Cybersecurity threats are an unavoidable challenge in the modern age, one that no one — be they Government agencies, companies or individuals — can ignore. Many federal agencies have put a concerted effort into creating and enforcing cybersecurity regulations. This includes the Securities and Exchange Commission (“SEC”) despite numerous setbacks to its efforts in the past couple of years.
Cyberattacks have only increased over the years in both frequency and severity, leaving both companies and their investors concerned. These incidents can affect a company’s future cash flows as well as investor returns. If a company’s networks are breached due to subpar cybersecurity, they may also face reputational harm and a costly lawsuit.
Among other priorities, the SEC is dedicated to protecting investors and encouraging the disclosure of important market information — which includes disclosures on how a company’s cybersecurity systems may impact investments. The agency has long had various rules related to cybersecurity, but the rules were disjointed and inconsistently applied across industries.
That is, until the SEC adopted a new set of standards for cybersecurity risk management, strategy, governance, and incident disclosure in July of 2023. (See 17 CFR §§ 229, 232, 239, 240, & 249.) The SEC’s attempts to enforce or expand upon its 2023 rules have not been entirely successful, but the rules nonetheless apply to any public company that is subject to the Securities Exchange Act of 1934 and its reporting requirements.
The SEC’s Rules for Cybersecurity
The SEC’s 2023 rules — fully laid out in this release and briefly summarized in the SEC’s accompanying fact sheet — imposes a baseline standard for cybersecurity incident reporting.
The rules require public companies to:
- Promptly disclose material cybersecurity incidents within four days of discovery,
- Provide annual disclosures regarding their cybersecurity risk management, strategy and governance, and
- Detail their processes for assessing and managing cybersecurity risks, including the oversight roles of management and the board of directors.
Foreign private issuers are also required to make comparable disclosures.
Form 8-K, which was already used to make disclosures to the SEC, was amended to include cybersecurity incidents under Item 1.05. Disclosures must include information regarding the nature, scope, and timing of the cybersecurity incidents. Companies are also required to note any anticipated material impact the incident may have on the company.
As mentioned, cybersecurity incidents have to be disclosed within four business days after the incident was discovered. The only exception to prompt public disclosure is if the U.S. Attorney General determines that doing so would pose a substantial risk to national security or public safety.
The requirement for companies to describe their cybersecurity processes is detailed under Regulation S-K Item 106 in the 2023 rules. This regulation directs public companies to outline their process for identifying and managing cybersecurity risks in their annual reports. Their reports should include a discussion of how cybersecurity incidents have or could affect business strategy, operations, and projected financial performance. Altogether, the reported information can help investors make informed investment decisions.
Enforcement Challenges and Developments
Since the inception of its 2023 rules, the SEC has attempted to double down on its enforcement. However, the agency’s efforts have been met with resistance.
Only one major lawsuit has been pursued under the 2023 rules thus far. The SolarWinds case involved a highly publicized cyberattack in 2020 that compromised several federal networks. The attack prompted the U.S. Government to focus more on cybersecurity and lead the SEC to file a lawsuit against SolarWinds. The lawsuit alleged that the company overstated its cybersecurity practices, failed to disclose known vulnerabilities, and, as a result, misled its investors. However, the majority of the SEC’s claims were dismissed in July 2024, and the Government ultimately abandoned its pursuit of the case in November 2025.
Under the Biden Administration, the SEC pushed to expand the 2023 requirements and related regulations but didn’t have much success. A court decision issued in June 2024 vacated the SEC’s Private Fund Advisor Rule, which underlies many of the SEC’s proposed regulatory actions. The court determined that the SEC had exceeded its statutory authority.
And, in June 2025, the SEC withdrew 14 additional proposed cyber rules, including several proposals involving investment companies and advisers. The SEC indicated that it would not proceed with the proposed rules.
Under the Trump Administration, the SEC has now recalibrated its enforcement priorities to focus on “fraudulent disclosure” related to cybersecurity incidents, rather than disclosure deficiencies. This change does narrow potential enforcement actions, but companies shouldn’t get too excited.
Both federal and state regulators have heightened their scrutiny of cybersecurity disclosures, and any shortcomings in the preparation or issuance of required disclosures may expose companies to costly investigations and significant repercussions. As a result, careful drafting and thorough vetting of all cybersecurity disclosures remain essential.
This alert marks the conclusion of the “Navigating DOJ Cybersecurity Enforcement” series, through which Leech Tishman addressed the DOJ’s Cybersecurity Fraud Enforcement program, compliance obligations, impacted industries, and applicable regulatory requirements. View previous alerts:
Part 1: Navigating DOJ Cybersecurity Enforcement: FCA Risks and Updated Regulatory Compliance
Part 2: Navigating DOJ Cybersecurity Enforcement: Lessons from the SolarWinds Attack
Part 3: Navigating DOJ Cybersecurity Enforcement: Common Violations & How Companies Can Mitigate Risk
Part 4: Navigating DOJ Cybersecurity Enforcement: A Foundation for Best Practices with the NIST Framework
Part 5: Navigating DOJ Cybersecurity Enforcement: Regulations for Government Contractors (FARS/DFARS)
Part 6: Navigating DOJ Cybersecurity Enforcement: The CMMC Program for Defense Contractors
Part 7: Navigating DOJ Cybersecurity Enforcement: The SEC’s Efforts to Regulate and Enforce
Leech Tishman’s Labor & Employment attorneys regularly counsel clients on compliance with statutory and common law requirements. Our team is prepared to assist your company in understanding and implementing the obligations and compliance measures required under the DOJ’s Cybersecurity Fraud Enforcement program. For assistance or additional information, please contact Lydia A. Pappas at lpappas@leechtishman.com, attorney in Leech Tishman’s Labor & Employment Practice Group.