SEC Cybersecurity Enforcement Action Underscores Why Cybersecurity Whistleblower Disclosures Should be Protected under SOX

 

There is mixed authority on whether the Sarbanes-Oxley whistleblower protection law protects disclosures about inadequate cybersecurity. Last year, in an unpublished decision, the Third Circuit held that SOX does not protect disclosures about information security vulnerabilities. In that case, the employee identified and pressed for the resolution of concerns about access authorization and server stability. At trial, he argued that he reasonably believed those concerns evidenced an undisclosed material weakness in internal controls and could have led to inaccurate financial reporting, in violation of SEC rules. The court disagreed, reasoning that the employee’s disclosures did not relate to any of the enumerated laws within the ambit of Sarbanes-Oxley Act protected conduct.

Some cybersecurity whistleblowers, however, have fared better in persuading judges that SOX protects whistleblowing about deficient information security controls. See, e.g.Prioleau v. Sikorsky Aircraft Corp., ARB Case No. 10-060 (ARB Nov. 9, 2011) (holding that disclosures about deficient information security are protected under SOX).

The SEC’s recent enforcement against Pearson plc, for misleading investors about a cyber-intrusion and for failing to maintain adequate disclosure controls and procedures suggests that whistleblowing about cybersecurity at a public company implicates violations of SEC rules and therefore should be deemed protected conduct under SOX.

Pearson Cybersecurity Enforcement Action

The SEC took enforcement action against Pearson, a London-based public company that provides educational publishing and other services to schools and universities, primarily because it made misleading statements and omissions about a 2018 data breach caused by a vulnerability on a server that permitted a sophisticated cyberthreat actor to steal student personal data and other sensitive information, including usernames and passwords. Although the server’s software manufacturer identified a significant vulnerability in September 2018 and informed Pearson of a patch for the vulnerability that same month, Pearson did not implement the patch until March 2019, after Pearson discovered the data breach. Pearson chose not to make a public statement about the breach, and in its July 2019 semi-annual report discussed a data privacy attack as a hypothetical risk, falsely implying that a data breach had not yet occurred.

The breach was material in that Pearson’s business entailed the collection and storage of large quantities of private data on school-age children and as it acknowledged in its risk disclosures, Pearson’s reputation and ability to attract and retain revenue depended in part on its ability “to adequately protect personally identifiable information.” This breach involved a compromise of a server holding a large quantity of data Pearson was responsible for protecting and exfiltration of a significant number of student names, dates of birth, and email addresses, and school administrator login credentials.

Pearson disclosed the breach to investors only after it was contacted by the media, and when it disclosed the breach in July 2019, Pearson made misstatements about the nature of the breach and the type of data involved.  It failed to disclose the fact that student data, usernames, and passwords had been stolen.

The SEC also took enforcement action against Pearson due to the company’s insufficient disclosure controls and procedures.  For example, although protecting student and user data is critical to Pearson’s business, and Pearson had identified the potential for improper access to such data as a significant risk, it failed to make appropriate disclosures in its July 2019 Form 6-K Risk Factor disclosures and its July 31, 2019 media statement.

In a press release, Kristina Littman, Chief of the SEC Enforcement Division’s Cyber Unit stated that “[a]s public companies face the growing threat of cyber intrusions, they must provide accurate information to investors about material cyber incidents.”

Pearson’s Violations of SEC Rules

The order settling the SEC’s charges against Pearson identifies three violations of securities law:

Whistleblower disclosures about inadequate information security can also implicate the following SEC rules:

Implications for Cybersecurity Whistleblowers

As inadequate cybersecurity and attempts to conceal data breaches harm shareholders at public companies, it is critical to protect cybersecurity whistleblowers against retaliation.  Although there are decisions denying SOX whistleblower protection to cybersecurity whistleblowers, the enforcement action against Pearson illustrates how cybersecurity disclosures implicate potential violations of SEC rules and why such disclosures should be deemed SOX-protected conduct.

Cybersecurity Whistleblower Protections

Cybersecurity Whistleblower Law Firm’s Guide for Cybersecurity and Data Privacy Whistleblowers

SEC Whistleblower Rewards for Whistleblowing About Cybersecurity or Data Privacy

Cybersecurity Whistleblower Attorneys

Our experienced cybersecurity whistleblower lawyers have represented Chief Information Security Officers, CIOs, and other cybersecurity professionals in cybersecurity whistleblower rewards and protections matters.

We are well versed in the cybersecurity issues that may qualify for an SEC whistleblower reward or for protection under the whistleblower protection provision of the Sarbanes-Oxley Act.  Recently the Wall Street Journal quoted Dallas Hammer, the head of our cybersecurity whistleblower practice, in an article titled Cybersecurity Whistleblowers Are Growing Corporate Challenge.

See our leading guide to cybersecurity whistleblower rewards and protections: Practitioners Guide to Cybersecurity Whistleblowing.

To find out more about the rights of cybersecurity whistleblowers, call us at 202-262-8959 for a free, confidential consultation and download our Practitioner’s Guide to Cybersecurity Whistleblowing.

Uncategorized
Tags: cybersecurity whistleblower bountycybersecurity whistleblower lawyersCybersecurity Whistleblower Protections for Employees of Federal Contractors and Granteesdata privacy whistleblower protectiondata privacy whistleblowinglaws protecting cybersecurity whistleblowinglawyer representing cybersecurity whistleblowersSarbanes-Oxley protected conductSOX protection for cybersecurity whistleblowers