Cybersecurity, Privacy, & AI

Trending Now
5 Structural Barriers Breaking Your Cybersecurity Compliance Framework • The Government’s AI Efficiency Numbers Look Good. That Should Worry You. • Why Data Centers Now Belong on the Critical Infrastructure List • The Colorado AI Act Hits a Wall: Litigation, Legislative Uncertainty, and an Enforcement Standstill • Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats

SEC Report Reiterates Cybersecurity Implications for Internal Control Requirement

On October 16, 2018, the Securities and Exchange Commission (SEC) issued a report on the results of investigations made by the SEC’s Division of Enforcement into nine public companies that were victims of cyber-related frauds.  In each case, the SEC investigation focused on whether the target companies had complied with the applicable requirements of the Securities Exchange Act of 1934, as amended (Act). The Act requires public companies to devise and maintain a system of internal control over financial reporting designed to provide reasonable assurance that, among other things, transactions are executed in accordance with company management’s authorization, that transactions are properly recorded and that access to assets is permitted only with management’s authorization.

Ultimately, the SEC did not pursue enforcement actions against any of these companies, but released the report to advise public companies that cyber-fraud incidents must be taken into account when designing and maintaining internal control procedures.

Read the full post at McGuire Woods

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.