2017-01-01 SEC Press press_release 62 KB 2,553 chars

SEC Chairman Clayton Issues Statement on Cybersecurity

Release
2017-170
Caption
Securities and Exchange Commission v. Chairman Clayton, et al.
summary

The SEC disclosed a 2016 cyber intrusion into its EDGAR test filing system that may have enabled illicit trading using nonpublic information, prompting an internal investigation and enhanced cybersecurity protocols, though no individuals were charged and no PII or systemic risk was compromised.

paragraph

In 2016, a software vulnerability in the SEC’s EDGAR test filing system was exploited, granting unauthorized access to nonpublic information that may have been used for illicit trading, though the flaw was promptly patched. The breach was confirmed in August 2017, triggering an internal investigation; no personally identifiable information was compromised, SEC operations were unaffected, and no systemic risk emerged. While no formal charges or enforcement actions were announced, Chairman Clayton emphasized the SEC’s commitment to strengthening cybersecurity resilience, improving internal risk management, and enforcing disclosure obligations against market participants who fail to report cyber threats.

narrative

In 2016, a software vulnerability in the SEC’s EDGAR test filing system was exploited, allowing unauthorized access to nonpublic information that may have been used for illicit trading, though the flaw was patched immediately upon discovery. The breach was not publicly confirmed until August 2017, when an internal investigation was launched under Chairman Jay Clayton’s direction. The SEC determined that no personally identifiable information was compromised, its operations were not disrupted, and no systemic market risk resulted from the incident. Although no individuals or entities were formally charged or named in connection with the breach, the event prompted a comprehensive reassessment of the SEC’s cybersecurity posture. This included the creation of a senior-level cybersecurity working group to improve information sharing, risk monitoring, and incident response across the agency. Chairman Clayton’s statement underscored the inevitability of cyber intrusions and stressed the importance of resilience, recovery, and proactive regulatory oversight. The SEC also committed to integrating cybersecurity considerations into its disclosure-based and supervisory frameworks, and to enforcing federal securities laws against market participants who fail to meet their obligations to disclose material cyber risks. Overall, the episode reinforced the agency’s dual mission of protecting market integrity and leading by example in cybersecurity governance.

Enriched metadata

Scheme
cyber-fraud (90%)
Classified cyber-fraud(confidence 90%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
chairman claytoncreation of senior-level cybersecurity working groupinternal investigationongoing assessment of sec cybersecurity risk profile in maysec chairman jay claytonsenior-level cybersecurity working groupsoftware vulnerability
Keywords
cybersecuritychairman claytonchairmanclaytonstatementcommissionsecrisksagencyriskclayton issuesissues statementstatement cybersecuritymarket participantscommission edgar

Extracted insights

Entities 7
  • person chairman clayton
  • company creation of senior-level cybersecurity working group
  • person internal investigation
  • agency ongoing assessment of sec cybersecurity risk profile in may
  • agency sec chairman jay clayton
  • company senior-level cybersecurity working group
  • person software vulnerability
Triples 10
  • SEC Chairman Jay Clayton Issued Statement Highlighting Importance Of Cybersecurity
  • Chairman Clayton Initiated Ongoing Assessment Of SEC Cybersecurity Risk Profile In May
  • Initiative Included Creation Of Senior-Level Cybersecurity Working Group
  • Senior-Level Cybersecurity Working Group Coordinates Information Sharing, Risk Monitoring, And Incident Response Efforts
  • Statement Provides Overview Of Commission’s Collection And Use Of Data
  • Commission’s EDGAR Test Filing System Suffered 2016 Intrusion
  • Commission Learned In August 2017 That Incident May Have Provided Basis For Illicit Gain Through Trading
  • Software Vulnerability Was Exploited Resulted In Access To Nonpublic Information
  • Intrusion Did Not Result Unauthorized Access To Personally Identifiable Information
  • Internal Investigation Was Commenced At Direction Of Chairman
View original SEC press releasesec.gov
Extracted body text (2,553c)
SEC Chairman Jay Clayton today issued a statement highlighting the importance of cybersecurity to the agency and market participants, and detailing the agency’s approach to cybersecurity as an organization and as a regulatory body. The statement is part of an ongoing assessment of the SEC’s cybersecurity risk profile that Chairman Clayton initiated upon taking office in May. Components of this initiative have included the creation of a senior-level cybersecurity working group to coordinate information sharing, risk monitoring, and incident response efforts throughout the agency. The statement provides an overview of the Commission’s collection and use of data and discusses key cyber risks faced by the agency, including a 2016 intrusion of the Commission’s EDGAR test filing system. In August 2017, the Commission learned that an incident previously detected in 2016 may have provided the basis for illicit gain through trading. Specifically, a software vulnerability in the test filing component of the Commission’s EDGAR system, which was patched promptly after discovery, was exploited and resulted in access to nonpublic information. It is believed the intrusion did not result in unauthorized access to personally identifiable information, jeopardize the operations of the Commission, or result in systemic risk. An internal investigation was commenced immediately at the direction of the Chairman. “Cybersecurity is critical to the operations of our markets and the risks are significant and, in many cases, systemic,” said Chairman Clayton. “We must be vigilant. We also must recognize—in both the public and private sectors, including the SEC—that there will be intrusions, and that a key component of cyber risk management is resilience and recovery.” The statement also outlines the management of internal cybersecurity risks, including the incorporation of cybersecurity considerations in disclosure-based and supervisory efforts, coordination with other government entities, and the enforcement of the federal securities laws against cyber threat actors and market participants that do not meet their disclosure obligations. Chairman Clayton writes, “By promoting effective cybersecurity practices in connection with both the Commission’s internal operations and its external regulatory oversight efforts, it is our objective to contribute substantively to a financial market system that recognizes and addresses cybersecurity risks and, in circumstances in which these risks materialize, exhibits strong mitigation and resiliency.”
OCR text (2,553c · plain-text · 99% conf)
SEC Chairman Jay Clayton today issued a statement highlighting the importance of cybersecurity to the agency and market participants, and detailing the agency’s approach to cybersecurity as an organization and as a regulatory body. The statement is part of an ongoing assessment of the SEC’s cybersecurity risk profile that Chairman Clayton initiated upon taking office in May. Components of this initiative have included the creation of a senior-level cybersecurity working group to coordinate information sharing, risk monitoring, and incident response efforts throughout the agency. The statement provides an overview of the Commission’s collection and use of data and discusses key cyber risks faced by the agency, including a 2016 intrusion of the Commission’s EDGAR test filing system. In August 2017, the Commission learned that an incident previously detected in 2016 may have provided the basis for illicit gain through trading. Specifically, a software vulnerability in the test filing component of the Commission’s EDGAR system, which was patched promptly after discovery, was exploited and resulted in access to nonpublic information. It is believed the intrusion did not result in unauthorized access to personally identifiable information, jeopardize the operations of the Commission, or result in systemic risk. An internal investigation was commenced immediately at the direction of the Chairman. “Cybersecurity is critical to the operations of our markets and the risks are significant and, in many cases, systemic,” said Chairman Clayton. “We must be vigilant. We also must recognize—in both the public and private sectors, including the SEC—that there will be intrusions, and that a key component of cyber risk management is resilience and recovery.” The statement also outlines the management of internal cybersecurity risks, including the incorporation of cybersecurity considerations in disclosure-based and supervisory efforts, coordination with other government entities, and the enforcement of the federal securities laws against cyber threat actors and market participants that do not meet their disclosure obligations. Chairman Clayton writes, “By promoting effective cybersecurity practices in connection with both the Commission’s internal operations and its external regulatory oversight efforts, it is our objective to contribute substantively to a financial market system that recognizes and addresses cybersecurity risks and, in circumstances in which these risks materialize, exhibits strong mitigation and resiliency.”