Egypt partners with Google to promote 'unmatched diversity' tourism campaign    Golf Festival in Cairo to mark Arab Golf Federation's 50th anniversary    Taiwan GDP surges on tech demand    World Bank: Global commodity prices to fall 17% by '26    Germany among EU's priciest labour markets – official data    UNFPA Egypt, Bayer sign agreement to promote reproductive health    Egypt to boost marine protection with new tech partnership    France's harmonised inflation eases slightly in April    Eygpt's El-Sherbiny directs new cities to brace for adverse weather    CBE governor meets Beijing delegation to discuss economic, financial cooperation    Egypt's investment authority GAFI hosts forum with China to link business, innovation leaders    Cabinet approves establishment of national medical tourism council to boost healthcare sector    Egypt's Gypto Pharma, US Dawa Pharmaceuticals sign strategic alliance    Egypt's Foreign Minister calls new Somali counterpart, reaffirms support    "5,000 Years of Civilizational Dialogue" theme for Korea-Egypt 30th anniversary event    Egypt's Al-Sisi, Angola's Lourenço discuss ties, African security in Cairo talks    Egypt's Al-Mashat urges lower borrowing costs, more debt swaps at UN forum    Two new recycling projects launched in Egypt with EGP 1.7bn investment    Egypt's ambassador to Palestine congratulates Al-Sheikh on new senior state role    Egypt pleads before ICJ over Israel's obligations in occupied Palestine    Sudan conflict, bilateral ties dominate talks between Al-Sisi, Al-Burhan in Cairo    Cairo's Madinaty and Katameya Dunes Golf Courses set to host 2025 Pan Arab Golf Championship from May 7-10    Egypt's Ministry of Health launches trachoma elimination campaign in 7 governorates    EHA explores strategic partnership with Türkiye's Modest Group    Between Women Filmmakers' Caravan opens 5th round of Film Consultancy Programme for Arab filmmakers    Fourth Cairo Photo Week set for May, expanding across 14 Downtown locations    Egypt's PM follows up on Julius Nyerere dam project in Tanzania    Ancient military commander's tomb unearthed in Ismailia    Egypt's FM inspects Julius Nyerere Dam project in Tanzania    Egypt's FM praises ties with Tanzania    Egypt to host global celebration for Grand Egyptian Museum opening on July 3    Ancient Egyptian royal tomb unearthed in Sohag    Egypt hosts World Aquatics Open Water Swimming World Cup in Somabay for 3rd consecutive year    Egyptian Minister praises Nile Basin consultations, voices GERD concerns    Paris Olympic gold '24 medals hit record value    A minute of silence for Egyptian sports    Russia says it's in sync with US, China, Pakistan on Taliban    It's a bit frustrating to draw at home: Real Madrid keeper after Villarreal game    Shoukry reviews with Guterres Egypt's efforts to achieve SDGs, promote human rights    Sudan says countries must cooperate on vaccines    Johnson & Johnson: Second shot boosts antibodies and protection against COVID-19    Egypt to tax bloggers, YouTubers    Egypt's FM asserts importance of stability in Libya, holding elections as scheduled    We mustn't lose touch: Muller after Bayern win in Bundesliga    Egypt records 36 new deaths from Covid-19, highest since mid June    Egypt sells $3 bln US-dollar dominated eurobonds    Gamal Hanafy's ceramic exhibition at Gezira Arts Centre is a must go    Italian Institute Director Davide Scalmani presents activities of the Cairo Institute for ITALIANA.IT platform    







Thank you for reporting!
This image will be automatically disabled when it gets reported by several people.



Yahoo hack may become test case for SEC data breach disclosure rules
Published in Amwal Al Ghad on 01 - 10 - 2016

Yahoo's disclosure that hackers stole user data from at least 500 million accounts in 2014 has highlighted shortcomings in U.S. rules on when cyber attacks must be revealed and their enforcement.
Democratic Senator Mark Warner this week asked the U.S. Securities and Exchange Commission to investigate whether Yahoo and its senior executives properly disclosed the attack, which Yahoo blamed on Sept. 22 on a "state-sponsored actor."
The Yahoo hack could become a test case of the SEC's guidelines, said Jacob Olcott, former Senate Commerce Committee counsel who helped develop them, due to the size of the breach, intense public scrutiny and uncertainty over the timing of Yahoo's discovery.
Yahoo has not specifically addressed when it learned of the 2014 attack. And the vagueness of SEC's 2011 rules on disclosure and its failure to enforce them are drawing equal attention, privacy lawyers and cyber security experts said.
The agency has "been looking for the right case to bring forward," said Olcott.
The agency in 2011 told publicly traded companies to report hacking incidents that could have a "material adverse effect on the business" but did not define that.
SEC has never acted against a company for failing to disclose a cybersecurity incident or threat, and it has brought just two enforcement actions against companies for insufficient data protection, an agency spokesman said.
Lawyers said this reflected difficulty in determining if breaches were material and many companies' belief that reporting on cyber threats generally satisfies the disclosure requirement.
Yahoo has not offered a precise timeline about when it was made aware of the breach.
On Sept. 9, it said in an SEC filing it did not know of "any incidents of, or third party claims alleging ... unauthorized access" of customers' personal data that could have a material adverse effect on Verizon Communication Inc's (VZ.N) planned $4.8 billion acquisition of Yahoo's core business.
Since then, Yahoo has not clarified if it knew of the attack before that SEC filing. "Our investigation into this matter is ongoing and the issues are complex," a Yahoo spokesman said last week.
In his letter, Warner asked the SEC to evaluate whether the current disclosure regime was adequate. He cited reports that fewer than 100 of 9,000 public companies disclosed a material data breach since 2010.
"I don't know that we need new rules. But in certain situations, you may need more aggressive enforcement," said Roberta Karmel, a Brooklyn Law School professor.
The SEC in 2014 examined whether cyber disclosure rules needed to be strengthened and imposed new requirements for broker-dealers and investment advisers but not public companies.
'PUNISH THE VICTIM'
Some policymakers worry rules compelling prompt disclosure of cyber attacks could deter companies from cooperating with authorities.
"We cannot blame executives for worrying that what starts today as an honest conversation about a cyberattack could end tomorrow in a ‘punish the victim' regulatory enforcement action," Commerce Secretary Penny Pritzker said this week.
Congress last year expanded liability protections for companies that share cyber information with the government, and Pritzker urged granting companies temporary immunity during the response to a hack.
Amid SEC inaction, the Federal Trade Commission has brought 60 successful data security cases since 2001 in part, lawyers said, because its authority is clearer than the SEC's.
Those cases have dealt with deceptive statements by companies and security lapses. The FTC is hampered by the lack of a national requirement for companies to notify the public about data breaches.
That idea got widespread support after the 2013 hacking of shoppers' credit card information from Target Corp. (TGT.N) But legislation proposed by President Barack Obama in 2015 fizzled.
Source: Reuters


Clic here to read the story from its source.