Legal analysts point out that the U.S. Supreme Court's recent ruling overturning the so-called "Chevron test" could have potential implications for the Biden administration's key regulatory actions in the cybersecurity field. This principle previously required courts to defer to federal agencies' interpretations of laws when statutory language was ambiguous.

In the absence of clear congressional authorization, the Federal Trade Commission (FTC) and the Securities and Exchange Commission (SEC) have adopted a relatively aggressive enforcement posture on cybersecurity issues in recent years, which has sparked discussions about "government overreach" in some cases. A typical example is that the FTC is considering drafting comprehensive rules covering data privacy and security under Section 18 of the Federal Trade Commission Act.

"Given this new ruling, if the FTC proceeds with this rulemaking, the likelihood of it being overturned by a court would significantly increase," said Daniel Kaufman, a partner at the law firm BakerHostetler, in an interview.

\n

In the case of "Loper Bright Enterprises v. Raimondo," the Supreme Court ruled 6-3 that courts do not need to defer to federal agencies' interpretations of laws merely because the statutes they enforce contain gaps or ambiguities.

"The Court's decision is not surprising, stemming from its dual commitment to textualist methods of interpretation and its continued departure from the Chevron principle in recent years," commented Scott Kimpel, a partner at the law firm Hunton Andrews Kurth, via email.

According to Michelle Kallen, a partner at Jenner & Block, the ruling could have significant implications for agencies such as the FTC and SEC that rely on older statutes to address modern policy issues like cybersecurity. "Part of the challenge is that Congress moves relatively slowly, especially when it comes to modern technology, so agencies try to find innovative ways to address these issues," Kallen said in an interview.

The FTC announced in August 2022 that it was studying the development of rules to combat "harmful commercial surveillance and lax data security practices." In the Advance Notice of Proposed Rulemaking at that time, the agency sought public comment on the necessity of such rules.

Although the FTC has long actively enforced data privacy and security laws, its role has been primarily limited to case-by-case enforcement under the broad prohibition on "unfair or deceptive acts or practices" in the Federal Trade Commission Act. According to a 2022 report by the Congressional Research Service, the Commission's plan to clarify specific data privacy and security requirements or prohibitions through rulemaking would be a "significant change."

To date, the agency has not made significant substantive progress on its rulemaking initiative.

Last month, a coalition of more than 30 public interest and advocacy groups called on the FTC in a letter: "You must act immediately to protect the general public, regardless of what federal data privacy protections Congress is discussing. We have waited long enough to stop deceptive and unfair use of data."

On the other hand, a group of Senate Republicans, including Florida Senator Marco Rubio, criticized the FTC's efforts in a November 2022 letter, urging the agency to "leave the task of developing data privacy and security rules to elected officials in Congress."

Congressional Republicans have also been critical of the cybersecurity rules adopted by the SEC last year. These rules, based on federal securities laws, require public companies to report to the SEC on Form 8-K (Item 1.05) within four business days after determining that a cyber incident is "material," along with meeting other related requirements.

"This cybersecurity disclosure rule is a complete overreach by the SEC and directly conflicts with congressional intent," said New York Representative Andrew Garbarino in November when announcing a House resolution aimed at overturning the rule. North Carolina Republican Senator Thom Tillis also introduced a companion resolution in the Senate.

The proposal has already faced a veto threat from President Joe Biden. The Office of Management and Budget stated the administration's position in a January 31 statement: "Overturning the SEC's rulemaking would not only disadvantage investors who deserve clear insight into the cyber risks inherent in their investments, but would also lead companies to underinvest in cyber programs, thereby harming our economy and national security."

Meanwhile, the SEC has been criticized for arguing in recent cases that cybersecurity failures can be considered violations of Section 13(b)(2)(B) of the Securities Exchange Act regarding "internal accounting controls." The latest example is that in June, the SEC announced that global business communications and marketing services provider R.R. Donnelley & Sons Co. agreed to pay approximately $2.1 million to settle charges that it violated Section 13(b)(2)(B) in its response to a 2021 ransomware attack.

The SEC also included similar allegations in its lawsuit against SolarWinds, a software vendor headquartered in Austin, Texas. That lawsuit is currently being heard in the U.S. District Court for the Southern District of New York. In February, the U.S. Chamber of Commerce and the Business Roundtable filed a joint amicus brief supporting SolarWinds' motion to dismiss the lawsuit. In the brief, the two industry groups stated that the Commission is increasingly using this provision to pursue companies that allegedly failed to comply with controls unrelated to the accuracy of financial statements. "By treating Section 13(b)(2)(B) as a mandate for general oversight powers, the SEC seeks to position itself as a super-enforcer of corporate conduct beyond the boundaries of federal securities laws," they wrote in the brief.