Skip to Main Content

A Deeper Dive: The SEC Cybersecurity Rule Enforcement Landscape

09/16/2025 | 2 minute read

Posted in DSIR

As readers of our 2025 Data Security Incident Response (DSIR) Report are aware, many organizations were concerned about complying with the Securities and Exchange Commission’s (SEC) cybersecurity rules given the SEC’s enforcement priority prior to the 2024 election. Following the election and subsequent court decisions, the SEC experienced meaningful challenges to its enforcement authority – in particular, the commission saw its enforcement authority under the rules challenged in the Solar Winds litigation, with the majority of the SEC’s claims dismissed by a trial court. Thus far in 2025, there have been no publicly disclosed enforcement actions initiated by the SEC under the cyber rules.

Additionally, the SEC’s actions thus far in 2025 presage a reversal in its position on the 2023 cybersecurity rules. This year, the SEC has:

  • Announced a shift in priorities for a rebranded and reorganized cyber enforcement team
    The creation of the Cyber and Emerging Technologies Unit under Acting Chair Mark Uyeda was accompanied by an announcement noting areas of focus that included “Public issuer fraudulent disclosure relating to cybersecurity,” indicating a possible move by the commission toward enforcement actions premised on traditional scienter-based fraud and away from targeting disclosures meeting a lower, and more controversial, negligence standard.
  • Settled the remainder of the Solar Winds litigation
    In early July, the SEC announced that it had reached a settlement in the litigation against Solar Winds and its chief information security officer, Timothy Brown. The matter might otherwise have gone to trial to address the SEC’s allegations that a public-facing statement regarding Solar Winds’ security posture was materially misleading and long known to be false by Brown and Solar Winds.
  • Withdrawn the 2023 proposed cybersecurity risk management rules
    In June, the SEC announced the withdrawal of cybersecurity risk management rules for investment advisers, broker-dealers and other securities market participants. These proposed rules contained many elements like those in the fully implemented 2023 rules

As noted in our 2025 DSIR Report, Form 8-K filings stemming from cybersecurity breaches remain rare among the firm’s clients, with less than 1 percent of the firm’s matters leading to disclosures in 2024. Overall, filings have declined as well: Between January and July, there have been seven 8-K Item 1.05 filings; there were 19 during the same period in 2024. This seems consistent with the SEC’s current guidance and lessened levels of concern among registrants about enforcement risk.

It is worth bearing in mind that current commissioners Uyeda and Hester Peirce have been consistent in their objections to the cyber breach rules, with regard to both the rule promulgation process and their enforcement, since 2023. In 2025, prospects of the implemented 2023 rules surviving significant revision, or avoiding a complete repeal, continue to dim. Regulated entities have stepped up lobbying over the past several months to achieve this end, and on March 31 the House Financial Services Committee urged the SEC to repeal the rules.

From a cybersecurity governance perspective, our guidance for managing risk and implementing a defensible process remains the same as outlined in our 2025 DSIR Report.