After retaining counsel, all subsequent strikes are fraught with hazard. “If the CISO believes that there was a fraud to the SEC, the CISO has an obligation to report it to the board. Which will itself be company suicide,” Rasch mentioned, including that the following move-going to the feds-is much more problematic. “Going to the SEC is crossing the Rubicon.”
“The CISO just isn’t an skilled on SEC disclosures, however you’ve an officer who now is aware of that the corporate made materially false disclosures,” Rasch mentioned. “There’s a authorized obligation for the CISO to take action if the CISO is correct. And solely if the CISO is correct.”
Rasch then tempered his remark barely, as he tried to articulate what an SEC lawyer is more likely to think about. “You do not essentially need to be proper, however you need to be cheap. It may be a query of diploma.” In different phrases, if the CISO suspects fraud however chooses to not report it to the SEC or to the board, the CISO won’t be prosecuted if the SEC concludes that the CISO moderately assessed that no fraud existed. If the CISO is definite that fraud did exist, there’s an obligation to report.
Set expectations for SEC filings when employed
Brush argues that CISOs want to barter after they settle for the CISO function that they’d have last say on SEC filings that cope with cybersecurity issues. On the very least, Brush mentioned, the CISO ought to insist that the CISO be requested about any modifications earlier than they’re last in order that the CISO has a possibility to argue why the change could also be a foul thought.
Put objections to SEC filings in writing
Past that, Brush means that CISOs put in writing any objections to submitting. “If I’ve a dissenting view, I would like it on the document,” Brush mentioned. That does not imply that it will likely be included within the submitting. It merely signifies that the doc is positioned in a personnel folder or another personal location. If issues blow up months later and turn into a authorized mess, the SEC can uncover the doc that makes it clear that the CISO objected.
“If there’s any IR [incident response] report that by no means sees the sunshine of day, I’m going to be placing in a dissenting view and ensuring that it’s filed away someplace,” Brush mentioned. “That is an ace in your again pocket.”