- February 2006
Recent Posts
- Rethinking Your Cyber Insurance Needs as Your Workplace Evolves
- Data Breach Defense for Educational Institutions
- COVID-19 and the Increased Cybersecurity Risk in a Work-From-Home World
- Like Incorporating Facebook into your Website? EU Decision Raises New Issues
- Lessons Learned: Key Takeaways for Every Business from the Capital One Data Breach
- Will Quick Talks to WRAL About Privacy Issues Related to Doorbell Cameras
- About Us
- Not in My House - California to Regulate IoT Device Security
- Ninth Circuit Says You’re Going to Jail for Visiting That Website without Permission
- Ninth Circuit Interprets “Without Authorization” under the Computer Fraud and Abuse Act
Topics
- Data Security
- Data Breach
- Privacy
- Defamation
- Public Records
- Cyberattack
- FCC Matters
- Reporters Privilege
- Political Advertising
- Newsroom Subpoenas
- Shield Laws
- Internet
- Miscellaneous
- Digital Media and Data Privacy Law
- Indecency
- First Amendment
- Anti-SLAPP Statutes
- Fair Report Privilege
- Prior Restraints
- Education
- Wiretapping
- Access to Courtrooms
- FOIA
- HIPAA
- Drone Law
- Access to Search Warrants
- Access to Court Dockets
- Intrusion
- First Amendment Retaliation
- Mobile Privacy
- Newsroom Search Warrants
- About This Blog
- Disclaimer
- Services