SEC Report Cautions Companies to Consider Cyber Threats with Internal Controls

Robinson+Cole Data Privacy + Security Insider
Contact

The Securities and Exchange Commission (SEC) this week issued an investigative report that outlined cyber incidents that nine public companies had experienced, causing fraudulent losses totaling more than $100 million. The conclusion of the report is that public companies “should consider cyber threats when implementing internal controls.”

The investigations focused on business email compromises where intruders posed as company executives or vendors and used emails (usually through phishing and spear phishing campaigns) to trick employees into sending large amounts of money to bank accounts controlled by the fraudsters. According to the report, these campaigns lasted months on end, and the funds were largely not recoverable. The report cited an FBI statistic that business email compromise has cost U.S. companies more than $5 billion since 2013.

The companies were from different industries, including technology, machinery, real estate, energy , financial and consumer goods. This is instructive for all companies to see that victim companies are in every industry and no industry is immune. SEC Chairman Jay Clayton stated “Cyber frauds are a pervasive, significant, and growing threat to all companies including our public companies. Investors rely on our public issuers to put in place, monitor, and update internal accounting controls that appropriately address these threats.”

Although none of the companies were fined as a result of the security incidents, the SEC stated “…our report emphasizes that all public companies have obligations to maintain sufficient internal accounting controls and should consider cyber threats when fulfilling those obligations.”

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide