Biden will veto attempts to kill off SEC's security breach reporting rules
- Reference: 1706807707
- News link: https://www.theregister.co.uk/2024/02/01/senate_resolution_to_undo_sec/
- Source link:
In a policy [1]statement [PDF] published yesterday by Biden's Office of Management and Budget (OMB), the administration said it "strongly opposes" Senate Joint Resolution [2]50 , introduced in November by Senator Thom Tillis (R-NC). The joint resolution, along with House Joint Resolution [3]100 , sponsored by Representative Andrew Garbarino (R-NY) and introduced the same day, would nullify the SEC rules [4]adopted in July of last year.
The SEC's rule require public companies hit by cybercriminals to report the incident within four days. Given that the SEC's primary concern is protecting investors, the body is mostly concerned with breaches that could have a "material" effect on a company's bottom line, and thus present a risk to shareholders.
[5]
"The lack of transparency by public companies about cyber incidents impacting their operations and data is fueling increasing cyberattacks across all sectors and all industries," the Biden OMB said in its objection to the Senate bill. "Greater transparency about cyber incidents, as required in the SEC's rule, will incentivize corporate executives to invest in cybersecurity and cyber risk management."
[6]
[7]
"If the president were presented with S.J. Res. 50, he would veto it," OMB said.
Undoing any breach reporting requirement seems antithetical to the work a Senator ought to be doing; we asked Tillis's office to explain his reasoning, but didn't hear back.
[8]
Garbarino, on the other hand, issued a [9]statement in November after submitting his companion resolution in the House that makes his position on the matter clear: Breach reporting requirements are the Cybersecurity and Infrastructure Security Agency's (CISA) job.
"This cybersecurity disclosure rule is a complete overreach on the part of the SEC and one that is in direct conflict with congressional intent," Garbarino said in the November release. "CISA, as the lead civilian cybersecurity agency, has been tasked with developing and issuing regulations for cyber incident reporting as it relates to covered entities."
Garbarino said Congress and the Biden administration are on the same page with regards to harmonizing cybersecurity reporting requirements (though that doesn't appear to be the case based on the OMB policy statement). He also said the SEC was simply creating duplicative requirements that "further burden an understaffed cybersecurity workforce with additional and unnecessary reporting requirements."
[10]
Part of those concerns may stem from the public nature of SEC incident reports, which have to be [11]submitted on SEC Form 8-K, the contents of which are public. Disclosures must include the scope, timing, and nature of the incident, though disclosure may be delayed if the US Attorney General determines doing so would pose a risk to national security or public safety.
Tillis, in a brief comment on Garbarino's release, only described the SEC's reporting rule as Commission chair Gary Gensler doing his best "to hurt market participants by overregulating firms into oblivion," with an onerous rule "that creates unrealistic timelines and unnecessary red tape that will ultimately make markets less safe overall."
[12]SolarWinds slams SEC lawsuit against it as 'unprecedented' victim blaming
[13]Future of America's Cyber Safety Review Board hangs in balance amid calls for rethink
[14]Regulator, insurers and customers all coming for Progress after MOVEit breach
[15]US State Dept has no idea if its IT security actually works, say auditors
It's not clear what the Senator and Congressman think of the Federal Trade Commission's (FTC) 30-day breach reporting requirement [16]passed in October, which isn't mentioned in the earlier statement or resolutions.
Someone has to do something
Despite Garbarino's professed belief that CISA is the one that should be handling breach reporting requirements, the agency has yet to pass any rules that would do so.
President Biden signed the Cyber Incident Reporting for Critical Infrastructure Act ( [17]CIRCIA ) into law in March 2022, but CISA had 24 months from passage (March 2024) to present a rule for consideration, which it has yet to do. When CISA's reporting requirements eventually go into effect, the disclosure window will be even smaller than the SEC's. CIRCIA asked CISA to give cybersecurity incident victims a mere 72 hours – three days – to report a breach.
In the meantime, the FTC and SEC have taken matters into their own hands, which appears to be helping – we've even been able to [18]report on breaches at companies like HPE thanks to SEC reports.
As previously [19]reported , the number of victims paying ransomware operators has fallen to 29 percent. The company behind that statistic, ransomware negotiation firm Coveware, attributes much of the decrease in ransom payments in recent months to reporting requirements from the SEC and FTC.
Those payments are down despite what the White House OMB said was a 45 percent increase in ransomware attacks year-over-year.
"Reversing the SEC's rulemaking would not only disadvantage investors … but would also cause companies to undervalue investments in cyber programs to the detriment of our economic and national security," the OMB said.
Then again, maybe giving the SEC cybersecurity reporting authority isn't the best move – after all, the agency [20]can't even keep its Twitter account secure. ®
Get our [21]Tech Resources
[1] https://www.whitehouse.gov/wp-content/uploads/2024/01/SAP-SJRes-50.pdf
[2] https://www.congress.gov/bill/118th-congress/senate-joint-resolution/50
[3] https://www.congress.gov/bill/118th-congress/house-joint-resolution/100/text
[4] https://www.theregister.com/2023/07/26/sec_reporting_security/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZbwioBmsAApIVysfyA@SwAAAAZM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbwioBmsAApIVysfyA@SwAAAAZM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbwioBmsAApIVysfyA@SwAAAAZM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbwioBmsAApIVysfyA@SwAAAAZM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://garbarino.house.gov/media/press-releases/garbarino-tillis-introduce-joint-resolution-disapproval-overreaching-sec-rule
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbwioBmsAApIVysfyA@SwAAAAZM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.sec.gov/news/press-release/2023-139
[12] https://www.theregister.com/2024/01/29/solarwinds_sec_lawsuit/
[13] https://www.theregister.com/2024/01/18/cyber_safety_review_board_rethink/
[14] https://www.theregister.com/2023/10/16/infosec_in_brief/
[15] https://www.theregister.com/2023/10/02/us_state_security_gao/
[16] https://www.theregister.com/2023/10/31/ftc_30_day_breach_disclosure/
[17] https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia
[18] https://www.theregister.com/2024/01/25/hpe_russia_email_attack/
[19] https://www.theregister.com/2024/01/31/ransomware_payment_rates_drop/
[20] https://www.theregister.com/2024/01/09/sec_bitcoin_etf_hacked/
[21] https://whitepapers.theregister.com/
Re: Veto he should -- and must
When the tougher CISA rules are up and running, the SEC rule can be lifted.
So what's the problem if an established organization can provide some interim protection for the shareholders it represents? Especially if it has the side-effect of protecting others, such as customers personal data.
Mall cops may not be "real" cops, but they serve a purpose.
Re: Veto he should -- and must
So what's the problem
Laws are all about dotting your "t's" and crossing your "i's".
It doesn't matter how reasonable and common-sense something might be, if the law doesn't specifically say you're allowed to breathe, then you're going to get slapped by the court for breathing...
The one that always bothered me is the term "broadband" in the US Fed is legally defined as bandwidth of 25Mbps download speeds. So your baseband ethernet network at home is legally broadband, while slower 5Mbps DSL service (which is a broadband signal/service) is legally not "broadband." It's like they updated the definition of a "horse" to include cars, and exclude horses...
Where is Biden's compassion? Four days isn't nearly enough time to discretely leak the information to insiders or set up short calls.
Республиканцы
Republican party is a Russian asset. They are set to destroy America from within and enrich themselves in the process. They want to become oligarchs like their Russian friends. They use divisive politics and mistakes of Democrats to take disillusioned Americans on their side. People who are struggling are easy to manipulate.
Though its interesting that somewhat well equipped security services (or at least that is the image being projected) can't or fail to see that. Maybe it's not the right time to pounce.
Re: Республиканцы
I think you are ascribing malice to sheer dumbassery.
Living in semi-rural Florida is a huge eye opener to how illiterate and uneducated people actually are.
Living in Orlando, London, or Silicon Valley gives one an image of people are are far above the norm, and nobody realizes just how low average intelligence is.
These people couldn't organize a piss-up in a brewery to save their lives.
Re: Республиканцы
I don't think the voters have malicious intent. As I wrote it's easy to manipulate disillusioned masses, tell them what they want to hear and give them "solutions" that their mind wouldn't be able to critically assess.
The Республиканцы may appear dumb, but they certainly aren't (it's a classic act for some politicians - see our Boris). It may be that they decided they live in gated communities anyway, separated from the "pleb", they have security, so why not give in to the enemy for some extra benefits and be shielded from any fallout? Seems like a no-brainer. That, and if Russian services have kompromats and skilled agents able to resolve any doubts I can see how easy they can go with that. They personally may not even mean malice, just become convinced that this is the way and their own ego vanity would cloud their judgment.
Re: Республиканцы
For anyone that has not had to deal with these audits.
Here just a few:
Insurance audit
Required pin testing
Federal audits
State audits
Internal audits
And here is the kicker - Sarbanes–Oxley Act
That one is directly applied to the requirement and use the SEC wants.
The government bureaucracy is so behind on the technology that their audit process does nothing to ensure you are protected. I am with California and Europe on better disclose this or it is open season for the law suits. Triple damages.
Let’s take the open border issue. The Biden administration has stated that they will consider enforcing the law if congress will provide more money to Ukraine to kill more people. Won’t matter what the law is passed if it is not enforced. Even when they take have taken oath to do so.
(By the way, there is no law that police, lawyers and politicians will be held accountable for lying, although there is one if you lie to them)
Blaming it on Democratic or Republican is an easy way out of the responsibility of determining what a$$ is doing this to us and voting them out.
Till then IT guys will always be the fall guy.
Re: Республиканцы
Republican party is a Russian asset. They are set to destroy America from within and enrich themselves in the process.
"No" to the first, "Yes" to the second.
Republicans (other than Trump) don't like Putin. Putin likes the Republicans because they're trying to destroy America. Republicans are right on the edge of being a non-viable national party, so they'll quietly accept Putin's help in any form that helps them win elections they might otherwise have lost.
Fine...
Change to the rule toe dry single persons details that get leaked due to poor security results in 1 hours prison for both the CEO AND the CFO.
1.5 million hours in the pokey should focus the mind a little.
Re: Fine...
and cue corporations scramble around sites frequented by homeless people to see if they can make figurehead CEOs and CFOs.
Veto he should -- and must
Bitch and moan about "Grandpa Joe" all you want, but this is truly the right thing to do.
And shame on those fatass Republicons for even sponsoring such a piece of ... work.
Undoing any breach reporting requirement seems antithetical to the work a Senator ought to be doing; we asked Tillis's office to explain his reasoning, but didn't hear back.
And likely you won't. But if you were to hear back, and if somehow the good Senator were to by some miracle (or chemical inducement) to tell the truth, the statement might include something along the lines of, "Well, my handlers/sponsors/patrons/leash-holders don't like this because it exposes how shit their security practices are, and exposes the lie that the canned statement 'our customers' security is important to us' really is. After all, if our corporate owners -- er, donors were to actually have to invest in proper security, well, they might not have quite as profitable a quarter, and this would materially affect their bonuses, and we can't have that, now can we?"