SEC Cyber Disclosure Charges Highlight Role of D&O Insurance to Mitigate Cyber Risks
Time 3 Minute Read
Categories: Cyber, D&O

Following an investigation involving public companies potentially impacted by the 2020 SolarWinds software compromise, the US Securities and Exchange Commission recently charged several companies with making materially misleading disclosures regarding cybersecurity risks and intrusions. The SEC’s enforcement is the latest example of “cyber as a D&O risk,” underscoring the importance of maintaining robust directors and officers (D&O) liability coverage, along with cyber insurance, as part of a comprehensive liability insurance program designed to respond to cyber incidents.

Background

On October 22, 2024, the SEC charged four current and former public companies with making materially misleading disclosures regarding cybersecurity risks and intrusions related to the 2020 SolarWinds Orion hack. The SEC specifically found that each company learned in either 2020 or 2021 that the threat actor behind the SolarWinds Orion hack had accessed their systems without authorization, but that the companies negligently minimized the cybersecurity incident in public disclosures. The companies did so, the SEC contends, by framing the relevant cybersecurity risk factors hypothetically or generically when they knew the warned of risks had already materialized.

The SEC concluded that each company had violated certain provisions of the Securities Act of 1933, the Securities Exchange Act of 1934 and related rules. Without admitting or denying the SEC’s findings, each company agreed to cease and desist from future violations of the cited provisions and to pay civil penalties ranging from $990,000 to $4 million.

Discussion

The recent SEC charges continue the trend of increased federal scrutiny by the SEC, DOJ and FTC following cybersecurity incidents. Individual directors and officers may also face personal liability, as regulators have targeted not just companies, but also individuals, in the wake of major cyber attacks. In 2022, for example, Uber’s former Chief Information Security Officer was criminally prosecuted and convicted by the FTC for failing to disclose a data breach during an ongoing investigation. More recently, the SEC’s far-reaching case against SolarWinds and its CISO was largely truncated in a highly-anticipated ruling earlier this year, but certain charges against the CISO were allowed to proceed.

Cyber insurance remains critical for protecting all companies from the fallout of a cyber incident—regardless of their particular industry or trade. But with the staggering cost of cybersecurity events ($9.48 million on average in the US), cyber insurance limits are often quickly eroded, if not exhausted entirely, in the immediate aftermath of a cyber event. Those risks, combined with continued increase in government investigations, enforcement actions and follow-on civil and criminal claims against both companies and individuals, make complementary D&O coverage even more critical to fill any gaps and respond to traditional D&O exposures that may arise following a cybersecurity incident.

From building a comprehensive cyber and D&O insurance program to ensuring that in-house cybersecurity professionals like CISOs do not fall through the cracks in traditional policies, we have previously outlined common pitfalls and best practices to consider in addressing these risks. Being proactive and consulting with insurance brokers, outside coverage counsel and other risk professionals at the time policies are negotiated, renewed and placed can help avoid unexpected denials and maximize the chance of recovery in the event of a claim.

  • Partner

    Andrea helps companies navigate disasters and swiftly recover insurance funds to restore operations with minimal impact to the bottom line. She leads the firm’s cyber insurance practice and serves as a firmwide hiring partner.

  • Partner

    Geoff works closely with corporate policyholders and their directors and officers to resolve high-stakes insurance disputes. He leads the firm’s directors and officers (D&O) insurance and executive protection practice.

    As a ...

You May Also Be Interested In

Time 4 Minute Read

Colleges and universities have long sat at the crossroads of freedom of expression and societal change. As campus activism surges, they face growing pressure to protect their institutional missions while upholding students’ individual rights in an era of heightened scrutiny.

Time 1 Minute Read

If recent years have taught insurance practitioners anything, it is that the most consequential coverage disputes rarely turn on novelty alone. In 2025, courts continued to resolve high‑stakes insurance disputes by returning to first principles—examining when claims are related, how losses and occurrences are defined and aggregated, and how policy language allocates risk across time and conduct. D&O coverage and other core insurance law issues again occupied center stage, while decisions in property, cyber, and liability disputes reinforced a familiar theme: policy interpretation remains the decisive factor in determining whether coverage is available in an increasingly complex claims environment. As the decisions discussed below demonstrate, 2025 confirmed that even as risks evolve, coverage disputes remain grounded in careful, policy‑specific analysis.

Time 6 Minute Read

Companies have long favored Delaware for business purposes for a multitude of reasons. One new reason to add to that list may be Delaware’s approach to coverage under directors and officers, errors and omissions, and other claims-made liability policies for costs incurred in responding to government investigations. Building upon prior pro-policyholder rulings, a Delaware court recently concluded that a DOJ civil investigative demand (CID) was a covered “Claim,” even where the policy expressly included other, more limited coverage targeting governmental investigation expenses.

Time 5 Minute Read

Directors and officers liability insurance is first and foremost protection against personal exposure of boards and management who are targeted in claims challenging their decisions in running the company. That’s why it is surprising how often dedicated “Side A” coverage—insurance coverage, subject to no self-insured retention, available exclusively for the benefit of directors and officers who are not indemnified by the company—is overlooked in placing and renewing D&O insurance programs. One recent Texas bankruptcy ruling, In re First Brands Group, LLC, No. 25-90399 (CML) (Bankr. S.D. Tex. Jan. 7, 2026), demonstrates just how powerful Side A protection can be. There, against strong objections from the creditors’ committee, the bankruptcy court granted motions by numerous former executives seeking relief from the automatic stay to recover D&O insurance proceeds, unlocking millions in Side A coverage to defend against private and governmental claims asserted in connection with the bankruptcy.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Authors

Archives

Jump to Page