Recent enforcement actions, proposed rule-making and increased staffing reflect the SEC Enforcement Division’s expanding focus on cybersecurity incidents and corresponding disclosures. While the Enforcement Division has historically focused its resources in this area on highlighting failures to disclose internal control deficiencies, the Division is beginning to cast a wider net in its investigations and enforcement actions.

In this article we discuss likely areas for continued expansion of cyber-related enforcement activity and practical implications for public companies. The SEC has also proposed new cybersecurity rules for investment advisers registered under the Investment Advisers Act of 1940 and investment companies registered under the Investment Company Act of 1940. See 17 CFR Parts 230, 232, 239, 270, 274, 275, and 279.

This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.

To view this content, please continue to their sites.

Not a Lexis Subscriber?
Subscribe Now

Not a Bloomberg Law Subscriber?
Subscribe Now

Why am I seeing this?

LexisNexis® and Bloomberg Law are third party online distributors of the broad collection of current and archived versions of ALM's legal news publications. LexisNexis® and Bloomberg Law customers are able to access and use ALM's content, including content from the National Law Journal, The American Lawyer, Legaltech News, The New York Law Journal, and Corporate Counsel, as well as other sources of legal information.

For questions call 1-877-256-2472 or contact us at [email protected]