News & Analysis as of

Enforcement Actions Data Breach Publicly-Traded Companies

Holland & Knight LLP

Settlement Alert: The Dust Settles in SEC's Cybersecurity Lawsuit Against SolarWinds

Holland & Knight LLP on

In a significant turn of events on July 2, 2025, the SEC, SolarWinds Corp. and its Chief Information Security Officer (CISO), Timothy Brown, announced through a joint letter to the U.S. District Court for the Southern...more

Vinson & Elkins LLP

Watch What You Say: SEC Enforcement Scrutinizes Cybersecurity Incident Disclosures

Vinson & Elkins LLP on

On January 13, 2025, the Securities and Exchange Commission (“SEC”) filed a settled enforcement action against Ashford Inc. (“Ashford” or “the Company”), a company that provides products and services to the real estate and...more

Morrison & Foerster LLP

SEC Caps 2024 with Another Cyber Enforcement Action

The SEC continues to leave its mark as a federal cybersecurity enforcer and closed out the year by charging another company with making misleading statements about a cybersecurity attack and failing to maintain cyber-related...more

Ropes & Gray LLP

SEC Announces Settlements with Four Issuers regarding Cybersecurity Disclosures

Ropes & Gray LLP on

On October 22, 2024, the Securities and Exchange Commission (“SEC”) filed settled enforcement orders involving four current and former public companies – Unisys Corp., Avaya Holdings Corp., Check Point Software Ltd, and...more

Fenwick & West LLP

The SEC is Cracking Down on Misleading Cybersecurity Disclosure

Fenwick & West LLP on

On October 22, 2024, the SEC charged two current reporting companies, Unisys Corp. and Check Point Software Technologies, and two former public companies, Mimecast Limited and Avaya Holdings Corp., with making materially...more

A&O Shearman

Undeterred By Recent Court Loss, SEC Charges Four Companies With Inadequate Cyber Disclosures In The Aftermath Of SolarWinds...

A&O Shearman on

On October 22, 2024, the SEC announced that it had entered into settlements with four separate companies for making allegedly misleading disclosures about how they were impacted by the SolarWinds data breach in 2019. The...more

Woodruff Sawyer

Violent Delights, Violent Ends? Two Possible Futures of SEC Cyber Regulation

Woodruff Sawyer on

What do the SolarWinds ruling and other recent developments mean for the future of the SEC’s cyber regulatory program? Will the SEC’s “lack of moderation” result in “violent ends” for its cyber agenda? Or will the current...more

Holland & Knight LLP

SEC Cyber Enforcement Update: Which Way Are the SolarWinds Blowing? (Update)

Holland & Knight LLP on

This Holland & Knight blog post is the second installment in a two-part series that examines the challenges to the U.S. Securities and Exchange Commission's (SEC) charges in its landmark case against SolarWinds Corp....more

BCLP

SDNY Dismisses Majority of SEC Landmark Charges Against SolarWinds and CISO

BCLP on

On July 18, 2024, District Court Judge Engelmayer of the Southern District of New York issued his 107-page opinion and order dismissing most – but not all – of the landmark allegations of the SEC against SolarWinds Corp. and...more

Parker Poe Adams & Bernstein LLP

Key Lessons for Cybersecurity and IT Leaders From Judge's Recent Fraud Decision in SEC Case Against SolarWinds

On July 18, a New York federal judge threw out most of the SEC’s claims brought against both SolarWinds Corp. and the company’s chief information security officer (CISO), Timothy Brown....more

Thomas Fox - Compliance Evangelist

SEC, Solar Winds and Compliance

The recent SEC lawsuit against SolarWinds Corp and its CISO, Tim Brown, following the 2020 data breach, has brought the issue of executive liability in cybersecurity disclosures to the forefront. This case sheds light on the...more

Robinson+Cole Data Privacy + Security Insider

SEC Hits SolarWinds and CISO with Investor Fraud Suit Over Cybersecurity

In a first, bold move by the Securities and Exchange Commission (SEC) following its new Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies, issued on July 26, 2023, this...more

The Volkov Law Group

SEC Sues SolarWinds and its CISO for Fraud Over Botched Data Breach Response, Marking New Era in Cyber Enforcement

The Volkov Law Group on

The U.S. Securities and Exchange Commission has a message for publicly-traded companies that suffer a data breach: own up. On Monday, the SEC sued Texas-based SolarWinds––and its Chief Information Security Officer...more

Guidepost Solutions LLC

The SEC has new Cybersecurity Rules. Are you prepared and ready?

On July 26, 2023, the Securities and Exchange Commission (SEC) implemented new cybersecurity rules to require disclosure of material cybersecurity incidents within four business days, with limited exceptions.  Additionally,...more

Jenner & Block

Client Alert: SEC’s Approach to Enforcement After Cyber Incidents: Key Takeaways for Public Companies from a Recent Speech

Jenner & Block on

Last month, Gurbir Grewal, the Director of the SEC’s Division of Enforcement, spoke at the Financial Times Cyber Resilience Summit. During the remarks, he outlined the importance of cybersecurity and signaled that the SEC is...more

Brownstein Hyatt Farber Schreck

When Should a Public Company Disclose a PCI Breach?

As companies collect growing amounts of data about their customers and other consumers, sophisticated adversaries, recognizing the value of this information, have increased their efforts to pilfer it. For publicly traded...more

Bilzin Sumberg

SEC’s $1 Million Settlement with Pearson Over Botched Data Breach Disclosure Is A Cautionary Tale for Public Companies

Bilzin Sumberg on

Careful—and truthful—reporting of a data breach should be a must for any company. But nowhere is this truer than for publicly traded companies. A recent Securities and Exchange Commission Order highlights how costly...more

BCLP

Privacy, Vulnerabilities, and Breaches, Oh My

BCLP on

A recent SEC settlement shed light on data security and privacy concerns that public companies should keep in mind when drafting and filing periodic reports. The SEC settlement concerned a 2018 data breach at Pearson Plc that...more

Herbert Smith Freehills Kramer

The SEC’s Continued Focus on Cybersecurity Enforcement

On June 14, the Securities and Exchange Commission (SEC) announced a $490,000 settlement with the real estate services provider First American Financial Corporation (First American) for violations of disclosure controls and...more

The Volkov Law Group

First American Financial Corporation Settles SEC Case for $487,616 for Cybersecurity Data Breach and Disclosure Failures

The Volkov Law Group on

The Securities and Exchange Commission is gaining traction in the enforcement of cybersecurity and disclosure requirements.  The SEC has a lot on its plate these days – ESG, cybersecurity, and the traditional mix of...more

Stinson - Corporate & Securities Law Blog

SEC Charges Issuer with Cybersecurity Disclosure Controls Failures

The SEC announced a settled enforcement action concerning First American Financial Corporation’s violations of disclosure controls and procedures.  The violations related to disclosures made in connection with a cybersecurity...more

Foley Hoag LLP - White Collar Law &...

White Collar Year in Preview: SEC Enforcement Trends in 2020

Editors’ Note: This is the first in our start-of-year series examining important trends in white collar law and investigations in the coming year. Up next: a look at trends in health care enforcement. Look for additional...more

Bass, Berry & Sims PLC

Key Takeaways from Our Public Company SEC Reporting Webinar

Bass, Berry & Sims PLC on

The Bass, Berry & Sims Corporate & Securities Practice Group recently hosted another in a series of complimentary webinars exploring various public company-related securities law issues. The most recent Securities Law...more

Perkins Coie

SEC 21(a) Report Warns Public Company Email Scam Victims of Bigger Problems Than Stolen Money

Perkins Coie on

Known by many names, including business email compromise fraud, CEO or CFO fraud, impersonation attacks, or “Man-in-the-Email” scams, cyber-related frauds involving spoofed or otherwise compromised business electronic...more

Skadden, Arps, Slate, Meagher & Flom LLP

SEC Investigative Report on Cybersecurity Emphasizes Internal Controls

On October 16, 2018, the Securities and Exchange Commission (SEC) issued a Report of Investigation (Report) detailing an investigation by the SEC’s Enforcement Division into the internal accounting controls of nine issuers...more

33 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide