The $7 million in penalties the Securities and Exchange Commission (“SEC”) collected from four current and former public companies warns other public companies and their leaders of the growing risks of making materially misleading disclosures regarding cybersecurity risks and intrusions affecting their operations to n violation of federal securities law.
The $7 million in civil penalties is the total amount Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies Ltd, and Mimecast Limited agreed to pay to settle a SEC lawsuit charging them with providing misleading disclosures about the cybersecurity incidents they experienced in connection with the SolarWinds’ Orion software breach.
The companies agreed to pay the following civil penalties to settle the SEC’s charges:
- Unisys will pay a $4 million civil penalty;
- Avaya. will pay a $1 million civil penalty;
- Check Point will pay a $995,000 civil penalty; and
- Mimecast will pay a $990,000 civil penalty.
According to Sanjay Wadhwa, Acting Director of the SEC’s Division of Enforcement, the enforcement actions warn other public companies that may become targets of cyberattacks not to further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered.
The SEC’s orders find that each company violated certain applicable provisions of the Securities Act of 1933, the Securities Exchange Act of 1934, and related rules thereunder.
According to the SEC’s orders, Unisys, Avaya, and Check Point learned in 2020, and Mimecast learned in 2021, that the threat actor likely behind the SolarWinds Orion hack had accessed their systems without authorization, but each negligently minimized its cybersecurity incident in its public disclosures.
The SEC’s order against Unisys finds that the company described its risks from cybersecurity events as hypothetical despite knowing that it had experienced two SolarWinds-related intrusions involving exfiltration of gigabytes of data. The order also finds that these materially misleading disclosures resulted in part from Unisys’ deficient disclosure controls. See SEC Order – Unisys Corporation.
The SEC’s order against Avaya finds that it stated that the threat actor had accessed a “limited number of [the] Company’s email messages,” when Avaya knew the threat actor had also accessed at least 145 files in its cloud file sharing environment. See SEC Order – Avaya Holdings Corp.
The SEC’s order against Check Point finds that it knew of the intrusion but described cyber intrusions and risks from them in generic terms. SEC Order – Check Point Software Technologies Ltd
The order charging Mimecast finds that the company minimized the attack by failing to disclose the nature of the code the threat actor exfiltrated and the quantity of encrypted credentials the threat actor accessed. SEC Order – Mimecast Limited.
“Downplaying the extent of a material cybersecurity breach is a bad strategy,” said Jorge G. Tenreiro, Acting Chief of the Crypto Assets and Cyber Unit. “In two of these cases, the relevant cybersecurity risk factors were framed hypothetically or generically when the companies knew the warned of risks had already materialized. The federal securities laws prohibit half-truths, and there is no exception for statements in risk-factor disclosures.”
Without admitting or denying the SEC’s findings, each company agreed to cease and desist from future violations of the charged provisions and to pay the penalties described above. Each company cooperated during the investigation, including by voluntarily providing analyses or presentations that helped expedite the staff’s investigation and by voluntarily taking steps to enhance its cybersecurity controls.
More Information
We hope this update is helpful. For more information about the these or other health or other legal, management or public policy developments, please contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452-8297.
Solutions Law Press, Inc. invites you receive future updates by joining and participating in our LinkedIn SLP Health Care Risk Management & Operations Group, HR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy.
About the Author
Cynthia Marcotte Stamer is a Martindale Hubble “AV-Preeminent” (Top 1%) rated management-focused attorney, coach, consultant and government affairs leader Board Certified in Labor and Employment Law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate, speaker, thought leader and strategist, recognized nationally and internationally for her decades of experience advising, coaching, and representing U.S. and multinational public and private performance and data dependent organizations, their boards and other leaders, investors, creditors, trustees, vendors, and service providers about the defensible use of data and technology, workforce, governance, internal investigations and controls, audits, contracting, and other legal, risk management and operational practices and tools to strengthen the effectiveness and defensibility of their mission-critical performance, compliance, risk management and other goals and activities.
Sought out by business, government and industry leaders for her deep, holistic and highly pragmatic knowledge and experience, scholarship and thought leadership on legally defensible and operationally effective processes for management and mitigation of cybercrime, identity theft, privacy and data security, and other data, technology and other legal and operational risks arising from human resources, employee benefit, and other workforce; health care; insurance; financial services; data and technology and other legal and operational risk management and compliance concerns, Ms. Stamer has worked extensively with health care, managed care and insurance, employee benefits, human resources, financial services, data and technology, and other private and public sector organizations, their leaders, data, technology, and other service providers and other business partners for more than 35 years to promote the legal defensibility of their design, use, protection and management of electronic health, telemedicine and other patient record; medical, insurance, lending and other billing; eligibility, membership, claims, provider, broker and other insurance; payroll and other human resources; investor; financial; research; training; production; quality; marketing; credentialing; and many other data sets; processes and records and operations management systems; Artificial Intelligence and other information systems; and workforce, contracting, security, crisis preparedness and response, breach detection and response, and other related processes, technologies, policies and practices to promote legal and operational compliance and prevent, mitigate, respond to, and resolve cybersecurity and other threats to their data, systems and other operations arising from internal and external theft of trade secrets and industrial espionage; hacking, malware, ransomware, data breaches, and other cybersecurity events; natural disaster; and other data, technology, privacy and other events arising in the course of their operations.
Ms. Stamer’s experience also includes advising, representing, and defending clients in relation to legal, operational, public policy and practical concerns involved in the development, ownership, collection, access, use, analysis, automation, administration, ownership, protection, contracting, licensing, analysis, sale, confidentiality, protection and security, marketing and a diverse range of other concerns associated with Al and other data andknowledge systems, uses, and processes; design, establishment,documentation, implementation, audit and enforcement of policies, procedures, systems and safeguards, drafting and negotiation data collection, analysis, automation, and other systems and processes; licensing, business associate, chain ofcustody, confidentiality, and other contracting; risk assessments, audits and other compliance and risk management; investigation, reporting, mitigation and resolution of known or suspected breaches, violations or other incidents; public policy and regulatory affairs; and defending investigations or other actions by the Justice Department, HHS OCR, FTC, FCC, state attorneys’ general and other federal or state agencies, business partners, private whistleblower and other complainants, and others. Ms. Stamer also regularly provides input and works with Congressional and state legislators; federal and state regulators; and other domestic and foreign governmental agencies, as well as publishes, conducts training and speaks extensively on GDPR, HIPAA, FACTA, PCI, and other data ownership, medical confidentiality, insurance confidentiality and other privacy and data security and other governance, risk management and compliance for a broad range of organizations,their business associates, trade associations and others.
A popular lecturer and prolific author, Cindy has authored hundreds of highly regarded works on cybersecurity, privacy and related matters including U.S. Evolving Restrictive Covenant and Other Knowledge Ownership Protections: Global & Domestic Business, Workplace and Entrepreneurship Effects, American Bar AssociationInternational Section 2024 Annual Conference (May 10, 2024); AI Ethical Competency: What Every IP Lawyer Needs To Know, American Bar Association Intellectual Property Section 2024 Annual Meeting (April 2024); Artificial Intelligence In Insurance, American Bar Association Tort Trial and Insurance Section Theft and Cybercrime Risks, Liabilities and Prevention: Risks & Exposures Relating to HR and Employee Benefits (WEB); Privacy Invasions of Medical Care-An Emerging Perspective, ERISA LITIGATION MANUAL (BNA) (2003-2006); When Your Employee’s Private Life Becomes Your Business (1999-2020); Hard Lessons on Protecting Health Data, INSURANCETHOUGHTLEADERSHIP.COM (May 4, 2017); Cybercrime and Identity Theft: Health Information Security Beyond HIPAA, ABA HEALTH ESOURCE (May 2005); Health Care Providers Face Continuing Personal Identity Theft Exposures, MD News (May 2005); Chapter 8: Other Liability-Tort and Regulatory, E-Health Business And Transactional Law (ABA Health Law Section/BNA (2009) and many others.
Scribe leading the American Bar Association (“ABA”) Joint Committee on Employee Benefits (“JCEB”) annual Technical Session Agency Meeting with the Department of Health and Human Services Office of Civil Rights, Ms. Stamer also provides leadership on these and other concerns by serving in the leadership of many professional, trade, community and other organizations including as the American Bar Association (ABA) Tort Trial and Insurance Practice Section Medicine and Law Committee, ABA International Section International Life Sciences and Health Committee Chair and International Employment Law Committee Co- Chair; ABA Intellectual Property Section Law Practice Management Chair; ABA RPTE Employee Benefits & Other Compensation Group Chair; ABA Health Law Section Managed Care & Insurance Interest Group Chair and E-Health and Technology Interest Group Vice Chair,ISSA-LA and other information security organizations, and many other organizations as well as editorial advisory board member and faculty member of multitude of publications and programs on these and other related topics.
To contact Ms. Stamer about her availability to provide legal services or training or for additional information about Ms. Stamer, her experience, involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources available here.
IMPORTANT NOTICE ABOUT THIS COMMUNICATION
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as legal advice or an admission. The author and Solutions Law Press, Inc.™ reserve the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving, and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The author and Solutions Law Press, Inc.™ disclaim, and have no responsibility to provide any update or otherwise notify anyone any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication. Readers acknowledge and agree to the conditions of this Notice as a condition of their access of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2024 Cynthia Marcotte Stamer. Limited non-exclusive right to republish granted to Solutions Law Press, Inc.™