Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • $2.5M age discrimination award against AutoNation upheld
    • Law firm did not infringe by purchasing rival’s mark as Google Ads keyword
    • Peirce, Uyeda say SolarWinds customer admins are regulation by enforcement
    • Former students allege elite private universities conspired to raise cost of education through financial aid price-fixing scheme
    • Telemedicine prescriptions of controlled substances likely extended into 2025, special registration possible
    • Fisher-Price, Mattel face claims of failure to warn of risks related to infant swings
    • Apple, Goldman Sachs fined more than $89M for mishandling disputes, misleading consumers
    • Appellate court finds definition of ‘oncological protocol’ irrational
    • Dow Jones, New York Post sue Perplexity AI for ‘massive’ illegal copying and trademark harm from ‘hallucinations’
    • EC clears JD Sports acquisition of Courir, fines Czech, Austrian state railways $53 million
    • Former IDF member who alleged discrimination based on Israeli heritage can’t proceed anonymously
    • HHS granted summary judgment in Novartis’ challenge to Drug Price Negotiation Program
    • Kentucky bank, trade groups sue CFPB, Chopra over personal financial data rights rule
    • NHTSA reveals 2025 vehicle lineup for comprehensive safety testing
    • Whistleblowers challenge award denials in CFTC enforcement against ‘off-channel’ communications
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Corporate Counsel Daily, Peirce, Uyeda say SolarWinds customer admins are regulation by enforcement, (Oct 23, 2024)

    By Rodney F. Tonkovic, J.D.

    The Commission is "playing Monday morning quarterback" in using hindsight to second-guess disclosures, Peirce and Uyeda say.

    Commissioners Peirce and Uyeda issued a joint dissent concerning administrative proceedings against customers of SolarWinds. O ...

    By Rodney F. Tonkovic, J.D.

    The Commission is "playing Monday morning quarterback" in using hindsight to second-guess disclosures, Peirce and Uyeda say.

    Commissioners Peirce and Uyeda issued a joint dissent concerning administrative proceedings against customers of SolarWinds. On October 22, 2024, the Commission charged four customers with violations of the securities laws, imposing almost $7 million in total penalties. Peirce and Uyeda argue that the Commission is treating these victims of cyberattacks as perpetrators instead. Insisting in hindsight that immaterial information be disclosed does the opposite of protecting investors, they argue.

    SolarWinds. The 2019-2020 cyberattacks against SolarWinds have been described as one of the most sophisticated hacking campaigns ever. A threat actor inserted malicious code into SolarWinds's Orion software suite that was then spread via software updates to customers. In December 2020, SolarWinds was made aware of the attack and disclosed it in an SEC filing. The Commission brought suit against SolarWinds in October 2023, and the matter is ongoing.

    Administrative proceedings. In settled administrative proceedings, four companies using Orion software were charged with making materially misleading disclosures. The charges stemmed from an SEC investigation into companies impacted by the attack, and the SEC asserted that the companies had downplayed the cybersecurity incidents in their public disclosures.

    Dissent. In their statement, Peirce and Uyeda take the stance that the Commission had donned a "Monday morning quarterback's jersey." The Commission's hindsight review, they say, does not focus on whether the companies’ disclosure provided material information to investors but instead second-guesses that disclosure and cites immaterial, undisclosed details to support the charges. In short, the Commission is regulating by enforcement.

    The dissent goes on to discuss each of the proceedings and the relevant disclosures:

    • Avaya: The Commission highlighted the fact that Avaya did not attribute the cyberattack to a nation-state threat actor. Peirce and Uyeda point out that the Commission's 2023 rulemaking on cybersecurity incident disclosure did not say that the identity of a threat actor (as opposed to the impact of the incident) is material information and that no comments on the rule expressed that view, so it is unlikely that investors consider this information to be material. Plus, by the time Avaya disclosed the incident, Russia's involvement was widely known, so the attribution of the attack would not have altered the total mix of information.

    • Mimecast: The Commission took issue with Mimecast disclosing that encrypted customer credentials had been accessed without providing a percentage or number. As in the Avaya case, this information is "details regarding the incident itself" that do not need to be disclosed. The material disclosure by Mimecast, the dissent says, is that the attack did not result in modifications to the company source code or affect its products, and the Commission did not find this misleading.

    As to Check Point and Unisys, the Commission said that the companies failed to update their cybersecurity risk factors after they had materially changed. For Check Point, the dissent noted that the SolarWinds court had dismissed portions of the Commission's case based on similar disclosures.

    As to Unisys, the dissent says that this case did not need to be brought. "Whether risk factors need to be updated because certain hypothetical risks have materialized is not always a straightforward matter, and the Commission should be judicious in bringing charges in this area," Peirce and Uyeda say, adding that aggressive enforcement may cause companies to fill their risk disclosures with immaterial events.

    Effect on disclosure. The dissent also points out that the Avaya and Mimecast proceedings in particular could shape disclosure provided under new Item 1.05 of Form 8-K, which requires disclosure of "the material aspects of the nature, scope, and timing" of a material cybersecurity incident. To avoid the second-guessing the dissent complains of, companies are likely to fill their disclosures with immaterial details or to disclose under the item about immaterial incidents (a practice already identified as problematic).

    MainStory: TopStory CorporateGovernance CyberPrivacyFeed DataBreach Enforcement ExchangesMarketRegulation FormsFilings FraudManipulation GCNNews InvestorEducation PublicCompanyReportingDisclosure RiskManagement

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use