On October 30, 2023, the U.S. Securities and Exchange Commission (SEC) took an assertive stance in enforcing cybersecurity transparency standards. The regulatory body filed charges against SolarWinds Corp. and its Chief Information Security Officer (CISO) for deceiving the company’s investors and customers.
The charges came amidst the SEC Division of Enforcement’s investigation of a significant cyberattack on SolarWinds. According to the complaint, SolarWinds and its CISO allegedly crafted a web of misstatements, omissions, and schemes that hid the real state of the company’s cybersecurity practices from the public – a damning assertion with potential repercussions for public companies’ cybersecurity disclosures.
In light of the SEC’s charges, it’s crucial that public companies and their legal counsel critically evaluate their cybersecurity policies and disclosure practices. A thorough understanding of the applicable laws and regulations, combined with a proactive approach to security, will protect both the company and its investors.
Moreover, this incident underscores the growing focus of the SEC on cybersecurity issues, and the expectation that companies will be transparent about their cybersecurity risks and incidents.
This case serves as a stark reminder of the potentially severe ramifications of substandard disclosure practices concerning cybersecurity procedures and breaches. The SEC’s clear message to public companies: be transparent about your cybersecurity situation or face the consequences.
With the SEC spotlight on cybersecurity increasingly sharpened, public companies must approach cybersecurity with even greater diligence, understanding that careful disclosure of cybersecurity risks is no longer optional, but rather, a mandatory part of doing business in today’s digital age.