For several years, cybersecurity has been a perennial D&O liability issue. Although there has never quite been the volume of cybersecurity-related D&O litigation that some anticipated, cybersecurity-related D&O claims do continue to arise. In the latest example, last week a plaintiff shareholder filed a securities suit against cloud data storage company Snowflake, alleging, among many other things, that the company…
The U.S. Department of Justice is increasingly focusing its enforcement efforts under the False Claims Act on cybersecurity, an official recently confirmed, raising new compliance challenges for a wide range of contractors. Deputy Assistant Attorney General Brenna Jenny, speaking last month at the American Conference Institute, noted a “significant upward trajectory” in cybersecurity FCA cases, a trend expected to continue.…
On May 16, 2024, the Securities and Exchange Commission (SEC) unanimously approved amendments to Regulation S-P, which imposes new rules relating to cybersecurity breaches involving investment advisers and broker-dealers. Larger entities must comply with the new rules by December 3, 2025, while smaller entities must comply by June 3, 2026. The amendments to Regulation S-P added requirements compelling covered institutions…
In the immediate aftermath of the Delaware Supreme Court’s 2019 decision in Marchand v. Barnhill, which revitalized so-called Caremark claims for breach of the duty of oversight, one question I was asked was whether claimants might seek to assert breach of the duty of oversight claims in the context of cybersecurity and data privacy issues. Claimants did, in fact, subsequently raise Caremark claims…
For public companies, the SEC’s announced focus on “fraudulent” cybersecurity disclosures potentially marks a likely shift away from SEC cybersecurity disclosure cases to date. The SEC’s cybersecurity disclosure actions have largely applied a consistent, but aggressive, approach in seeking negligence-based fraud charges and significant penalties despite mitigating factors such as cooperation and remediation. The cybersecurity enforcement landscape going forward may…
Enforcement takeaways (according to DFS allegations in the Consent Order with PayPal): • NYDFS found customer data was exposed after PayPal implemented changes to make 1099-K forms available to more of its customers, after teams tasked with implementing these changes failed to follow proper procedures before the changes went live. • Malicious actors leveraged compromised credentials to access Form 1099-Ks, and PayPal…
The number of cybersecurity incidents disclosed by public companies has increased 60% since the SEC rules went into effect. Reed: The rule itself is clearly having an impact and forcing public companies to consider whether a cyber incident has a material impact on a company. And it’s giving insight, I think, into the market of incidents that otherwise might not…
More corporate victims of cyberattacks disclosed their hacks during the first year of new federal reporting requirements, according to a Paul Hastings analysis of breach disclosures. The law firm’s study, examining 75 disclosures from 48 public companies between Dec. 18, 2023 and Oct. 31, revealed a 60% increase in cyber incident disclosures since the US Securities and Exchange Commission’s new…
Canellos is not a fan of the way the materiality standard has been applied to the cyber security cases. From the panel transcript: Okay, look, I think the rules in general were much needed. Right? I think we had very little guidance in this and I applaud the commission for coming up, taking a stab at it. Their rulemaking, I…
Takeaways Worth Considering — Public companies may want to include representatives from their cyber function in discussions about periodic cyber risk disclosures to ensure the disclosure function has the benefit of current information about which risks remain hypothetical and which have been realized. — The impact of SolarWinds’ partially successful motion to dismiss, which challenged among other things the SEC’s…
