Analysts point out that the U.S. Securities and Exchange Commission's (SEC) newly introduced cybersecurity disclosure rules may expose listed companies to a higher risk of class-action lawsuits, but a recent Supreme Court ruling is expected to temper this impact.

Earlier this month, the Supreme Court ruled inMacquarie Infrastructure Corp. v. Moab Partnersthat, under Section 10(b) of the Securities Exchange Act (which prohibits securities fraud), a mere omission of information required by the SEC to be disclosed does not itself constitute a basis for a private lawsuit. The 9-0 ruling, however, leaves room for claims based on "misleading half-truths."

"If the Macquarie case had been decided the other way, future plaintiff attorneys might have argued that companies failed to meet their obligations under the cyber rules merely by omitting rule-required information. Now, that path is unavailable in Section 10(b) cases," said Walker Newell, vice president of management liability at insurance brokerage Woodruff Sawyer, in an email.

In that case, shareholder plaintiffs accused Macquarie Infrastructure of securities fraud for failing to disclose a change in an international regulation, as the company was required to report "known trends and uncertainties" under Item 303 of SEC Regulation S-K.

In 2021, the U.S. District Court for the Southern District of New York dismissed the case for failure to state a claim. The Second Circuit Court of Appeals reversed that ruling, holding that the company had an obligation to disclose the international regulatory change under Item 303 and that the omission alone could support a securities fraud claim.

The Supreme Court disagreed.

"We hold that a failure to disclose information required by Item 303 can support a claim under Rule 10b-5(b) only if the omission renders affirmative statements misleading," the unanimous opinion, written by Justice Sonia Sotomayor, stated.

Although the case involved Item 303, analysts say it has implications for other disclosure obligations under Regulation S-K, including those related to cybersecurity risk management and climate change.

"If the court had ruled the other way—that is, in favor of the plaintiffs here—the impact could have been significant," said Kevin LaCroix, vice president and attorney at RT ProExec, a division of specialty insurance services firm RT Specialty, in an email.

Given the remaining liability risks, Scott Kimpel, a partner at Hunton Andrews Kurth LLP, believes listed companies should remain vigilant when drafting investor communications, including cybersecurity disclosures.

"This unanimous opinion is a welcome relief for the issuer community, but the court carefully limited the scope of its opinion and left alternative liability theories for pure omissions," he said in an email.

LaCroix also warned that even if a violation of Regulation S-K alone is insufficient to support investor claims, the SEC still has the authority to bring enforcement actions against reporting companies for violating its rules.

"One concern is that, given this ruling, reporting companies might be inclined to stay silent on cybersecurity issues, despite the SEC's cybersecurity disclosure guidance. That would be an unwise strategy for companies, and I think few will follow it," he said.

Under thenew cybersecurity rulesadopted by the SEC last year, companies must determine the materiality of an incident "without unreasonable delay" after discovering it, and if deemed material, generally must file an Item 1.05 Form 8-K within four business days of that determination, as stated in the ruling.

Companies must also annually describe in Form 10-K the board's oversight of cybersecurity risks.

The new rules are expected to subject listed companies to stricter scrutiny from both the SEC and plaintiff attorneys.

"Inadequate or misleading disclosures could lead to allegations of securities law violations, such as misstatements or omissions of material information, thereby laying the groundwork for securities class actions," wrote Ethan Collins, a risk consultant at insurance brokerage Hylant Group, in ablog postlast month.

Priya Cherian Huskins, senior vice president at Woodruff Sawyer, predicted in an August 2023blog postarticle

that plaintiff attorneys would "scrutinize" incident disclosures for opportunities to file lawsuits. "We should also expect them to attempt to challenge the truthfulness of any company's risk management and governance disclosures made before a cyber event, whether through securities litigation or breach of fiduciary duty claims," Huskins wrote.

Despite the Supreme Court's ruling in Macquarie, Newell said he still expects plaintiffs to carefully review listed companies' disclosures.

"This will include reviewing 10-K risk disclosures and attempting to argue that a company's description of its cyber program was misleading due to omissions, given vulnerabilities revealed after the incident," he said.