The SEC Continues To Push The Internal Controls Envelope

June 19, 2024

To push the envelope means to surpass normal limits or attempt something viewed as radical or risky.

The FCPA’s enforcement agencies (the DOJ and SEC) have long pushed the envelope and enforcement agency officials may think – why not – a risk averse company is often going to cough up millions of dollars just to make us go away regardless of the underlying enforcement theory.

As highlighted in this prior post, in November 2023, Charter Communications agreed to cough up $25 million in a non-FCPA, FCPA enforcement action in which the SEC found that the company violated the FCPA’s internal controls provisions in connection with stock buybacks.

Prior to this, in October 2023 the SEC charged SolarWinds with, among other things, FCPA internal controls violations in connection with cybersecurity issues in another non-FCPA, FCPA enforcement action. (See here for the prior post). SolarWinds is contesting the SEC’s theory of enforcement. (See here for a summary of the recent motion to dismiss hearing).

In the latest example of the SEC continuing to push the internal controls “envelope,” the SEC announced yesterday that R.R. Donnelley & Sons Company (RRD), a global provider of business communication and marketing services, agreed to pay over $2.1 million to settle disclosure and internal control failure charges relating to cybersecurity incidents and alerts in late 2021.

In summary fashion, this administrative order finds:

“This matter concerns violations by RRD of the Exchange Act’s disclosure controls and procedures and internal accounting control provisions relating to its cybersecurity practices between November 2021 and January 2022 (the “Relevant Period”). Throughout the Relevant Period, RRD failed to design effective disclosure controls and procedures as defined in the Exchange Act rules related to the disclosure of cybersecurity risks and incidents. RRD also failed to devise and maintain a system of cybersecurity-related internal accounting controls sufficient to provide reasonable assurances that access to RRD’s assets – its information technology systems and networks, which contained sensitive business and client data – was permitted only with management’s authorization. Due to RRD’s business of storing and transmitting large amounts of data, including sensitive data, information technology and cybersecurity are critically important to RRD. As a result of these internal accounting controls deficiencies, RRD failed to execute a timely response to a ransomware network intrusion that occurred between November 29, 2021 and December 23, 2021, which culminated in encryption of computers, exfiltration of data, and business service disruptions.”

Under the heading “RRD’s Failure to Maintain Sufficient Internal Accounting Controls and Disclosure Controls and Procedures,” the order states in pertinent part:

“RRD failed to reasonably design and maintain internal controls that complied with [the FCPA’s internal controls provisions]. Namely, as discussed above, RRD’s cybersecurity alert review and incident response policies and procedures failed to adequately establish a prioritization scheme and to provide clear guidance to internal and external personnel on procedures for responding to incidents. In addition, RRD failed to establish sufficient internal controls to oversee the MSSP’s review and escalation of the alerts.

During the 2021 ransomware incident, RRD’s failure to design and maintain internal controls sufficient to provide reasonable assurances that access to RRD’s assets was permitted only with management’s authorization was exploited by hackers. While RRD’s internal systems began issuing alerts on the first day of the compromise, approximately three weeks before any encryption and exfiltration of data took place, RRD’s external and internal security personnel failed to adequately review these alerts and take adequate investigative and remedial measures until a company with shared access to RRD’s network notified RRD about anomalous internet traffic on December 23, 2021.”

Based on the above, the order finds that RRD violated, among other things, the FCPA’s internal controls provisions.

Without admitting or denying the SEC’s findings, RRD agreed to pay a $2.125 million civil penalty.