When Seth Cohen began his career as a corporate finance analyst at Lehman Brothers, the internet had not yet evolved into a global phenomenon. That was about forty years ago, when floppy disks and dot-matrix printers were still the mainstream information technology tools.

Today, the internet is deeply embedded in the daily operations of businesses across the U.S. economy, serving as a major driver of growth and productivity while also presenting a range of challenges, including cybersecurity and even national security risks. Cohen, recently appointed CFO of DMK Pharmaceuticals, based in San Diego, California, considers this one of the most important issues facing modern financial leaders.

"Now, I think we are inseparable from the IT department," he said in an interview.

Cohen, 61, was appointed to the new role during an executive reshuffle aimed at quickly turning around sales of two struggling drugs: Zimhi, for opioid overdoses, and Symjepi, for acute allergic reactions. According to results released last month, the company's net income for the third quarter ended September 30 plummeted to just $9,062, compared to $1.5 million in the same period in 2022.

Beyond pressing financial issues, Cohen is also focused on ensuring the company complies with the new cybersecurity rules from the U.S. Securities and Exchange Commission (SEC). These require public companies to disclose any "material cybersecurity incident" to the agency via an 8-K filing within four days of determining that a significant cyber event has occurred.

These new rules, built on prior guidance, took effect in September, with enforcement beginning this month. As of December 18, all covered entities except smaller reporting companies must comply with the new breach disclosure requirements. Smaller reporting companies must comply by June 5 next year.

Since the rules were finalized in the summer, public companies have been busy ensuring they have appropriate policies and procedures in place to meet the requirements.

"I think December will be cybersecurity month at DMK," said Cohen, who served as director of pensions and public finance in the New York City Mayor's Office under Rudy Giuliani in the 1990s. "We will be ready."


"The stakes are high for CFOs because they could face charges from the SEC or other government regulators, as well as shareholder lawsuits and other private litigation."

c26dbb7f8ae5524841267a35b6468bcbecf9efd7dcf6efba56bf278ef43ecb45.png

Danette Edwards

Partner at Katten Muchin Rosenman LLP


Meanwhile, as companies prepare for the new rules, they have seen increased cybersecurity enforcement by the SEC and other federal agencies.

"The stakes are high for CFOs because they could face charges from the SEC or other government regulators, as well as shareholder lawsuits and other private litigation," said Danette Edwards, a partner at Katten Muchin Rosenman LLP and co-chair of the securities enforcement defense practice.

Pressure of expanding responsibilities

In recent years, the rapid escalation of cyber threats, along with associated costs, business risks, and regulatory requirements, has led to increasing pressure on the CFO's office.

"It's like adding one more thing to a pile of complexity—rising interest rates, talent shortages, and everything else," said Josh Schauer, finance vice president at insightsoftware, a Raleigh, North Carolina-based company that provides financial reporting and enterprise performance management software. "The past few years have been a wild ride."

As CFO Dive previously reported, responsibility creep has been a major source of pressure for CFOs, especially as their core tasks related to earnings reporting and finance have not diminished.

A 2022 survey by Datarails, a New York-based financial software company, found that a majority of CFOs (81%) believe they carry a more intensive daily workload compared to all C-suite peers.

"Years ago, the teams led by CFOs primarily prepared historical financial performance reports and set spending limits," said Steve Vintz, CFO of Tenable, a cybersecurity company based in Columbia, Maryland. "While that is still part of the role today, now CEOs, boards, investors, and others increasingly expect CFOs to be value-added business partners who can provide more business insights and help position the company best for success."

This trend shows no signs of slowing, especially as technology issues consume more and more of CFOs' time and energy.

In a Grant Thornton survey released in July, cybersecurity and digital transformation topped the list of areas where CFOs expect to increase spending over the next 12 months.

"I think cybersecurity is getting more attention because of its very real business impact," said Christopher Hodson, chief security officer at data security company Cyberhaven. "And I think it increasingly falls on CFOs because they are ultimately the ones trained in business risk."

MGM Resorts International disclosed in early October that it expected the cybersecurity breach it reported in September to impact the company's third-quarter financial results by approximately $100 million.

"We still believe the losses will be covered by our cyber insurance," MGM CFO Jonathan Halkyard said on an earnings call last month.

Rising cost of data breaches

According to a report released by IBM in July, the average global cost of a data breach between March 2022 and March 2023 was $4.45 million, a 15% increase over three years, reaching an all-time high. During the same period, detection and escalation costs jumped 42%, accounting for the highest proportion of breach costs, indicating more complex investigations.

Destructive attacks that rendered systems inoperable accounted for a quarter of all attacks, with another 24% involving ransomware—where criminals use malware to block a company from accessing its own computer files, systems, or networks until a ransom is paid. Such attacks can also involve threats to leak sensitive data to the public internet.

A White House report released in March designated ransomware as a national security threat. The document argued that some businesses have not done enough due diligence in combating cybercrime and called for regulatory measures, such as expanding minimum cybersecurity requirements in "critical areas."

"This strategy recognizes that strong collaboration, especially between the public and private sectors, is essential to securing cyberspace," President Joe Biden said in a statement in the report. "It also addresses the systemic challenge that too much of the responsibility for cybersecurity has fallen on individual users and small organizations."

In a high-profile case that drew SEC attention, software provider SolarWinds disclosed in 2020 that its Orion software platform had suffered a cyberattack. The attack, believed to be carried out by a Russian government-backed group, affected U.S. agencies, including parts of the Pentagon, the Department of Homeland Security, the State Department, the Department of Energy, the National Nuclear Security Administration, and the Treasury Department, as well as major private companies such as Microsoft, Cisco, Intel, and Deloitte, the Wall Street Journal reported.

The U.S. Government Accountability Office said the breach was "one of the largest and most sophisticated hacking campaigns ever conducted against the federal government and the private sector."

Risk of personal liability

In October, the SEC sued SolarWinds and its chief information security officer, Timothy Brown, accusing them of defrauding investors by misrepresenting the company's cybersecurity practices before the attack. The Austin, Texas-based company denied the allegations and vowed to defend itself in court.

"This case should serve as a wake-up call to all executives," said Tenable's Vintz.

During the agency's investigation, both Brown and the company's CFO, J. Barton Kalsu, were informed they could face charges. Although Kalsu was ultimately not named in the lawsuit, legal experts say this does not necessarily mean CFOs can easily escape liability in such cases.

"I think each case will be reviewed based on its specific facts," Edwards said. She said one way CFOs can reduce their risk of personal liability is by documenting the reasons for their decisions, such as denying a CISO's request for additional cybersecurity funding.

Cara Peterman, a partner in the securities litigation practice at Alston & Bird LLP, recommends personal risk mitigation strategies, such as: reviewing corporate bylaws and other company documents to ensure they provide the maximum indemnification allowed under the company's state of incorporation; reviewing directors' and officers' liability insurance policies to ensure adequate coverage; and establishing an ongoing relationship with the general counsel's office.

"Generally, you don't want to find yourself without that ongoing relationship and then suddenly have a breach, forcing you to discuss these issues for the first time in the midst of chaos," she said.