How to Navigate the New SEC Disclosure Requirements with Nakul Goenka | SecOps Vision 2024
Transcript
Good morning everyone. My name is Na Goenka. I'm with Color Tokens.
We are a company headquartered in the Silicon Valley. Uh, I have, I'm a lawyer by training. I I have been in the IT and cybersecurity business for the last eight plus years, and today I'm gonna be talking about the new SEC disclosure requirements.
Uh, timing could not have been better, I assume by now. Most of you have read or heard about SEC's recent, uh, complaint that has been lodged against SolarWinds and its cso, uh, alleging fraud and other misconduct. Um, so this is gonna be an interesting topic for, to us, for us to discuss and, uh, understand what really these requirements are and how to comply with them.
So, what I've done in order to talk about this is, uh, we are gonna cover a couple of things. First, I'd like to give you an legal overview of all the current federal laws in place. Then we'll get into specifically the SEC requirements, uh, and then talk about, you know, the reporting triggers in terms of when do you disclose, how do you determine, uh, what incidents to disclose or not.
And then finally, we'll talk about how do you prepare for these upcoming, uh, regulations and some key takeaways from that. So, did you know that there are currently 45 in place cyber-security reco reporting requirements in place? These 45 requirements are spread across 22 federal agencies, and it depends on what industry you are in.
I'll give you an example in a minute. But all these rules were created and designed for different purposes. They are independently administered, and they often lead to regulatory overlap and duplicative reporting.
But all these duplicative reporting serve an equally legitimate purpose and distinct information needs of each agency under the respective mission and authorities. So, for example, if you are in the financial services sector, there are eight federal agencies that require reporting incidents that may have a cyber nexus. So, for example, the OCC, which is the Office of Comp Controller, or the FDIC, the Federal Deposit Insurance Corporation, and the Federal Reserve Board, the FRB, they all require cyber incident notification under the computer security incident notification rule.
The same agencies also have a similar reporting requirements under the Graham Leach Bly Act, which of course may overlap, and according, uh, adding to more confusion as a lot of these rules overlap. Similarly, in the health and public sector, you have agencies like the Department of Health and Human Services, or the Federal Trade Commission, and the Fed Food and Drug Administration that have different reporting requirements for, uh, uh, companies operating in the sector. Then you also have, uh, hip hop, which requires another breach notification under their specific rules.
Given that there is so much already in place, you might be wondering why has SEC created yet another different set of rulings or requirements for publicly traded companies to comply with? Well, to give you some insight, I have found these excerpts from the SEC itself, which gives you really good insights into what the s c's thinking is first. SEC has recognized, and rightly so, that cybersecurity is among the most critical governance related issues in the US and what they have recognized, uh, after doing a thorough due diligence and talking to many industry personnel and, uh, uh, or using the information that has been filed by companies that investors don't have information, which is timely and consistent, that may impact their decisions.
SEC, as you know, is concerned with publicly traded companies, and their main thinking is that investors will benefit. Uh, if they are, they are, they are, they are aware of these requirements, or they are aware of these material incidents that may have a significant impact on the company and its business. So with that in mind, uh, you also need to consider there is some broader national context which impacts national security.
So just in the last two years, for example, the, uh, legislators have passed a law which requires all critical infrastructure companies to report cybersecurity incidents to the government within 72 hours. They have also, uh, require CSA to develop and implement regulations, uh, to report these cyber incidents and ransomware payments. Uh, similarly, the Department of Homeland Security has mandated that a range of cyber, uh, critical infrastructure sectors should report incidents within 24 hours.
All these federal rules and statutes follow a series of high profile cybersecurity attacks that have harmed the US national security and the private sector in, in the recent years, just to name a few. SolarWinds is, of course, one, you can think about the move ransomware, which recently created massive havoc across many, many companies, and also Microsoft was recently compromised, compromised, which led to disclosure of thousands, if not millions, of government emails to our, uh, state sponsored actors. So, with that in mind, hopefully this gives you a current landscape of what laws exist today.
And depending on each sector, you may want to look at it really closely because it's not one, one, uh, law that applies. There are multitudes of law and regulations that you need to be aware of. So now let's look at the SEC and what they have done.
So, the SEC, like, like I was talking about, they are primarily concerned that investors should have the right information before them, before they make a investment decision. Publicly traded companies, as you know, they regularly, uh, sell their securities to raise money from the public, and the SEC believes that cybersecurity, since it's a, it's a, a material issue that impacts the entire business, we investors need to be aware of what incidents have, uh, uh, uh, have occurred at the company. So there are three main categories of reporting under the new SEC rules.
I've broken them down into, uh, uh, two slide, two slides. So the first one talks about cybersecurity incident reporting, which has to be filed in something called a Form eight K, which is a proxy statement or a, or a, or a form that you filed with the SEC whenever a material incident happens. Now, we'll talk about what material means in a minute, but in the context of cybersecurity, what the SEC is requiring you to do is, is you must disclose all material aspects of the nature, scope and timing of the incident, and also the material impact or reasonably likely material impact on the company, including its financial condition and the results of operations.
So, for example, recently the Clorox company, we've all used and heard, you know, products from the Clorox company. Uh, they have, they are, uh, they, they had a incident and they were required. They formed a file eight K in their form eight K.
They actually disclosed that their net sales have decreased from 28% to 23%. Their gross margins are expected to be down compared to the company's prior expectations for gross margins to go up, and also the diluted earnings per share is going to take a loss. So these are the kind of information that the SEC is expecting you to disclose so that the investors can make a decision before they actually invest in that particular company.
A lot of times it may also happen that you have identified that yes and cybersecurity incident has occurred, but you may not have the complete information in terms of what to disclose or what impact it may have on the company. In this case, the si uh, CCC says that, you know, there is a requirement where you issue updates about previously disclosed cyber incidents. So I may say that yes, there has been a cybersecurity incident.
This is the nature of the attack, and we are currently, uh, uh, we are currently investigating what impact it may have on the company. Once you identify or once that missing information is available, then you need to file an amendment to the previously filed Form eight K to update the information. Couple of interesting things that have happened in this space is obviously, you know, you need to be cognizant of what a cybersecurity incident really means.
Uh, the SEC defines it as an unauthorized occurrence or a series of related unauthorized occurrence, which are conducted through the company's information system that jeopardizes the confidentiality integrity or availability of the company's systems, or any information residing therein. So it's quite broad and to understand what material is, we look at it in a minute. At the same time, the SEC has also talked about that, look, we are not requesting, or we do not want you to disclose information about the technical details of the incident.
So, for example, what is the remediation status, whether any data has been compromised or what vulnerabilities do exist because the SEC has recognized that all these disclosures are gonna be made public, and if they fall into the wrong hands, they can actually be misused against the, against the disclosing company. So all they, all they're trying to do is that they are, they're recognized that cybersecurity is an important material issue that that faces that we face. And investors need to know about what companies are, are doing, have they been impacted, and if yes, what are, what are they doing to, uh, uh, remediate those issues?
You also have a duty to correct or update any prior disclosures. That's where, again, you file a Form eight K to, uh, as you learn more information, uh, you need to update that periodically. This requirement of for filing a form eight K is already in effect.
And the trigger date really is the date on which the company determines that an incident it has experienced is material. Now, the key word here to consider is material materiality. You know, the, uh, uh, SEC has said that the legal standard for determining materiality of a cybersecurity incident is the same in securities law.
Is, is securities law. Keep in mind, securities law was not designed for cybersecurity. Securities law was designed for making disclosures for the investors.
So, determining materiality, you have to take a lot of information, uh, into consideration. It's not only the quantitative impact or the quantitative, quantitative information like we talked about from the Clorox company, where, you know, the, the gross margins or net sales have gone down. But you also need to look at qualitative factors to determine whether the incident is material or not.
Unfortunately, the quotes have been reluctant to adopt a bright line test or any rigid formula. And the court's view and determination, uh, is, has always been that there is a delicate assessment that is inherently fact and context specific. So what does that mean for you?
We'll talk about it in a minute in terms of what you can do to actually determine whether the material, uh, whether the incident is material or not. But keep in mind, materiality is a key threshold. The SEC has also said that this determination of materiality must be made without unreasonable delay after discovery of a cybersecurity incident.
Now, when I think about this, and when I think about, you know, it, uh, the fact that the average dwell time for a malware or a ransomware ranges between 21 days to 700 days in some instances, it really makes me wonder that we need to take some action so that we can detect attacks faster, collect forensics information, forensic information, and do some analysis, this materiality threshold analysis, so that we can make these disclosures in a timely fashion. Uh, one thing that came to my mind is that most organizations have spent a lot of money and in invest and, and, and effort in actually strengthening that perimeter. So we know what's coming in, in our network, but today, we live in a age where everything is remote.
So there is no perimeter anymore. The internet has become the new perimeter. So it is, is it, it should, it behooves us to consider investments where we get visibility into your east west traffic, into your internal need of data so that you can understand exactly what is happening, who's considering, uh, who's, uh, inside your network, where are they going, just so that you can, you're able to detect incidents faster and understand the impact of such an incident quickly.
There is a very small exception to this rule, uh, in terms of when do you disclose, the SEC says that, you know, if you get a written statement from the US Attorney General that the, or she determines that this disclosure poses a substantial risk to national security of public safety, then this, you can delay the disclosure for up to 30 days and potentially one 20 days again, if you fall under certain exceptions. So this one was largely to do with the Form eight K, the first two ad degrees where you need to disclose material cybersecurity incidents. Next, we'll talk about governance risk management, Andra, uh, risk management and strategy.
The SEC has also mandated that all companies, all publicly traded companies that are under its purview in their annual report, which is filed in a form, uh, which is filed by Form 10 K, they need to describe the company's processes for assessing, identifying and managing material risks from cybersecurity threats. It, it does two things. One, it, it, it, it makes sure that your board is aware.
So come SEC wants to see how the board is providing oversight of risks from cybersecurity threats. And simultaneously, it also talks about, it also wants you to disclose what your management team is doing in assessing and managing the company's material risk from cybersecurity. So, things like, where does the CSO fit in the organization?
How is the information from a SOC analyst or a person who's actually, uh, uh, uh, looking at all your incoming or outgoing threats, how is that information being processed, analyzed, and sent up the chain to the management team right up to the board level so that they know exactly what has, what has been happening, uh, or, or not. Uh, when the SEC had initially proposed these rules, the SEC did state that, you know, every board should have somebody who has cybersecurity expertise. But when the final rules were published in July, 2023, they did not, they did not require the boards to have a cybersecurity expertise.
So it's not like, you know, you need to have a board member who is a cybersecurity expert, but with what's currently going on with the SEC and with these new disclosure requirements, it's just inevitable. It's a matter of time when, you know, boards will want to have somebody who is an expert in cybersecurity, uh, so that they have, they provide proper oversight and also guide the other members of the board and senior management team to do what is right for the company. This specific requirement of filing your annual report is going to, uh, uh, is, is, is going to get effective in December 15th, 2023.
So any company post that, they will have to start in including all this information in their annual reporting, uh, from the subsequent years. So these were in short, the rules, the SEC main re main requirements by the SEC. Now, let's look at what can you do to be, to prepare for these, uh, cybersecurity events?
Of course, you know, uh, from our disclosure controls and procedures, uh, you may already have, uh, a lot of controls processes in place. So make sure that your information security and your IT teams can quickly communicate with the officials who are responsible for disclosure. So that information is free flowing, and it, you can determine that materiality quickly, um, from you.
Remember, one of the requirements was also to a first disclose any material cybersecurity incident, but then also to update that information as in when information becomes available. So collecting and tracking material information and documenting that becomes extremely important. So make sure you have a mechanism in place where you have, uh, all the material information is identified, collected, tracked, documented, and reported to all relevant business units and officials.
Documenta document interactions. I cannot stress enough how important documentation is going to be document. You need to document interactions between security and disclosure officials to illustrate that yes, there is effectiveness or there is lack thereof.
Uh, just in the recent, uh, complaint that has been filed by the SEC against SolarWinds, SEC has actually cited internal emails and documents and presentations where staff has have reported issues to the CSO and to the other members of the management team. And they have cited that as, uh, they have used that to say that the CISO was aware that the management team was aware that they lacked internal controls, but yet they made contradictory statements to the public. So, yes, documentation can be a double-edged sword, but it makes sense to have documentation necessary for what you're doing or what you're not doing.
Uh, either way. I mean, you know, if you're not doing SCC has already fired a warning shot that it, it is going to take this seriously and it'll come after companies who are, who are not complying with these requirements. So there is no, uh, uh, there is, there is no, uh, question about the fact that you will have to comply with these regulations.
Um, you know, you may also have an incidents response in, uh, uh, uh, in place already, but make sure that you include, you know, this materiality assessment in the incidents response plan, uh, so that you know exactly what needs to be done. You must limit the lateral movement of ransomware. So you need to take steps of how you segment your network and limit the lateral movement so that you can include that either in your business continuity plan or incident response plans just for faster detection and risk containment.
This is all, you know, the best situation is that yes, even if an incident occurs, it, it is not material enough for you to disclose, and the way you do that is by containing your risk as much as possible. So that's another, uh, way you can do that by limiting lateral movement of ransomware within your data centers. Um, scheduling regular tests, you know, tabletop exercises, you guys already do that for a lot of other things, uh, including, including this requirement and this process into your tabletop exercises is very, very important.
Uh, you don't want to be caught, uh, uh, caught unaware when actually the incident happens, and then you are scrambling to do stuff. Um, and then also think about hiring third party experts. Uh, either it can be an outside council or like a law firm or a forensic cybersecurity firms to exploit the review, but at the same time, also be aware of how you engage the third party.
You may all remember Capital One got breached several years ago. Uh, one of the unfortunate things that happened with Capital One is that they hired a third party forensics firm, but, uh, and they wanted to keep all the findings of that forensic firm, uh, privilege and confidential. Uh, but the court rule that they are not simply because it was not hired in the, in the right way.
What I mean by that is when you engage an attorney, there is always an attorney client privilege that exists between you and the attorney. And so if you hire me, and if I hire somebody else as a third party, that privilege extends to the third party as well. So, all work that this third party does for you is covered under the attorney client privilege.
So make sure, have a discussion with your legal team or with your general counsel in terms of how do you want to engage, and if this is the right way where you want, you want to make sure that for some stuff, you get that production of attorney client privilege and it's not, uh, discoverable in the event of a litigation or, or, uh, a complaint filed by the SEC. Um, some additional steps, um, ensure consistency of disclosures. This is a big thing, uh, with the SolarWinds complaint currently that is going on.
The SEC has categorically with evidence stated that SolarWinds made a lot of disclosures publicly that were not consistent with the evidence that they saw from internal documentation. So making sure that you are, uh, ensuring consistency of disclosures not only to your regulations, uh, and com, uh, and affected individuals, but also internally because everything should be based on known and verifiable facts and information. Um, this is, this is an ongoing process, uh, right, uh, you saw the requirement was you need to disclose it once, and then as you learn more, you need to update that disclosure.
So make sure that you are continually reassessing all the communications that have been made. This is only going to happen, uh, or you're only going to get stronger with time in terms of how you disclose, uh, and developing some checklists for what you need to disclose, uh, in your proxy statements or in your annual file filings is important. Again, in the recent SolarWinds uh, complaint, the SEC has noted that a lot of companies, uh, you know, include a boiler trade language of how cybersecurity may pose a risk, uh, to their operations.
But that is not sufficient. If you have identified vulnerabilities or if there is something, or if you are complying with a particular standard, say like nist, you need to make sure that you are doing that and documenting all the steps through that. Uh, so just developing a checklist in terms of things that you want to include what you're doing or what you're not doing is important from a disclosure standpoint, and again, I think we covered this earlier, but just tracking historical incidents to help assess whether separate or future incidents could be considered a part of series of related unauthorized occurrences, which is part of the definition of a cybersecurity incident laid out by the SEC is gonna be very, very important.
So, lastly, I'll leave you with some takeaways with my takeaways. Make friends with your legal team, uh, team members, they are the experts. They obviously understand, uh, this requirement.
They have, I'm assuming they have read the case laws, which actually determine materiality. My personal take is that we are gonna see increased litigation and enforcement action by the SEC litigation, not only from the SEC, but also from your investors, uh, or from, uh, uh, uh, uh, share, uh, back act shareholder activists who may want to go after the company. And this is, this is a perfect opportunity for them to do that.
So, uh, make sure that you're covered, uh, uh, and which goes into the right, right into the second point, which is make sure you have, at least for the c-level folks, or who are officers of the company, make sure you have insurance coverage. It's extremely important, uh, because if you don't have coverage, then either you're paying out of pocket or the company is making, uh, or paying, paying for you, uh, which can become really burdensome. Um, there have been some reports, which where I've read, uh, SolarWinds have actually has actually incurred more than a couple of million dollars in legal cost already.
And the complaint of the SEC has just been filed. So it's gonna be a long drawn process and a battle. So making sure you have insurance coverage is gonna be extremely important.
Um, practice, practice and practice. That's the only way you can make sure that you have your plans right. Uh, you are documenting and memorializing stuff, uh, internally and also to your external stakeholders, and you need to make sure that you revisit previous disclosures, just again, from a consistency standpoint to make sure that you are not contradicting yourself.
Otherwise, that can land you on a big, uh, big trouble. With that, I thank you for the opportunity to allow, allowing me to speak, uh, and share a little bit more information about the SEC and their requirements. Please feel free to contact me.
My email is here. I'm, I'm pretty active on LinkedIn as well. Uh, and I look forward to hearing from you.
Thank you.





