Senators call on SEC to mandate more breach reporting

Share this article:

Prompted by recent breaches of intellectual property belonging to U.S. corporations, federal lawmakers want the Securities and Exchange Commission (SEC) to clarify guidance around the obligation to publicly disclose these incidents to shareholders.

In a Wednesday letter to SEC Chairwoman Mary Schapiro, five senators said existing securities regulations require publicly traded businesses to reveal any "material network breach." That includes incidents leading to the loss of sensitive data, such as intellectual property and trade secrets, which could be used by adversaries to gain a competitive advantage, impact earnings or shrink market share.

Judy Burns, an SEC spokeswoman, said the agency hasn't specifically issued guidance related to breaches, but such incidents likely are covered under securities laws from the 1930s.

"If something is material to investors then they have to disclose it," she told SCMagazineUS.com. "If it's a big enough that the shareholders care about it and need to know about it, then you have to disclose it."

But many organizations fail to report data compromises to investors, particularly those involving corporate espionage, according to the five lawmakers who signed the letter. They are members of the Senate Committee on Commerce, Science and Transportation.

"Our review of recent corporate disclosures suggests that material breach reporting, like information risk, is inconsistent and unreliable," the letter said. "We are concerned that the lack of quality, public information in these matters enables an inefficient marketplace that devalues security and impairs investor decision-making."

But John Pescatore, vice president and research fellow at Gartner, said issuing new guidance will result in more paperwork, not necessarily better security or investor insight.

"Trying to say we want specific guidance on a specific type of risk usually results in more reporting burdens," Pescatore said. "We already have [SEC] disclosure requirements. Material impact is material impact. Risk is risk."

Burns said the agency likely will respond to Sen. Jay Rockefeller, D-W.Va., who heads the Commerce Committee.

Share this article:

Sign up to our newsletters

More in News

Five schools earn NSA's excellence in cyber ops distinction

The schools earned NSA's Centers for Academic Excellence designation for their cyber offerings.

With RATs at their disposal, 419 scammers target businesses

With RATs at their disposal, 419 scammers target ...

A new report reveals how Nigeria's 419 scammers are spreading malware to pocket business funds.

InfoSec pros worried BYOD ushers in security exploits, survey says

InfoSec pros worried BYOD ushers in security exploits, ...

A study by the Information Security Community on LinkedIn found most organizations don't have proper polices and support for BYOD.