SEC Charges R.R. Donnelley & Sons Co. with Cybersecurity-Related Controls Violations
R.R. Donnelley & Sons Company (RRD) agreed to pay over $2.1 million to settle SEC charges regarding disclosure and internal control failures related to 2021 cybersecurity incidents.
R.R. Donnelley & Sons Company (RRD) agreed to pay a $2,125,000 civil penalty to settle SEC charges involving cybersecurity disclosure and internal control failures. The SEC found that RRD violated Section 13(b)(2)(B) of the Securities Exchange Act of 1934 and Rule 13a-15a. These violations stemmed from the company's failure to maintain effective procedures for reporting cyber alerts and ensuring authorized access to its IT systems.
The Securities and Exchange Commission announced that R.R. Donnelley & Sons Company (RRD) will pay a $2,125,000 civil penalty to settle charges related to cybersecurity incidents in late 2021. The SEC found that RRD failed to implement effective disclosure controls to report cyber alerts to management and lacked sufficient internal accounting controls to protect its IT assets. Specifically, the company's systems were insufficient for elevating cyberattacks to management and ensuring that network access was properly authorized. RRD violated Section 13(b)(2)(B) of the Securities Exchange Act of 1934 and Exchange Act Rule 13a-15a. Without admitting or denying the findings, RRD agreed to cease and desist from future violations. The settlement reflects RRD's meaningful cooperation with the investigation and its voluntary adoption of new cybersecurity technologies and controls.
Exhibits & Attached Documents (1)
Extracted insights
- $2.13M $2,125,000 $1M–$10M
- $2.10M $2.1 million $1M–$10M
- person Jorge G. Tenreiro
- agency the sec’s investigation
- agency the sec’s order
- agency the securities and exchange commission
- The Securities and Exchange Commission announced R.R. Donnelley & Sons Company (RRD) agreed to pay over $2.1 million to settle disclosure and internal control failure charges relating to cybersecurity incidents and alerts in late 2021
- Jorge G. Tenreiro said The Commission instituted this enforcement action because RRD’s controls for elevating cybersecurity incidents to its management and protecting company assets from cyberattacks were insufficient
- RRD cooperated with our investigation in a meaningful way
- The SEC’s order found data integrity and confidentiality were critically important to RRD’s business
- RRD’s information security personnel and the third-party service provider RRD hired were responsible for monitoring the network’s security
- RRD failed to design effective disclosure controls and procedures to report relevant cybersecurity information to management with the responsibility for making disclosure decisions
- RRD failed to carefully assess and respond to alerts of unusual activity in a timely manner
- RRD failed to devise and maintain a system of cybersecurity-related internal accounting controls sufficient to provide reasonable assurances that access to RRD’s assets – its information technology systems and networks – was permitted only with management’s authorization
- The SEC’s order found RRD violated Section 13(b)(2)(B) of the Securities Exchange Act of 1934 and Exchange Act Rule 13a-15a
- RRD agreed to cease and desist from committing violations of these provisions
- RRD agreed to pay a $2,125,000 civil penalty
- RRD cooperated throughout the investigation
- RRD reported the cybersecurity incident to staff prior to filing a disclosure of the incident
- RRD provided meaningful cooperation that helped expedite the staff’s investigation
- RRD voluntarily adopted new cybersecurity technology and controls
- The SEC’s investigation was conducted by Arsen Ablaev of the Crypto Assets and Cyber Unit and Christine S. Bautista of the Chicago Regional Office
- The SEC’s investigation was supervised by Amy Flaherty Hartman and Mr. Tenreiro of the Crypto Assets and Cyber Unit
The Securities and Exchange Commission today announced that R.R. Donnelley & Sons Company (RRD), a global provider of business communication and marketing services, agreed to pay over $2.1 million to settle disclosure and internal control failure charges relating to cybersecurity incidents and alerts in late 2021. “The Commission instituted this enforcement action because RRD’s controls for elevating cybersecurity incidents to its management and protecting company assets from cyberattacks were insufficient,” said Jorge G. Tenreiro, Acting Chief of the Crypto Assets and Cyber Unit. “RRD did, however, cooperate with our investigation in a meaningful way, and that is reflected in the terms of this settlement.” According to the SEC’s order, data integrity and confidentiality were critically important to RRD’s business. Because client data was stored on RRD’s network, its information security personnel and the third-party service provider RRD hired were responsible for monitoring the network’s security. However, according to the order, RRD failed to design effective disclosure controls and procedures to report relevant cybersecurity information to management with the responsibility for making disclosure decisions, and failed to carefully assess and respond to alerts of unusual activity in a timely manner. The order further finds that RRD failed to devise and maintain a system of cybersecurity-related internal accounting controls sufficient to provide reasonable assurances that access to RRD’s assets – its information technology systems and networks – was permitted only with management’s authorization. The SEC’s order found that RRD violated Section 13(b)(2)(B) of the Securities Exchange Act of 1934 and Exchange Act Rule 13a-15a. Without admitting or denying the SEC’s findings, RRD agreed to cease and desist from committing violations of these provisions and to pay a $2,125,000 civil penalty. As described in the order, RRD cooperated throughout the investigation, including by reporting the cybersecurity incident to staff prior to filing a disclosure of the incident, by providing meaningful cooperation that helped expedite the staff’s investigation, and by voluntarily adopting new cybersecurity technology and controls. The SEC’s investigation was conducted by Arsen Ablaev of the Crypto Assets and Cyber Unit and Christine S. Bautista of the Chicago Regional Office, with assistance from Kathleen Sweeney and Christopher Carpenter, and was supervised by Amy Flaherty Hartman and Mr. Tenreiro of the Crypto Assets and Cyber Unit.
The Securities and Exchange Commission today announced that R.R. Donnelley & Sons Company (RRD), a global provider of business communication and marketing services, agreed to pay over $2.1 million to settle disclosure and internal control failure charges relating to cybersecurity incidents and alerts in late 2021. “The Commission instituted this enforcement action because RRD’s controls for elevating cybersecurity incidents to its management and protecting company assets from cyberattacks were insufficient,” said Jorge G. Tenreiro, Acting Chief of the Crypto Assets and Cyber Unit. “RRD did, however, cooperate with our investigation in a meaningful way, and that is reflected in the terms of this settlement.” According to the SEC’s order, data integrity and confidentiality were critically important to RRD’s business. Because client data was stored on RRD’s network, its information security personnel and the third-party service provider RRD hired were responsible for monitoring the network’s security. However, according to the order, RRD failed to design effective disclosure controls and procedures to report relevant cybersecurity information to management with the responsibility for making disclosure decisions, and failed to carefully assess and respond to alerts of unusual activity in a timely manner. The order further finds that RRD failed to devise and maintain a system of cybersecurity-related internal accounting controls sufficient to provide reasonable assurances that access to RRD’s assets – its information technology systems and networks – was permitted only with management’s authorization. The SEC’s order found that RRD violated Section 13(b)(2)(B) of the Securities Exchange Act of 1934 and Exchange Act Rule 13a-15a. Without admitting or denying the SEC’s findings, RRD agreed to cease and desist from committing violations of these provisions and to pay a $2,125,000 civil penalty. As described in the order, RRD cooperated throughout the investigation, including by reporting the cybersecurity incident to staff prior to filing a disclosure of the incident, by providing meaningful cooperation that helped expedite the staff’s investigation, and by voluntarily adopting new cybersecurity technology and controls. The SEC’s investigation was conducted by Arsen Ablaev of the Crypto Assets and Cyber Unit and Christine S. Bautista of the Chicago Regional Office, with assistance from Kathleen Sweeney and Christopher Carpenter, and was supervised by Amy Flaherty Hartman and Mr. Tenreiro of the Crypto Assets and Cyber Unit.