Tag: Cybersecurity

Cybersecurity Breach

SEC Charges Four Companies With Misleading Cyber Disclosures

T he Securities and Exchange Commission has charged four public companies with making materially misleading disclosures regarding cybersecurity risks and intrusions. The charges against the four companies—Unisys, Avaya, Check Point Software, and Mimecast—result from an investigation involving public companies impacted by the compromise of SolarWinds’ Orion software. The SEC also Read More

Hornet FA 18 Fighter Jet

DoD Finalizes Cybersecurity Certification Program for Contractors

T he U.S. Department of Defense issued final rules for its Cybersecurity Maturity Model Certification (CMMC) Program, which is indented to ensure that defense contractors meet standards for safeguarding sensitive information. The CMMC Program aligns with the DoD’s existing information security requirements for private sector defense contractors. It is designed Read More

SEC Cyber Reporting

Equiniti Trust Penalized by SEC for Failing to Protect Client Assets from Cyber Theft

The Securities and Exchange Commission announced that it settled charges against New York-based registered transfer agent Equiniti Trust Company LLC, , for failing to assure that client securities and funds were protected against theft or misuse. Those failures led to the loss of more than $6.6 million of client funds Read More

AT&T logo in park

AT&T Sued for Failing to Protect Customer Data in Cybersecurity Breach

After having nearly all of its customers’ records breached, AT&T is facing a class action lawsuit alleging that the cellular company failed to implement adequate cybersecurity procedures and protocols. The class action is taking place in Texas, Montana and New Jersey federal courts. The lawsuit arises out of an incident Read More

SEC Cyber Reporting

SEC’s Cyber-Rule Enforcement a Prime Worry for Compliance

According to a 2024 Cybersecurity Benchmarking Survey, 45 percent of surveyed compliance personnel from asset management, investment adviser and private market firms have expressed concerns about how the Securities and Exchange Commission (SEC) will enforce its newly developed cybersecurity rules.  The ACA Group and National Society of Compliance Professionals released Read More

CafePress_data_security

HHS Reaches First Settlement with Health Care Firm Involved in Ransomware Attack

The U.S. Department of Health and Human Services announced a $100,000 settlement with Doctors’ Management Services for failures to determine the potential risks and vulnerabilities to electronic protected health information after a cyberattack exposed the information of more than 200,000 patients. It is notable in that it is the first Read More

SolarWinds

SEC Charges SolarWinds and Its CISO with Fraud, Control Failures

The Securities and Exchange Commission announced charges against Austin, Texas-based software company SolarWinds and its chief information security officer, Timothy G. Brown, for fraud and internal control failures relating to allegedly known cybersecurity risks and vulnerabilities. The complaint alleges that, from at least its October 2018 initial public offering through Read More

patient data breaches on the rise

Health Care Patient Data Breaches Doubled in 2023, Reaching 87M

Health care companies are increasingly falling victim to sophisticated hacking efforts—including ransomware attacks—insider threats, and basic security flaws despite the highly confidential nature of patient data. According to new research by Atlas VPN, a virtual private network provider, 87 million patients in the United States had their personal information improperly Read More

ChatGPT comes with risks every compliance officer should know about

Six Risks from ChatGPT that Compliance Leaders Should Know About

Artificial intelligence applications like ChatGPT are becoming common tools in the workplace to do everything from generating job descriptions, writing and editing reports, and to managing schedules (See related article, “How Employees Are Using ChatGPT on the Job“). But the apps aren’t perfect. In fact, they can be error prone Read More

SolarWinds Gets SEC ‘Wells Notice’ over Orion Software Platform Cyberattack

SolarWinds disclosed in a press release accompanying a recent regulatory filing that the Securities and Exchange Commission has issued it a “Wells Notice” concerning an investigation into SolarWind’s previously disclosed cyberattack on the company’s Orion Software Platform and internal systems. “The Wells Notice states that the SEC staff has made Read More