On October 30, 2023, the US Securities and Exchange Commission (SEC) announced fraud charges against SolarWinds and its former chief information security officer (CISO), alleging that “SolarWinds’ public statements about its cybersecurity practices and risks were at odds with its internal assessments.” This comes on the heels of the SEC’s newly implemented rules for disclosures relating to cyber risk. Publicly traded companies (along with pre-IPO and foreign private issuers) must now adhere to new and prescriptive rules requiring the disclosure of “material cybersecurity incidents” as well as annual disclosures relating to “cybersecurity risk management, strategy, and governance.”
There is a lot going on with all the recent SEC and cyber headlines, so let’s break it down piece by piece. This blog outlines several high-level calls to action that CISOs and their stakeholders should consider as they work through their cyber risk strategy and their cyber and/or directors and officers (D&O) insurance renewals.
Also read:
Roadmap for Plaintiffs or Boon for Investors: The SEC’s New Cyber RulesCISO Liability in Focus: SEC Enforcement, Insurance, and [Personal] Risk Mitigation
Let’s dive into some cyber risk management controls that, as a CISO, you should be implementing (or actively lobbying for) in your organization—because the SEC and other relevant third-party claimants are more likely to go after you and your company when a very public, catastrophic, and expensive cyberattack happens.
If your company isn’t at an “ideal” stage of cyber preparedness or maturity, don’t panic. Every journey begins with a single step and you and your team probably have access to resources you may not have thought of. For example, some companies may already have a foundational cyber risk management strategy by virtue of their engagements with cyber insurers, brokers, privacy attorneys, technology consultants, and service providers. If your company has attempted to or currently carries cyber liability insurance, you have already worked to put together detailed information around your incident response plans, disaster recovery, and data protection strategies.
For companies truly beginning from ground zero, the changes in cyber security risk management strategy will likely be a paradigm shift for the entire enterprise, including board members and your C-suite peers. This means the group working on this must open new lines of communication and learn new languages. Fundamentally, clear and open lines of communication and establishing trust and accountability for all stakeholders will be key drivers of success.
Since the wholesale construction of a company’s cyber risk management strategy requires the involvement of many disciplines (not least of which is privacy), seek support from your company’s securities attorneys, privacy counsel, insurance brokers and carriers, and any other experts to advise your team as you go through your dirty laundry. We strongly advise you to engage outside counsel to establish attorney-client privilege at the onset of this journey. Having outside counsel involved may help to protect you and your team as you prioritize projects and make decisions on risk management initiatives—while also justifying your methodologies and timelines in writing. (Where did we see before?)
A tried-and-true starting point to build a roadmap for holistic cybersecurity governance for any company may be the NIST Cybersecurity Framework. The process flows in a logical method and plots a high-level path for boards, audit committees, and management to begin mapping their organization’s cyber risk:
Finally, there is a lot of uncertainty and angst around the intersection of cyber and D&O insurance coverage—specifically in the context of the two policies’ potential coverage for the recent SEC claim against SolarWinds and its former CISO. To be clear, D&O policies should respond to claims alleging mismanagement of a company by its directors and officers and act as an effective backstop and protection for personal assets. This means a D&O policy should respond to the SolarWinds claim resulting from the SEC's October 30 fraud charge. Furthermore, a typical cyber policy would not respond to this type of claim because they are built to respond to loss or theft of data and any resulting privacy litigation.
Let’s shed some light on coverage questions and few calls to action for CISOs to protect themselves:
Regardless of how prepared your company is to meet these SEC requirements today, aligning your cyber and D&O insurance brokers is a great way to simplify efforts and prepare to meet this challenge head-on (and not alone). Working together, your brokers can help you:
It might be a scary time to be a CISO, but knowing the steps to take to protect your company from cyberattacks—and protect yourself from liability—is your best defense. Reach out to your broker to learn how you can beef up your cybersecurity controls and ensure you have the protection you need.