Senators call on SEC to mandate more breach reporting

Share this article:

Prompted by recent breaches of intellectual property belonging to U.S. corporations, federal lawmakers want the Securities and Exchange Commission (SEC) to clarify guidance around the obligation to publicly disclose these incidents to shareholders.

In a Wednesday letter to SEC Chairwoman Mary Schapiro, five senators said existing securities regulations require publicly traded businesses to reveal any "material network breach." That includes incidents leading to the loss of sensitive data, such as intellectual property and trade secrets, which could be used by adversaries to gain a competitive advantage, impact earnings or shrink market share.

Judy Burns, an SEC spokeswoman, said the agency hasn't specifically issued guidance related to breaches, but such incidents likely are covered under securities laws from the 1930s.

"If something is material to investors then they have to disclose it," she told SCMagazineUS.com. "If it's a big enough that the shareholders care about it and need to know about it, then you have to disclose it."

But many organizations fail to report data compromises to investors, particularly those involving corporate espionage, according to the five lawmakers who signed the letter. They are members of the Senate Committee on Commerce, Science and Transportation.

"Our review of recent corporate disclosures suggests that material breach reporting, like information risk, is inconsistent and unreliable," the letter said. "We are concerned that the lack of quality, public information in these matters enables an inefficient marketplace that devalues security and impairs investor decision-making."

But John Pescatore, vice president and research fellow at Gartner, said issuing new guidance will result in more paperwork, not necessarily better security or investor insight.

"Trying to say we want specific guidance on a specific type of risk usually results in more reporting burdens," Pescatore said. "We already have [SEC] disclosure requirements. Material impact is material impact. Risk is risk."

Burns said the agency likely will respond to Sen. Jay Rockefeller, D-W.Va., who heads the Commerce Committee.

Share this article:

Sign up to our newsletters

More in News

Research shows vulnerabilities go unfixed longer in ASP

Research shows vulnerabilities go unfixed longer in ASP

A new report finds little difference in the number of vulnerabilities among programming languages, but remediation times vary widely.

Bill would restrict Calif. retailers from storing certain payment data

The bill would ban businesses from storing sensitive payment data, for any long than required, even if it is encrypted.

Amplification, reflection DDoS attacks increase 35 percent in Q1 2014

Amplification, reflection DDoS attacks increase 35 percent in ...

The Q1 2014 Global DDoS Attack Report reveals that amplification and reflection distributed denial-of-service attacks are on the rise.