Fines Given to SolarWinds Breach Victims for Inadequate Reporting

Published:

spot_img

SEC Charges Four Companies for Minimizing SolarWinds Breach Impact

The Securities and Exchange Commission (SEC) has charged four companies for their attempt to downplay the impact of the 2020 SolarWinds breach on their systems. Unisys received the largest civil penalty of $4 million for its misleading disclosure practices and control violations. The SEC found that Unisys failed to accurately report the exfiltration of data during two SolarWinds-related intrusions.

Avaya Holdings Corp. agreed to pay $1 million for understating the extent of the breach, and Check Point was fined $995,000 for vague disclosures. Mimecast received the lightest penalty of $990,000 for failing to disclose the nature of the exfiltrated code and accessed encrypted credentials.

The SEC’s goal with these charges and fines is to deter companies from minimizing the impact of cybersecurity breaches through vague or misleading disclosures. Jorge G. Tenreiro, acting chief of the Crypto Assets and Cyber Unit, emphasized the importance of accurate and precise disclosures in such cases.

According to cybersecurity attorney Beth Burgin Waller, companies can no longer rely on generalizations or hypotheticals when reporting breaches. She highlights the need for closer collaboration between chief information security officers and legal teams to ensure that disclosures are technically precise and comply with regulatory requirements.

This enforcement action by the SEC serves as a warning to companies to be transparent and forthcoming in their reporting of cybersecurity incidents to avoid facing similar penalties in the future. It underscores the importance of maintaining strong cybersecurity controls and proactive risk management strategies in the face of evolving cyber threats.

spot_img

Related articles

Recent articles

Google’s Dark Web Monitoring Is Ending: Next Steps for You

Google is set to discontinue its dark web monitoring service designed to warn users about the exposure of personal information, such as names, email...

Understanding the Digital Trust Crisis: Why We Question Every Click

When Convenience Turns into Caution The internet was originally founded on a principle of trust: confidence that online transactions would be secure, personal identities would...

84 Hours of Internet Blackout in Iran Amid Growing Unrest

Iran's Internet Blackout: A Deepening Crisis Amid Unrest Four Days Without Connectivity Iran has plunged into a state of digital isolation as an internet blackout enters...

NSA Appoints Timothy Kosiba to Lead Cybersecurity Strategy

Appointment of Timothy Kosiba as NSA Deputy Director: A Leadership Milestone The National Security Agency (NSA) has recently announced a pivotal leadership change with the...