An SEC roundtable on cybersecurity focused on the requirements of the commission's 2011 Guidance on cybersecurity disclosure, compliance practices and recommended actions to help the SEC to fulfill its dual mission of encouraging capital raising while protecting markets and investors.
SEC's 2011 GuidanceÂ
As a baseline point of reference, the U.S. Securities and Exchange Commissionâs Division of Corporation Finance (DCF, or CF) released
CF Disclosure Guidance Topic No. 2: Cybersecurity in 2011
.  The document, which is not a formal position of the commission or standard,  states:
We are mindful of potential concerns that detailed disclosures could compromise cybersecurity efforts -- for example, by providing a âroadmapâ for those who seek to infiltrate a registrantâs network security -- and we emphasize that disclosures of that nature are not required under the federal securities laws.
Current Disclosure Status
When asked by SEC commissioners and senior staff what types of disclosures have resulted from the 2011 guidance, most of the  panelists' responses fell into two categories:
- Companies provided no disclosure or very little disclosure of any actual cyber breaches, often on advice of counsel or otherwise, based on a determination that the event(s) was(were) ânot materialâ, or
- Companies made a very âboilerplateâ disclosure.
The reasons given by panelists for âboilerplateâ disclosures were much like the reason cited in the SECâs 2011 rule: there was concern not to provide, via public disclosure, a 'roadmap' to cyber vulnerabilities that could be used to plan cyberattacks against the company.
David Burg, global and U.S. advisor, cybersecurity leader, PwC noted, âThere are very real cybersecurity threats, whether they are made public or not.â
Attorney Douglas Meal of Ropes & Gray noted, âA company disclosing a cybersecurity risk that is not otherwise disclosed could be viewed as doing as much damage as the attacker.â He added, âThere is a tremendous disincentive to disclose a cybersecurity breach, if it would not otherwise become public.â
Asked by SEC Chair Mary Jo White if her company is ever specifically instructed by DHS not to disclose information publicly, Leslie T. Thornton, vice president and general counsel, WGL Holdings, Inc. and Washington Light and Gas Co. replied, âSometimes we are told by the government that something is classified; we have to determine what we can disclose.â She added she is hopeful government agencies would understand the challenges her company faces with some agencies asking her to keep information classified, and others placing duties to disclose certain matters to investors on her company.
Cyber is Threat #1, Comey Tells Congress
SEC Chair White, citing remarks made by FBI Director Jim Comey last fall, stated in her
opening remarks that the scope of the cyberthreat problem exceeds the threat of (physical) terrorism.
This message was hammered home in Comeyâs testimony at budget hearings in Congress and the Senate last week.
Ari Schwartz, acting senior director for cybersecurity programs, National Security Council, told the SEC roundtable, âThe president has focused on the need for critical infrastructure. The starting point is to have an attitude in place that cybersecurity is risk, and what do market participants need to know about risks.â
He added, âWe need Congress to act in this space, we hear this in a bipartisan way. The president issued executive orders (see Executive Order: Improving Critical Infrastructure Cybersecurity), the agencies are working together, NIST issued its cybersecurity framework.â (See: NIST Cybersecurity Framework. See also: DHS Critical Infrastructure Partnership Advisory Council (CIPAC), and DHS Critical Infrastructure Cyber Community C3 Voluntary Program.)
Larry Zelvin, director, National Cybersecurity & Communications Integration Center, U.S. Department of Homeland Security, said, âYou can lock down your controls here, but if portions of your business are overseas, you are vulnerable to cyber [threats]."
He encouraged companies to engage in  discussions with DHS.  âWe have the ability to share our information with all the ISPs and law enforcement to go after bad people;  cybersecurity and intelligence can see where an adversary is going next. It's about trust that government can use information appropriatelyâ he said.
Asked by Commissioner Michael Piwowar if there are particular kinds of cyber attackers the government agencies are concerned about, DHSâs Zelvin said, âThere are nation states coming after you, they see you as a representation of the country;Â I worry about inside threats (as well).â
The Private Sectorâs Response
Mary Galligan, director of the Cyber Risk Services Practice of Deloitte and a former special agent in charge of Cyber and Special Operations for the FBIâs New York City Office,  said âthe more quickly a [cyber] incident is detected, the easier it is to recover.â
"We cannot close every cybersecurity vulnerability,â Galligan said, but she added it is very important to conduct "a true risk assessment/baseline,â as well as focus on âhow do I monitor the monitors,â i.e.: 1) how are we monitoring what data leaves my company, (2) do we have a cybersecurity incident response plan, and (3) is that cybersecurity response plan up to date?" She added, âWe see companies doing (cybersecurity) war games, [as simulations]."
Perhaps most significantly, Galligan noted, âThe cybersecurity issue starts at the keyboard.â
âWe are seeing more organized use of [credit card] information; and rapid development of malware,â said Andy Roth of Dentonâs LLP, where he serves as co-head of Dentonâs privacy and cybersecurity group.
Karl Schimmick, managing director, Financial Services Operations, SIFMA, said it is important to, âFocus on the outcomes: compliance is not the outcome. You can be in compliance, and still be vulnerable.â
John Reed Stark, a Managing Director in Stroz Friedbergâs office and former chief of the SECâs Office of Internet Enforcement in the Division of Enforcement, Â cautioned the SEC chair, commissioners and senior staff at the roundtable, âI urge you to be judicious in your enforcement referrals; if you are not sensing a fraud, hopefully you will consider this [advice].â He continued, âI am worried a lot of companies won't be able to give you the satisfaction that they are giving you everything they can.â
The Bottom Line: The Challenges of Cost-Benefit
My two cents: The more I read about cyber threats, the more harrowing the cybersecurity threat  becomes, not only with respect to the financial markets, but also  to critical infrastructure.
âThe Bottom Lineâ often refers to total cost vs. total benefit. The SEC and others have remarked on difficulties in quantifying or measuring âcostsâ and âbenefits,â and in the case of the costs of cybersecurity disclosures in particular, it would appear the potential cost of adding risk through detailed disclosures of cyber break-ins could overcome the potential benefits of disclosure.
As some panelists suggested, a âprudentialâ regulatory approach of having confidential discussions between the SEC and companies, may be a better form of âdisclosureâ with respect to this particular issue; and boilerplate information may be the only disclosure that can  be given safely to avoid providing âroadmapsâ of vulnerabilities to third parties.
The issue of cyber disclosure could be a case where less is more to avoid providing a roadmap to cyber terrorists,  additional reputational damage, and  needlessly fueling the plaintiffâs bar. Companies reeling from a cyber attack are least fit to face procyclical affects of further downward pressure on their stock price, credit ratings or other aspects of their financial or physical security from public disclosures that perhaps could be as effective, or more effective, if provided  privately to the SEC and other federal agencies tasked with market protection, analogous to a prudential regulation capacity.
Chair White remarked toward the end of the roundtable, âWhat you worry about is ârational thinkingâ that may not lead to meaningful investor disclosure.â
âGuidance for disclosure by critical infrastructure companies would be helpful,â said Washington Gas & Light's Thornton.
However, SIFMA's Schimmick warned, âThink through cost-benefit;Â Are you putting a sector at greater risk by putting [a new]Â regulation into place?â
Roberta Karmel, a former SEC commissioner and currently a professor at Brooklyn Law School, stated during the roundtable, âThis may be an area where more disclosure is not in the public interest.â
She added, âI have a resistance to the idea that when a matter becomes an important matter of public policy, the SEC should be tasked with doing it.â
Following the roundtable, we caught up with Karmel for any additional comments, and we appreciate her taking the time to share this additional overall observation:
The SEC's primary cybersecurity mission should be to monitor and assist security infrastructure institutions and broker dealers and investment advisors to safeguard the integrity of their systems--the subject of the two afternoon panels. Requiring more disclosure by public companies beyond a materiality standard could be more informative to hackers than investors. In some cases national security concerns could be implicated. So the commission needs to be very careful in crafting any new disclosure requirements.
Whatâs Next?
âWeâre working with the other agencies in the financial services group to implement the new NIST framework," SEC spokesman John Nester said. As to plans for post-roundtable action, he said, "staff are continuing to consider the issues raised.â