Latest Publications

Share:

SEC Reportedly Announces Major Reorganization of Enforcement and Exams Divisions

The U.S. Securities and Exchange Commission (SEC) has reportedly announced internally a major reorganization of its enforcement and exams divisions. This restructuring, effective April 9, 2025, was detailed in a staff memo...more

When to Notify Your Cyber Carrier of a Security Incident - Dear Mary – Incidents + Investigations Cybersecurity Advice Column

Our company experienced a cybersecurity incident. It seemed pretty minor — just a few suspicious emails and an employee’s account being locked. To my dismay, we’re now hearing from our IT team that the issue is more serious....more

SEC 2024 Enforcement Results: A Decline in Total Enforcement, but a Record-Breaking Recovery of Financial Remedies

On November 22, the Securities and Exchange Commission (SEC) announced its enforcement results for fiscal year (FY) 2024. As compared to FY 2023, the Division of Enforcement (the division) reported a 26% decline in the total...more

6 Considerations to Determine if a Cyber Incident Is Material

In late June, the staff of the U.S. Securities and Exchange Commission’s Division of Corporation Finance released five new compliance and disclosure interpretations regarding the disclosure of material cybersecurity incidents...more

Cyber Incident Response Checklist for SEC Compliance

By now, public companies are generally aware of the cybersecurity rules adopted by the U.S. Securities and Exchange Commission a year ago, requiring public companies to disclose material cybersecurity incidents under Item...more

SEC Cybersecurity Incidents Disclosures: Materiality, Decryptors, and Ransom Payments - Dear Mary – Incidents + Investigations...

I work for a public company that recently experienced a ransomware attack. Fortunately, we were able to restore our business operations quickly by obtaining a decryption key from the threat actor. Given that we managed to get...more

SEC Charges Broker-Dealer and Two Affiliated Investment Advisers With Violating Whistleblower Protection Rule

On September 4, the Securities and Exchange Commission (SEC) issued an order against three investment adviser firms for violating the whistleblower protections of Rule 21F-17(a) under the Securities Exchange Act of 1934. This...more

Notifying Law Enforcement of Security Incidents - Dear Mary – Incidents + Investigations Cybersecurity Advice Column

“Dear Mary” is Troutman Pepper’s Incidents + Investigations team’s advice column. Here, you will find Mary’s answers to questions about anything and everything cyber-related — data breaches, forensic investigations, how to...more

Ensuring Proper Legal Involvement in the Incident Response Process - Dear Mary – Incidents + Investigations Cybersecurity Advice...

“Dear Mary” is Troutman Pepper’s Incidents + Investigations team’s advice column. Here, you will find Mary’s answers to questions about anything and everything cyber-related — data breaches, forensic investigations, how to...more

Restrictions on Paying a Ransom Demand - Dear Mary – Incidents + Investigations Cybersecurity Advice Column

“Dear Mary” is Troutman Pepper’s Incidents + Investigations team’s advice column. Here, you will find Mary’s answers to questions about anything and everything cyber-related — data breaches, forensic investigations, how to...more

Understanding Access vs. Acquisition - Dear Mary – Incidents + Investigations Cybersecurity Advice Column

Each of the 50 states has its own definition of what constitutes a reportable data breach. For some, it requires “unauthorized access” to personal information. For others, it requires “unauthorized acquisition.” And then,...more

Understanding Breach Notification Obligations Under California Law: What Does the CCPA Require? - Dear Mary – Incidents +...

‘Dear Mary,’ is Troutman Pepper’s Incidents + Investigations team’s advice column. Here, you will find Mary’s answers to questions about anything and everything cyber-related – data breaches, forensic investigations, how to...more

Preserving Forensic Artifacts Following Incident Detection - Dear Mary – Incidents + Investigations Cybersecurity Advice Column

‘Dear Mary,’ is Troutman Pepper’s Incidents + Investigations team’s advice column. Here, you will find Mary’s answers to questions about anything and everything cyber-related – data breaches, forensic investigations, how to...more

Can Vendors Notify Affected Individuals on Behalf of Businesses After a Data Breach? - Dear Mary – Incidents + Investigations...

‘Dear Mary,’ is Troutman Pepper’s Incidents + Investigations team’s advice column. Here, you will find Mary’s answers to questions about anything and everything cyber-related – data breaches, forensic investigations, how to...more

SEC Charges Investment Advisor for Misleading Disclosures About Its Work With Short Publishers

On June 11, the Securities and Exchange Commission (SEC) announced the first settled case in its ongoing review of collaborations between investment advisors and short publishers. The SEC fined affiliated investment advisors...more

How to Respond When Your Service Provider Suffers a Cyberattack - Dear Mary – Incidents + Investigations Cybersecurity Advice...

‘Dear Mary,’ is Troutman Pepper’s Incidents + Investigations team’s advice column. Here, you will find Mary’s answers to questions about anything and everything cyber-related – data breaches, forensic investigations, how to...more

Understanding Regulatory Response Times Following a Cybersecurity Incident - Dear Mary – Incidents + Investigations Cybersecurity...

‘Dear Mary,’ is Troutman Pepper’s Incidents + Investigations team’s advice column. Here, you will find Mary’s answers to questions about anything and everything cyber-related – data breaches, forensic investigations, how to...more

Does Every Incident Require a Forensic Report? - Dear Mary – Incidents + Investigations Cybersecurity Advice Column

‘Dear Mary,’ is Troutman Pepper’s Incidents + Investigations team’s advice column. Here, you will find Mary’s answers to questions about anything and everything cyber-related – data breaches, forensic investigations, how to...more

Should Companies Conduct Their Own Forensic Investigations? - Dear Mary – Incidents + Investigations Cybersecurity Advice Column

‘Dear Mary,’ is Troutman Pepper’s Incidents + Investigations team’s advice column. Here, you will find Mary’s answers to questions about anything and everything cyber-related – data breaches, forensic investigations, how to...more

FINRA’s First Disciplinary Action Targeting Firm’s Use of Social Media Influencers

The Financial Industry Regulatory Authority’s (FINRA) Enforcement Division recently announced its first settlement involving a firm’s supervision of social media influencers. The respondent, M1 Finance LLC (M1), is a...more

Unanimous Supreme Court Decision Allows for Early Challenges to Federal Agency Enforcement Actions

On April 14, the Supreme Court unanimously held that federal district courts have jurisdiction to review constitutional challenges to the structures of the Federal Trade Commission (FTC) and Securities and Exchange Commission...more

Encrypted Electronic Instant Messaging Applications Continue to Catch the Government's Attention

In March 2023, the Department of Justice (DOJ) Criminal Division updated its Evaluation of Corporate Compliance Programs (ECCP) guidance to address the use of personal devices and third-party messaging applications by...more

SEC Settlement With McDonald's and Ex-CEO Signals Potential Expansion of Executive Compensation Disclosure Requirements

On January 9, the Securities and Exchange Commission (SEC) announced that it had reached a settlement with McDonald’s and its former CEO, Stephen Easterbrook, for charges stemming from McDonald’s 2019 termination of...more

FINRA Issues 2023 Examination and Risk Management Program Report: What It Says and How to Respond

On January 10, FINRA published its “2023 Report on FINRA’s Examination and Risk Management Program” (Report) — FINRA’s third annual compendium of guidance, covering key topics and emerging risks for member firms to consider...more

SEC's Enforcement Results for FY 2022 Reflect Robust Enforcement and Record-Breaking Penalties

On November 15, the U.S. Securities and Exchange Commission (SEC) announced its enforcement results for fiscal year 2022, which featured the following key metrics...more

37 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide