Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Judge Engelmayer: Securities Law Requiring “Internal Accounting Controls” Does Not Reach Cybersecurity Deficiencies

By Charles Michael on July 23, 2024
Email this postTweet this postLike this postShare this post on LinkedIn

In an opinion last week, Judge Engelmayer dismissed most of the SEC’s fraud claims against the software company SolarWinds over the so-called “SUNBURST” cyberattack in 2020 that is generally attributed to state-sponsored Russian hackers.

Judge Engelmayer allowed the SEC’s claims to proceed as to certain pre-SUNBURST statements on SolarWinds’ website touting its cybersecurity practices, but dismissed the SEC’s claims based on statements the company made after the fact, finding that those claims “impermissibly rel[ied] on hindsight and speculation.” For example, a Form 8-K filed after the attack allegedly left out certain details about the extent of the harm, but Judge Engelmayer noted that “perspective and context are critical,” including that the filing was made as the facts were evolving and that, overall, the Form 8-K “by any measure bluntly reported brutally bad news for SolarWinds.”

Judge Engelmayer rejected a novel theory advanced by the SEC that SolarWinds’ cybersecurity failures violated a provision of the Securities Exchange Act requiring issuers to maintain “internal account controls sufficient” to prevent unauthorized “access to assets,” finding that the language concerned “financial accounting,” not cybersecurity:

In various respects, the text of the statute strongly supports that the term “system of internal accounting controls” . . . refers to a company’s financial accounting. The term “accounting” is widely defined in this manner-for example, as “the system of recording and summarizing business and financial transactions and analyzing, verifying, and reporting the results.” Accounting, Merriam-Webster Dictionary, https://www.merriam-webster.com/dictionary/accounting (emphasis added). The SEC has not identified any dictionary definition favoring its construction.

[T]here is no evidence . . .  that Congress intended its reference to “a system of internal accounting controls” to reach cybersecurity controls. That is no surprise. The statute was enacted in 1977 — long before cybersecurity became a relevant concept in business or society.

Photo of Charles Michael Charles Michael

Charles Michael is an accomplished commercial litigator who resolutely defends clients in high stakes disputes and arbitrations. He is also experienced in regulatory and criminal investigations, and represents clients under investigation by the Securities and Exchange Commission (SEC), the Financial Industry Regulatory Authority…

Charles Michael is an accomplished commercial litigator who resolutely defends clients in high stakes disputes and arbitrations. He is also experienced in regulatory and criminal investigations, and represents clients under investigation by the Securities and Exchange Commission (SEC), the Financial Industry Regulatory Authority (FINRA), the Commodity Futures Trading Commission (CFTC), and the Department of Justice (DOJ).

Read more about Charles MichaelEmail
Show more Show less
  • Posted in:
    Business and Commercial, Privacy and Cybersecurity
  • Blog:
    SDNY Blog
  • Organization:
    Steptoe LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo