SEC fined RR Donnelley $2.1 million for hacker incident, criticized for overstepping authority
The U.S. Securities and Exchange Commission (SEC) fined RR Donnelley approximately $2.1 million, alleging violations of Section 13(b)(2)(B) of the Securities Exchange Act for failing to establish and maintain internal accounting controls related to cybersecurity. The case stems from a ransomware attack in 2021. Legal experts believe that the SEC's action represents an expansive interpretation of the provision, potentially exceeding congressional intent, and has sparked controversy over regulatory boundaries.

Legal analysts point out that the U.S. Securities and Exchange Commission (SEC) is attempting to more aggressively assert jurisdiction over cybersecurity-related matters by relying on a broad interpretation of a provision in the regulations it enforces.
The provision is Section 13(b)(2)(B) of the Securities Exchange Act, which requires public companies to maintain internal accounting controls. In recent years, the SEC's interpretation and application of this provision have continued to expand, drawing criticism from multiple quarters.
In the latest case, the SEC announced last week that R.R. Donnelley & Sons Co., a global provider of business communications and marketing services, agreed to pay approximately $2.1 million to settle allegations that it violated Section 13(b)(2)(B) by failing to "design and maintain a system of internal accounting controls related to cybersecurity." The allegation stemmed from the company's response to a ransomware attack in 2021.
"As the SEC's dissenting commissioners noted, this is arguably an aggressive expansion of the SEC's use of this provision," said Charu Chandrasekhar, a partner in the securities enforcement practice at Debevoise & Plimpton LLP, in an interview. "I think applying this provision to cybersecurity systems is inconsistent with the legislative purpose of the provision and its historical context of application."
According to a memo released last Friday by Sullivan & Cromwell LLP, this enforcement action is the latest assertion of jurisdiction by the SEC under Section 13(b)(2)(B) to penalize alleged failures that did not affect financial reporting or accounting controls.
The memo also noted that this case marks the second time the SEC has used this provision to address cybersecurity vulnerabilities. The first case, against SolarWinds, an Austin, Texas-based software provider, is currently pending in the U.S. District Court for the Southern District of New York.
"Given that challenges to the SEC's expansive interpretation of jurisdiction under Section 13(b)(2)(B) in the SolarWinds case remain unresolved, whether the SEC's use of this provision to penalize companies victimized by cybercrime can withstand judicial scrutiny remains to be seen," the memo stated.
Over the past few years, the SEC has been intensifying its cybersecurity enforcement and regulatory efforts.
Last October, the Commission sued SolarWinds and its Chief Information Security Officer, Timothy Brown, alleging that they misled investors by misrepresenting the company's cybersecurity practices before the discovery of a significant vulnerability in December 2020. SolarWinds was also charged with violating the reporting and internal control provisions of the Exchange Act. The company has denied the allegations.
Meanwhile, in December of last year, the SEC began enforcing new rules requiring public companies to disclose information about cybersecurity incidents within four days of determining that they are "material." These rules build on earlier agency guidance. At the time, Erik Gerding, Director of the SEC's Division of Corporation Finance, stated that the agency did not seek to "prescribe specific cybersecurity defenses, practices, technologies, risk management, governance, or strategies."
A blog post published last Thursday by the law firm Debevoise & Plimpton LLP noted that the SEC's latest action directly conflicts with Gerding's statement.
Mark Schonfeld, a litigation partner at Gibson, Dunn & Crutcher LLP, said in an interview that the SEC's interpretation of Section 13(b)(2)(B) in this case places the agency in a position of "essentially judging or questioning the strength and adequacy of a company's cybersecurity controls."
"I think there is a real question here: Is this what Congress intended when it passed the internal accounting controls provision?" he said.
Schonfeld believes another issue with the case is that it creates regulatory uncertainty.
"This enforcement action provides no guidance on what constitutes adequate cybersecurity controls," he said.
Under Section 13(b)(2)(B), public companies must design and maintain a system of internal accounting controls sufficient to provide "reasonable assurances" that access to company assets is permitted "only in accordance with management's general or specific authorization."
Nicole Friedlander, a partner in the criminal defense and investigations group and co-head of the cybersecurity practice at Sullivan & Cromwell LLP, said that based on the SEC's interpretation of the regulation, the agency could penalize any company that suffers a cybercrime.
"The SEC believes that assets are anything a company owns or holds, including computer systems," Friedlander said in an interview. "So, if someone accesses those assets without management authorization, the SEC can say the company violated federal securities laws."
According to the SEC order resolving the case, R.R. Donnelley failed to respond in a timely manner to a ransomware attack that occurred between November 29 and December 23, 2021.
The order stated that the threat actors used "deceptive hacking techniques" to install encryption software on some of R.R. Donnelley's computers and stole 70 gigabytes of data, including data belonging to 29 of the company's 22,000 customers, with some of the data containing personally identifiable information and financial information.
However, the company's investigation found no evidence that the threat actors accessed financial systems or the company's financial and accounting data.
According to the Commission's order, R.R. Donnelley failed to design effective disclosure controls and procedures related to cybersecurity incidents to ensure that relevant information was communicated to management to enable timely decisions regarding required disclosures.
The SEC stated that the company also failed to "reasonably design and maintain internal controls consistent with Section 13(b)(2)(B) of the Exchange Act." Specifically, the company's cybersecurity alert review and incident response policies and procedures "failed to adequately establish a prioritization scheme and did not provide clear guidance to internal and external personnel on incident response procedures."
Jorge Tenreiro, Acting Director of the SEC's Crypto Assets and Cyber Unit, said in a press release: "The Commission brought this enforcement action because RRD's controls for escalating cybersecurity incidents to management and protecting the company's assets from cyberattacks were inadequate. That said, RRD did cooperate with the investigation in a meaningful way, which is reflected in the settlement terms."
Without admitting or denying the SEC's findings, R.R. Donnelley agreed to pay a $2.1 million civil penalty and to cease and desist from violating Section 13(b)(2)(B) of the Exchange Act and Rule 13a-15(a) under the Exchange Act, which requires public companies to maintain disclosure controls and procedures.
Two Republican SEC commissioners, Hester Peirce and Mark Uyeda, issued a joint dissenting statement opposing the agency's action.
"The Commission's order faults RRD's internal accounting controls, breaking new ground with its expansive interpretation of 'assets' under Section 13(b)(2)(B)(iii)," the two commissioners stated.
Broadly interpreting the provision to cover computer systems "provides the Commission with a hook to regulate public companies' cybersecurity practices," they said.
An SEC spokesperson declined to comment. R.R. Donnelley did not immediately respond to a request for comment.