“Hey, Look, There’s A Hoof Cleaner!” – SEC Commissioners Again Criticize Recent Internal Controls Enforcement Theory

June 20, 2024

Yesterday’s post highlighted the SEC’s enforcement action against R.R. Donnelley & Sons Company (RRD) and how – in the non-FCPA, FCPA enforcement action – the SEC “pushed the internal controls envelope” in connection with a cybersecurity breach at the company. In prior recent enforcement actions against SolarWinds and Charter Communications, the SEC also “pushed the internal controls envelope.” (See here and here).

In connection with the Charter Communications matter, SEC Commissioners Hester Peirce (appointed by President Trump) and Mark Uyeda (appointed by President Biden) issued a blistering statement criticizing the SEC’s internal controls enforcement theory by stating that the SEC “does not have authority to tell companies how to run themselves – but [the SEC is] now routinely us[ing] the internal controls provisions to do just that.”

In connection with the RRD matter, Commissions Peirce and Uyeda once again criticized the SEC’s internal controls theory of enforcement and stated that the SEC “stretch[ed] the law to punish a company that was the victim of a cyberattack” and “distort[ed] a statutory provision.”

Their statement titled “Hey, Look, There’s a Hoof Cleaner! Statement on R.R. Donnelley & Sons, Co.” reads in full:

“As we have noted before, the Commission in recent years has taken to treating Exchange Act Section 13(b)(2)(B)’s internal accounting controls provision as a Swiss Army Statute to compel issuers to adopt policies and procedures the Commission believes prudent. Identifying a link between the Commission’s preferred policies and procedures and accounting controls seems a collateral concern, if it is a concern at all. In [the] settled administrative proceeding against R.R. Donnelly & Sons, Co. (“RRD”), the Commission finds and uses a novel attachment on its multi-use tool—“a system of cybersecurity-related internal accounting controls.”

Understanding the particulars of RRD’s alleged violation of Section 13(b)(2)(B) requires careful parsing of the Order Instituting Proceedings. RRD was the victim of a cyberattack. For a period of approximately four weeks in 2021, a “threat actor was able to utilize deceptive hacking techniques to install encryption software on certain RRD computers (mostly virtual machines) and exfiltrated 70 Gigabytes of data, including data belonging to 29 of RRD’s 22,000 clients, some of which contained personal identification and financial information.” On December 23, “a company with shared access to RRD’s network alerted RRD’s Chief Information Security Officer [“CISO”] about potential anomalous internet activity emanating from RRD’s network,” and RRD “began actively responding to the attack.” Importantly, RRD’s investigation into the incident “uncovered no evidence that the threat actor accessed RRD’s financial systems and corporate financial and accounting data.”

The Order notes that RRD did have an “internal intrusion detection system” that, as early as November 29, “began issuing alerts . . . about certain malware in the RRD network” that were “visible” to both RRD and its third-party managed security services provider (“MSSP”). The MSSP sent three of the alerts to RRD personnel who reviewed them, “but, in partial reliance on its MSSP, did not take the infected instances off the network and [RRD] failed to conduct its own investigation of the activity, or otherwise take steps to prevent further compromise, before December 23, 2021.” The MSSP also failed to escalate to RRD at least 20 other alerts related to the same activity. Although RRD’s controls detected possible intrusions, according to the Order, the internal accounting controls nonetheless were deficient because “RRD’s cybersecurity alert review and incident response policies and procedures failed to adequately establish a prioritization scheme and to provide clear guidance to internal and external personnel on procedures for responding to incidents.” This lack of an adequate “prioritization scheme” and “clear guidance . . . for responding to incidents” meant that “RRD’s external and internal security personnel failed to adequately review these alerts [generated by the intrusion detection system]” and that RRD in consequence failed to “take adequate investigative and remedial measures” until after the CISO was alerted by an outside company. The delayed response created by RRD’s inadequate policies and procedures “was exploited by hackers” who accessed RRD’s computer systems and exfiltrated client data. From these findings, the Order concludes that RRD violated Section 13(b)(2)(B)(iii)’s requirement that it “devise and maintain a system of internal accounting controls sufficient to provide reasonable assurance that . . . (iii) access to assets is permitted only in accordance with management’s general or specific authorization.”

The Order states that the “assets” that were accessed were RRD’s “information technology systems and networks,” which does not fit the category of assets captured by Section 13(b)(2)(B). The computer systems, while an RRD asset in a broad sense, are not an asset of the type covered by Section 13(b)(2)(B)’s internal accounting controls provisions. To explain why requires some discussion of the source and function of the Foreign Corrupt Practices Act’s internal accounting controls provision.

Section 13(b)(2)(B) originates with American Institute of Certified Public Accountants (“AICPA”) Statement on Auditing Standards No. 1 (“SAS”). The SAS explains that, in the context of internal accounting controls, the “safeguarding of assets refers only to protection against loss arising from intentional and unintentional errors in processing transactions and handling the related assets.” The specific objectives codified in Section 13(b)(2)(B) come from a section of the auditing standards that were adopted to clarify what internal accounting controls that safeguard assets means “in relation to the functions involved in the flow of transactions.” To that end, the SAS explained that transactions “include exchanges of assets or services” and “[t]he primary functions involved in the flow of transactions and related assets include the authorization, execution, and recording of transactions and the accountability for resulting assets.” Authorization for transactions, in turn, “refers to management’s decision to exchange, transfer, or use assets for specified purposes under specified conditions,” and the related “accountability function follows assets from the time of their acquisition in one transaction until their disposition or use in another.”

After setting out the functions involved and the meaning of the terms used, the SAS then defines two distinct, chronological categories of controls: administrative controls and accounting controls. Administrative controls precede accounting controls and include “the plan of organization and the procedures and records that are concerned with the decision processes leading to management’s authorization of transactions.” Accounting controls, in contrast, focus on the transactions themselves and “are concerned with the safeguarding of assets and the reliability of financial records.” To that end, the SAS sets out four objectives for effective internal accounting controls: “to provide reasonable assurances that:

  1. Transactions are executed in accordance with management’s general or specific authorization.
  2. Transactions are recorded as necessary (1) to permit preparation of financial statements in conformity with generally accepted accounting principles or any other criteria applicable to such statements and (2) to maintain accountability for assets.
  3. Access to assets is permitted only in accordance with management’s authorization.
  4. The recorded accountability for assets is compared with the existing assets at reasonable intervals and appropriate action is taken with respect to any differences.”

The SAS’s focus on creating and maintaining an accurate accounting for the use and disposition of assets in transactions makes clear that the objective of permitting “access to assets . . . only in accordance with management’s authorization” is concerned not with all corporate assets, but rather with assets of a particular character—those that are the subject of corporate transactions.

The asset at issue in the Order—RRD’s computer systems—does not have that essential characteristic. While RRD’s computer systems constitute an asset in the sense of being corporate property, computer systems are not the subject of corporate transactions. At most, computer systems process transactions in corporate assets, but the internal accounting controls are concerned with the use and disposition of the corporate assets themselves. The controls associated with the means of processing transactions in corporate assets are more appropriately categorized as administrative controls involving management’s decisions prior to authorizing transactions.

The Commission’s 2018 report related to the intersection of cybersecurity and internal accounting controls is consistent with this essential distinction between categories of administrative controls and internal accounting controls. For example, one of the schemes involved “using spoofed email domains and addresses” to entice “the companies’ finance personnel to cause large wire transfers to foreign bank accounts controlled by the perpetrators.” In another scheme, “[a]fter hacking the existing vendors’ email accounts, the perpetrators inserted [an] illegitimate request for payments (and payment processing details) into electronic communications” and sent the issuer “doctored invoices [that] reflected the new, fraudulent account information.” As a result, the issuer “made payments on outstanding invoices to foreign accounts controlled by the impersonator rather than the accounts of the real vendors.” The common thread in the schemes is that they involved access to corporate cash. The internal accounting controls were deficient not because the payment processing systems were the means to execute transactions disposing of corporate assets; the internal accounting controls were deficient because outside actors were able to access the corporate cash through fraudulent transactions. In other words, the payment processing systems implicitly were understood to be distinct from the cash itself, and the internal accounting controls were those controls directly related to the transactions that ended in the disbursement of cash.

The Commission’s order faulting RRD’s internal accounting controls breaks new ground with its expansive interpretation of what constitutes an asset under Section 13(b)(2)(B)(iii). By treating RRD’s computer systems as an asset subject to the internal accounting controls provision, the Commission’s Order ignores the distinction between internal accounting controls and broader administrative controls. This distinction, however, is essential to understanding and upholding the proper limits of Section 13(b)(2)(B)’s requirements.

Eliding the distinction between administrative controls and accounting controls has utility for the Commission. As this proceeding illustrates, a broad interpretation of Section 13(b)(2)(B) to cover computer systems gives the Commission a hook to regulate public companies’ cybersecurity practices. Any departure from what the Commission deems to be appropriate cybersecurity policies could be deemed an internal accounting controls violation. The Commission’s assurances in connection with the recent cyber-disclosure rulemaking ring untrue if the Commission plans to dictate public company cybersecurity practices indirectly using its ever-flexible Section 13(b)(2)(B) tool. Also concerning is the Commission’s decision to stretch the law to punish a company that was the victim of a cyberattack. While an enforcement action may be warranted in some circumstances, distorting a statutory provision to form the basis for such an action inappropriately amplifies a company’s harm from a cyberattack.”