SEC Holds Companies Accountable for Cybersecurity Disclosures
The U.S. Securities and Exchange Commission (SEC) recently charged four key companies for alleged misleading public disclosures regarding cybersecurity risks. The companies involved are Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies, and Mimecast.
The Impact of the SolarWinds Attack
The SEC's investigation centers around the ramifications of the infamous SolarWinds Corp. Orion software supply chain attack. This attack, executed in 2020, was a significant cyber incident where malicious code was inserted into the Orion software, providing attackers with access to critical systems across various sectors, including government and private organizations.
Misleading Public Disclosures
The SEC discovered that these four companies downplayed the severity of the SolarWinds breach in their financial filings. Such actions potentially misled investors concerning the true impact of these cybersecurity breaches. Sanjay Wadhwa, acting director of the SEC’s Division of Enforcement, emphasized that companies must not deceive their shareholders regarding the incidents affecting their cybersecurity measures.
Penalties Imposed by the SEC
Among the companies charged, Unisys received the highest penalty of $4 million for failing to employ adequate disclosure controls and procedures. The SEC highlighted that Unisys had described cybersecurity risks as hypothetical while having knowledge of two significant breaches linked to SolarWinds, which led to the extraction of vast amounts of sensitive data.
Comparative Fines
Other companies faced substantial fines as well, with Avaya directed to pay $1 million, Check Point $995,000, and Mimecast $990,000. Avaya had claimed that only a small number of email messages were accessed, yet investigations revealed a much broader breach involving at least 145 files stored in their cloud systems.
Response from Cybersecurity Firms
Check Point, known for its cybersecurity solutions, was accused of minimizing the breach's details and utilizing vague terminology to describe the cyber intrusions. Meanwhile, Mimecast, which provides cloud email and data protection, was cited for not fully disclosing the extent of the attack, particularly regarding sensitive code and compromised credentials.
Moving Towards Compliance
Although the companies have not publicly admitted to any wrongdoing, they have consented to pay the imposed fines and to enhance their cybersecurity frameworks. This response signifies a crucial step toward better accountability and resilience in the face of cyber threats.
Ongoing Legal Proceedings
In a related matter, while the SEC filed a lawsuit in October 2023, many allegations against SolarWinds were recently dismissed in July by U.S. District Judge Paul Engelmayer. The judge concluded that allegations of fraudulent activities against investors lacked substantial evidence, indicating a complex legal landscape surrounding the incident.
Conclusion
The recent SEC actions underscore the importance of transparency and accountability in corporate disclosures concerning cybersecurity risks. As companies increasingly face cyber threats, it becomes essential for them to communicate potential risks accurately to their investors.
Frequently Asked Questions
What companies were charged by the SEC?
The charged companies are Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies, and Mimecast.
What was the main issue leading to the SEC charges?
The SEC found that these companies made materially misleading public disclosures regarding the severity of cybersecurity risks associated with the SolarWinds hack.
What penalties did the companies face?
Unisys was fined $4 million, Avaya $1 million, Check Point $995,000, and Mimecast $990,000 for their misleading disclosures.
What was the SolarWinds attack?
The SolarWinds attack was a significant cyber incident where malicious code was inserted into the Orion software, allowing hackers access to numerous systems across various organizations.
Have the companies admitted to any wrongdoing?
No, the companies have not admitted to or denied the SEC’s findings, but they have agreed to pay fines and improve their cybersecurity practices.