SEC Tightens Grip on Cybersecurity Disclosures: CISOs Face Increased Enforcement and Risks

In an era moving steadily towards digitization, cybersecurity has become a linchpin of concerns for businesses. Most recently, public company CISOs (Chief Information Security Officers) have been positioned in the crosshairs of the U.S. Securities & Exchange Commission (SEC). Unsettlingly, the SEC appears to be ending its friendly reminders and transitioning into an era of increased enforcement.

Earlier on October 30, the SEC pronounced fraud charges against SolarWinds and their erstwhile CISO. They alleged that SolarWinds’ made public statements in relation to its cybersecurity practices that contradicted its internal evaluations. The accusation emerged amid the initiation of the SEC’s recently formulated regulations for disclosures relevant to cyber risk. Now, public companies are required to adhere to these new and stricter regulations. This compliance necessity also extends to pre-IPOs and foreign private issuers.

The fallout from this case could have extensive implications for CISOs and compliance teams worldwide. Firstly, there’s the potential personal and professional fallout for CISOs if their company’s cybersecurity exaggeration becomes a public issue. It could lead to them being implicated in any penalties handed out due to the misrepresentation.

Moreover, these developments inform a broader shift in the SEC’s approach to enforcing its rules and regulations. An apparent retreat from a “comply or explain” mode, moving towards a stance of rigorous enforcement, can be observed.

CISOs, compliance teams, and executives globally will need to give due attention to this change. Their mandates must now include a focus on demonstrating that their organization’s public statements match the internal realities – especially when it pertains to cybersecurity. Non-compliance to the SEC’s rules could potentially lead to significant corporate and personal consequences.