Focus on US Securities and Exchange Commission and Cybersecurity
SEC Cybersecurity is a term to encompass the Securities and Exchange Commission (SEC) guidance role in the overall spectrum of cyber threats against public companies. The SEC is a federal agency charged with the task of ensuring the protection of investors. According to the official webpage, “The mission of the U.S. Securities and Exchange Commission is to protect investors, maintain fair, orderly, and efficient markets, and facilitate capital formation.” The agency’s efforts to guide against and prevent breaches in cybersecurity are simply an extension of the SEC’s function.
There are several ways the SEC carries out its mission. This includes:
- Offering guidance to investors about safe online trading practices
- Providing resources to prevent cyber-related crimes
- Offering guidance to organizations on reporting breaches and other cybersecurity threats
- Use civil law to pursue criminal activity and wrongdoing
On February 21st, 2018, The SEC published a Commission Statement to take effect five days after February 26th, 2018. The statement is for interpretive guidance, or recommendations, specifically for public companies on the subject of “preparing disclosures about cybersecurity risks and incidents.” With the dramatic increase of data breaches and other malicious problems of the hostile Internet, companies are being caught unaware. The statement aims to protect investors by recommending best practices for companies in terms of their cybersecurity.
The online world is perhaps one of the most hostile environments for financial markets. With no shortage of malicious software and wrong-doing, there are now multiple cases of law enforcement. In fact, the SEC has a dedicated cybersecurity enforcement webpage including:
- Digital Currency and Initial Coin Offerings (ICOs)
- Account Intrusion
- Hacker and Insider Trading
- Market Manipulation
- Safeguarding Customer Information
- Trading Suspensions
Cases of note include:
- Morgan Stanley Failed to Safeguard Customer Data
- Day Trader Charged in Brokerage Account Takeover Scheme
- Securities and Exchange Commission v. Iat Hong, et al.
Contributed by Magdalena A K Muir
Sources
SEC Webpage: What we do; https://www.sec.gov/Article/
SEC Commission Statement and Guidance on Public Company Cybersecurity Disclosures; https://www.sec.gov/rules/
SEC Cyber Enforcement Actions; https://www.sec.gov/spotlight/