Four Companies Settle Allegations of Deceptive Cyber Disclosures with SEC

Robinson+Cole Data Privacy + Security Insider
Contact

This week, the Securities and Exchange Commission (SEC) charged four public companies for alleged deceptive cyber disclosures: Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies Ltd., and Mimecast Limited. The companies agreed to pay civil penalties to settle the SEC’s charges as follows:

  • Unisys, $4 million
  • Avaya, $1 million
  • Check Point, $995,000
  • Mimecast, $990,000

These penalties and settlements come after an SEC investigation into public companies that were potentially affected by the SolarWinds’ Orion software compromise. The SEC alleged that while the companies learned about the unauthorized access to their systems as a result of the SolarWinds Orion attack, they each negligently minimized the effects of the cybersecurity incident in their public disclosures. Sanjay Wadhwa, Acting Director of the SEC’s Division of Enforcement, said, “As [these] enforcement actions reflect, while public companies may become targets of cyberattacks, it is incumbent upon them to not further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered. Here, the SEC’s orders find that these companies provided misleading disclosures about the incidents at issue, leaving investors in the dark about the true scope of the incidents.”

The SEC’s orders found that each company violated some provisions of the Securities Act of 1933, the Securities Exchange Act of 1934, and related rules.

A few key takeaways from these settlements:

  • Cybersecurity is still an SEC enforcement priority;
  • Disclosure and escalation procedures are vital;
  • The SEC will be aggressive on its charges for negligence-based fraud charges related to cyber attacks; and
  • Be prepared -have an incident response procedure and disclosure policy.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Robinson+Cole Data Privacy + Security Insider

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide