No Scroll News

SEC Enforces Fines on Four Companies for Misleading Cybersecurity Disclosures

The SEC fined Mimecast, Avaya, Check Point, and Unisys for materially misleading cybersecurity disclosures, reinforcing the need for transparent reporting of cyber incidents.
Published on April 14, 2025

The U.S. Securities and Exchange Commission (SEC) has taken decisive action against four companies—Mimecast, Avaya, Check Point, and Unisys—for providing materially misleading disclosures about cybersecurity incidents. The enforcement, reported throughout October 2024 and noted as linked to the SolarWinds hack, resulted in penalties totaling up to $7 million. Unisys faced fines of up to $4 million, while the remaining firms were fined approximately $1 million each.

These actions underscore the SEC's intensified focus on ensuring that companies report cybersecurity risks and breaches with accuracy and timeliness. With the backdrop of significant events such as the 2020 SolarWinds incident, regulators are emphasizing the importance of transparent communication to protect investors and maintain market integrity.


Sources
ReutersAxiosCRNHelp Net SecuritySecurity BoulevardCyberScoopHarvard Law School Forum on Corporate Governance