Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Partner Perspectives  Connecting marketers to our tech communities.
SPONSORED BY
3/14/2018
09:00 AM
Peter Martini
Peter Martini
Partner Perspectives
50%
50%

How to Interpret the SECs Latest Guidance on Data Breach Disclosure

Forward-looking organizations should view this as an opportunity to reevaluate their cybersecurity posture and install best practices that should have already been in place.

On the heels of several headline-grabbing data breaches – and greater emphasis on the importance of disclosure in the lead-up to the May 25 General Data Protection Regulation (GDPR) deadline – the US Securities and Exchange Commission (SEC) recently issued a statement that puts more responsibility on executives for data breaches.

This updated guidance calls for public companies to provide investors with more information on all cybersecurity incidents – even just the existence of potential risks – with minimal delay. The statement goes a step farther in attempting to thwart the potential for the exchange of "insider" information, which was a major concern on the heels of the record-shattering Equifax data breach.

Specifically, corporate officers, directors and “other corporate insiders” are prohibited from trading shares if they have knowledge of any unpublicized security incident within the company.

While the overall intent of this latest statement is clear, the guidance is vague in key areas by design. For instance, the second section of the guidance emphasizes that companies must make "timely disclosure of any related material nonpublic information." It’s unclear what the SEC explicitly means by "timely disclosure," as the SEC doesn’t provide a specific time limit that companies must meet. This puts a lot of trust in corporate leaders to put speedy remediation and due diligence at the center of their security policy, which is a bit of a gamble given the track record of executive action during the fallout of the Equifax breach.

The GDPR, on the other hand, is much more prescriptive, giving organizations 72 hours to report an incident related to the personal data of EU citizenry. This isn’t to say that the European Commission has greater distrust for business leaders to make the right call than legislators in the United States, so much as it creates a clear and distinct timetable.

The guidance from the SEC is significant, however, in that it essentially tees up every executive board to make room for or delegate an in-house expert on cybersecurity best practices. It updates a comparably less hawkish stance on the part of the SEC in trying to minimize the occurrence of insiders acting poorly in the time between a major data breach and public disclosure.

Another reason for the vagueness surrounding the actual time limits for disclosure is that the SEC doesn’t want to force businesses to prematurely disclose information that might only publicize vulnerabilities to potential hackers. It’s a delicate balance, as teams want to make sure they are planning their defense thoughtfully before inciting more damage to the company’s data stores – not to mention brand perception.

As part of the GDPR guidance, many data-centric businesses will be required by law to employ a Data Protection Officer (DPO) that acts alongside the network administrators and security teams to enforce best practices and report potential incidents. While this isn’t mandatory for all businesses, companies that aren’t looking to employ cybersecurity experts are doing so at their own risk – especially given this new guidance from the SEC. The cost for not following through on best practices in the event of a breach can be far more significant than putting an in-house expert on the payroll.

While many may view the new SEC guidance and GDPR as onerous red tape, forward-looking organizations should view this as an opportunity to reevaluate their cybersecurity posture and install best practices that should have already been in place. After all, having someone who is tasked with ensuring your organization is secure and protecting its data appropriately is something every organization should embrace.

As president and co-founder of iboss, Peter Martini has played a major role in developing iboss' innovative technology, and has helped shepherd iboss' phenomenal growth, since its founding. He has been awarded dozens of patents focused on network and mobile security, and with ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/31/2020
'BootHole' Vulnerability Exposes Secure Boot Devices to Attack
Kelly Sheridan, Staff Editor, Dark Reading,  7/29/2020
Out-of-Date and Unsupported Cloud Workloads Continue as a Common Weakness
Robert Lemos, Contributing Writer,  7/28/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-14310
PUBLISHED: 2020-07-31
There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a ma...
CVE-2020-14311
PUBLISHED: 2020-07-31
There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.
CVE-2020-5413
PUBLISHED: 2020-07-31
Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" exploit when provided data contains mali...
CVE-2020-5414
PUBLISHED: 2020-07-31
VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Manager; however, the unredacted logs are a...
CVE-2019-11286
PUBLISHED: 2020-07-31
VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2, contain a JMX service available to the network which does not properly restrict input. A remote authenticated malicious user may request against the ...