{"id":4240,"date":"2024-06-28T08:13:13","date_gmt":"2024-06-28T13:13:13","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/don-t-forget-to-report-a-breach-a-cautionary-tale"},"modified":"2024-06-28T08:13:13","modified_gmt":"2024-06-28T13:13:13","slug":"dont-forget-to-report-a-breach-a-cautionary-tale","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/28\/dont-forget-to-report-a-breach-a-cautionary-tale\/","title":{"rendered":"Don&#8217;t Forget to Report a Breach: A Cautionary Tale"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt6ae5a8b97267d3cc\/667586d4f826a378b835a25e\/Compliance%281800%29_NicoElNino_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When the Intercontinental Exchange (ICE) identified a breach in its virtual private network (VPN), the organization immediately launched investigation and remediation efforts. However, it&nbsp;was not until four days later that the company reported the breach to regulators, violating not only the Security and Exchange Commission&#8217;s (SEC) compliance requirements but also the company&#8217;s own internal cyber incident reporting procedures. This is according to the SEC in its <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sec.gov\/news\/press-release\/2024-63\" rel=\"noopener\">May announcement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of a $10 million fine. The question of why ICE delayed&nbsp;reporting&nbsp;the incident was never answered publicly.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The SEC stated: &#8220;The SEC&#8217;s order finds that ICE personnel did not notify the legal and compliance officials at ICE&#8217;s subsidiaries of the intrusion for several days in violation of ICE\u2019s own internal cyber incident reporting procedures. As a result of ICE&#8217;s failures, those subsidiaries did not properly assess the intrusion to fulfill their independent regulatory disclosure obligations under Regulation SCI (Regulation Systems Compliance and Integrity), which required them to immediately contact SEC staff about the intrusion and provide an update within 24 hours unless they immediately concluded or reasonably estimated that the intrusion had or would have no or a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">de minimis<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> impact on their operations or on market participants.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Both ICE and the SEC declined to answer Dark Reading&#8217;s inquiries, but there are some possible explanations. It is also a cautionary tale for other critical infrastructure organizations that consider bypassing compliance for quicker incident response.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A popular misconception is that enterprises have a cavalier attitude about compliance and think that it is easier to pay the fine and chance the consequences of bad press and lawsuits, rather than file the necessary compliance documents and deal with the outcome of suffering a breach.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I&#8217;ve never been in a situation or a meeting where someone has seriously said, &#8216;Well, we&#8217;ll just pay the fine,'&#8221; says Fred Rica, a partner at certified public accounting firm BPM Associates. &#8220;I think most boards and management committees strive to do the right thing and abide by the rules and regulations that they&#8217;re bound to.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The challenge remains that nontechnical board members often do not understand cybersecurity implications, while CISOs may struggle to explain threats in business terms. Rica emphasizes the need for boards to ask better questions and be more engaged with cybersecurity issues.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The first thing that has to change is, boards need to start asking better questions,&#8221; he says, adding that the time where boards could pass off cyber threats to the technical team has passed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;What was sufficient even three years ago probably is not sufficient anymore,&#8221; Rica says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the case of ICE, the VPN attack turned out to have \u201c<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">de minimis<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> impact on their operations or on market participants,&#8221; the SEC said. While that alone does not change the need to report attacks against critical infrastructure within 24 hours, it could&nbsp;indicate that the company focused&nbsp;on fixing a problem as quickly as possible. Or it simply might mean that the company dropped the ball on what should have been a task that should have been done within 24 hours.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A company that doesn&#8217;t report a data breach could face greater scrutiny of its cyber insurance policy. Companies with adequate security controls get better rates and terms on their cyber policies, while those with shortcomings face higher rates and less favorable terms, notes Bridget Quinn Choi, an attorney at Woodruff-Sawyer &amp; Co.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In this case, she says, ICE was on top of the incident almost immediately.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;They had a criticality matrix. They had reporting controls, they were looking at the severity, and they fairly quickly went in and found the vulnerability. They found that there was a minor intrusion, and they remediated so quickly,&#8221; she says. &#8220;It wasn&#8217;t a big deal. So it was a pretty good result from an incident response perspective. The thing that was missing is that in their incident response plan, they had to report within 24 hours if there was a reasonable suspicion of an intrusion. They didn&#8217;t do it.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Choi notes that while the response was fast, the company had procedural issues.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Even the SEC came back and said this was <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">de minimis<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. But it&#8217;s their second violation,&#8221; she says. (The company previously violated the SEC&#8217;s Regulation SCI for failing to have appropriate backup and backup procedures.)<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I think that there&#8217;s a common misconception that cyber is an infosec issue,&#8221; she says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Rather, cybersecurity is a business process that can have a wide-ranging effect on the company, its reputation, and revenue.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The impact to the company can be wide-ranging,&#8221; she says. There can be cascading costs, there&#8217;s regulatory issues, [and] there&#8217;s a plaintiff&#8217;s bar that is hungry to get into this game. So it&#8217;s not just doing things, right? It&#8217;s doing things right.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/don-t-forget-to-report-a-breach-a-cautionary-tale\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When the Intercontinental Exchange (ICE) identified a breach in its<\/p>\n","protected":false},"author":12,"featured_media":4241,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4240","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/dont-forget-to-report-a-breach-a-cautionary-tale.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4240","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4240"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4240\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4241"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4240"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4240"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4240"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}