Focus on US Securities and Exchange Commission and Cybersecurity

SEC Cybersecurity is a term to encompass the Securities and Exchange Commission (SEC) guidance role in the overall spectrum of cyber threats against public companies. The SEC is a federal agency charged with the task of ensuring the protection of investors. According to the official webpage, “The mission of the U.S. Securities and Exchange Commission is to protect investors, maintain fair, orderly, and efficient markets, and facilitate capital formation.” The agency’s efforts to guide against and prevent breaches in cybersecurity are simply an extension of the SEC’s function.

There are several ways the SEC carries out its mission. This includes:

  • Offering guidance to investors about safe online trading practices
  • Providing resources to prevent cyber-related crimes
  • Offering guidance to organizations on reporting breaches and other cybersecurity threats
  • Use civil law to pursue criminal activity and wrongdoing

On February 21st, 2018, The SEC published a Commission Statement to take effect five days after February 26th, 2018. The statement is for interpretive guidance, or recommendations, specifically for public companies on the subject of “preparing disclosures about cybersecurity risks and incidents.” With the dramatic increase of data breaches and other malicious problems of the hostile Internet, companies are being caught unaware. The statement aims to protect investors by recommending best practices for companies in terms of their cybersecurity.

The online world is perhaps one of the most hostile environments for financial markets. With no shortage of malicious software and wrong-doing, there are now multiple cases of law enforcement. In fact, the SEC has a dedicated cybersecurity enforcement webpage including:

  • Digital Currency and Initial Coin Offerings (ICOs)
  • Account Intrusion
  • Hacker and Insider Trading
  • Market Manipulation
  • Safeguarding Customer Information
  • Trading Suspensions

Cases of note include:

https://digitalguardian.com/sites/default/files/SECresources.png

Contributed by Magdalena A K Muir

Sources

What is SEC Cybersecurity; https://digitalguardian.com/blog/what-sec-cybersecurity?mkt_tok=eyJpIjoiTnpWaE5qZzFOalZsT1RKaSIsInQiOiJsdlZkbVI2UCtzOHR4T2JcL2JhVUZ2MXVRM3VLMXNkWmllNEFzbDBlY3M4ek1pUVpDNGVxZytMeFMzdyt2Q0lNdGFCakZKTmlsZVJHWW1OUGIzNXhyN1poYTNtUUxSVXYrZWIyTnB0VUh1XC95dGtmSDZsSEdRZHhFSnpQQUswV0JrIn0%3D

SEC Webpage: What we do;  https://www.sec.gov/Article/whatwedo.html

SEC Commission Statement and Guidance on Public Company Cybersecurity Disclosures; https://www.sec.gov/rules/interp/2018/33-10459.pdf

SEC Cyber Enforcement Actions; https://www.sec.gov/spotlight/cybersecurity-enforcement-actions