Subscribe

Join Us On LinkedIn

On June 14, the Securities and Exchange Commission (SEC) announced a $490,000 settlement with the real estate services provider First American Financial Corporation (First American) for violations of disclosure controls and procedures related to cybersecurity vulnerabilities. Notably, the SEC’s case against First American did not specifically focus on a cyberattack or allege an underlying securities […]
According to the SEC’s order, on the morning of May 24, 2019, a cybersecurity journalist notified First American of a vulnerability with its application for sharing document images that exposed over 800 million images dating back to 2003, including images containing sensitive personal data such as social security numbers and financial information. In response, according […]
Many publicly traded companies are leaving investors in the dark on important cybersecurity risks, a new report suggests. That includes vulnerabilities like the ones that allowed Russian hackers to exploit SolarWinds and other firms to infiltrate nine federal agencies and at least 100 companies. The study’s authors found that many publicly traded companies fail to provide […]
A cyber breach can have serious legal, financial, and reputational consequences for a fund sponsor, as described in our previous post. As such, cybersecurity threats must be treated as business risks, not just a potential IT problem. Senior management at fund sponsors should take the lead to ensure that the sponsor is taking appropriate actions […]
On December 12, 2019, the Securities and Exchange Commission (SEC) awarded Booz Allen Hamilton (NYSE: BAH) an extensive 10-year contract, totaling $113 million, to deliver modernized cyber defense operations support. With this new contract, Booz Allen will become the SEC’s major provider of cybersecurity services. Booz Allen was selected for its clear understanding of the […]
The Securities and Exchange Commission today announced that Nancy Sumption will serve as Chairman Jay Clayton’s Senior Advisor for Cybersecurity Policy. In this role, Ms. Sumption will coordinate efforts across the agency to address cybersecurity policy, engage with external stakeholders on matters related to cybersecurity, and help enhance the SEC’s mechanisms for assessing and responding […]
The Securities and Exchange Commission Commission’s Office of Compliance Inspections and Examinations (OCIE) today issued examination observations related to cybersecurity and operational resiliency practices taken by market participants. The observations highlight certain approaches taken by market participants in the areas of governance and risk management, access rights and controls, data loss prevention, mobile security, incident response and resiliency, […]
Davis Polk today announced that Robert Cohen will join the firm as a partner in the Litigation Department in Washington DC. Mr. Cohen will be a member of the firm’s White Collar Criminal Defense and Government Investigations Group, where he will focus on representing companies and boards in regulatory matters and internal investigations. He joins […]
The Securities and Exchange Commission today announced that Robert A. Cohen, Chief of the Division of Enforcement’s Cyber Unit, will be leaving the agency in August after 15 years of service. Mr. Cohen is the first Chief of the Cyber Unit, created in 2017. The unit focuses on violations involving digital assets and cryptocurrency, cyber-related trading […]
A Louisiana law firm that specializes in shareholder class-action suits says it is investigating reports that Duke Energy Corp. has agreed to a record $10 million regulatory fine for a raft of cybersecurity violations on its electric grid. New Orleans-based Kahn Swick & Foti says the “investigation is focusing on whether Duke’s officers and/or directors […]