Senators call on SEC to mandate more breach reporting

Share this article:

Prompted by recent breaches of intellectual property belonging to U.S. corporations, federal lawmakers want the Securities and Exchange Commission (SEC) to clarify guidance around the obligation to publicly disclose these incidents to shareholders.

In a Wednesday letter to SEC Chairwoman Mary Schapiro, five senators said existing securities regulations require publicly traded businesses to reveal any "material network breach." That includes incidents leading to the loss of sensitive data, such as intellectual property and trade secrets, which could be used by adversaries to gain a competitive advantage, impact earnings or shrink market share.

Judy Burns, an SEC spokeswoman, said the agency hasn't specifically issued guidance related to breaches, but such incidents likely are covered under securities laws from the 1930s.

"If something is material to investors then they have to disclose it," she told "If it's a big enough that the shareholders care about it and need to know about it, then you have to disclose it."

But many organizations fail to report data compromises to investors, particularly those involving corporate espionage, according to the five lawmakers who signed the letter. They are members of the Senate Committee on Commerce, Science and Transportation.

"Our review of recent corporate disclosures suggests that material breach reporting, like information risk, is inconsistent and unreliable," the letter said. "We are concerned that the lack of quality, public information in these matters enables an inefficient marketplace that devalues security and impairs investor decision-making."

But John Pescatore, vice president and research fellow at Gartner, said issuing new guidance will result in more paperwork, not necessarily better security or investor insight.

"Trying to say we want specific guidance on a specific type of risk usually results in more reporting burdens," Pescatore said. "We already have [SEC] disclosure requirements. Material impact is material impact. Risk is risk."

Burns said the agency likely will respond to Sen. Jay Rockefeller, D-W.Va., who heads the Commerce Committee.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters


More in News

Information sharing requires breaking down barriers, White House cyber guru says

Information sharing requires breaking down barriers, White House ...

The White House has advanced an agenda to promote and facilitate information sharing on security threats and vulnerabilities.

Worm variant of Android ransomware, Koler, spreads via SMS

Worm variant of Android ransomware, Koler, spreads via ...

Upon infection, the Koler variant will send an SMS message to all contacts in the device's address book.

Patch for Windows flaw can be bypassed, prompts temporary fix from Microsoft

Patch for Windows flaw can be bypassed, prompts ...

The Windows zero-day received a patch last week, but the fix can still be bypassed by crafty attackers.