
insta_photos // Shutterstock
1 / 3The wide-ranging impact of a breach
Cybersecurity breaches can affect businesses, their investors, and, of course, the privacy and security of consumers, who are often embroiled in cybercrimes whether they know it or not. A 2022 survey of 1,000 American adults by cybersecurity company Varonis found that over 3 in 5 Americans (64%) had never checked to see whether they'd been affected by a data breach.
One University of Maryland study found that cyberbreaches occur nearly constantly—every 39 seconds, on average. They're expensive to deal with too.
The average data breach costs a company $4.9 million in either lost business, ransom payment, or cleanup and mitigation, according to IBM's Cost of a Data Breach report for 2024. Too often, they aren't disclosed to the public, despite their potential for harm. Security software provider Arctic Wolf's 2023 annual report found that 7 in 10 companies (72%) that experienced a data breach did not disclose it.
The complexity of the 2019 breach, the time it took to identify, and the vulnerability it created for federal government agencies, including the Department of Homeland Security, only increased the pressure on officials to enforce existing regulations in court.
The SEC filed charges against SolarWinds and its chief information security officer, Timothy G. Brown, and several of the companies involved in its 2019 cyberbreach, applying those new rules to American companies for the first time. The case against SolarWinds alleged it misled investors about its cybersecurity practices in the years leading up to the attack.
In a statement accompanying the announcement of the new rules in early 2023, SEC chair Gary Gensler likened data breaches at publicly traded companies to a fire at a company-owned facility, arguing that these occurrences are consequential to investors and other stakeholders and thus deserve to be shared transparently through SEC filings.
"Through helping to ensure that companies disclose material cybersecurity information, today's rules will benefit investors, companies, and the markets connecting them," Gensler said.
Partners working in international law firm Holland & Knight's cybersecurity practice dubbed the charges against SolarWinds a "landmark" case that would test the SEC's power to impose rules that would "likely create significant compliance challenges as well as litigation and enforcement risks for public companies."
Although four of the charged companies settled with the agency, most filed by the SEC against SolarWinds and its executive under its new rules were dismissed in July, dealing a blow to the agency's ability to regulate corporate cybersecurity transparency, according to legal experts. It's just one of several instances in the Biden administration where federal regulators have been stymied by courts in their attempts to expand their authority over major corporations.










