SEC fines NYSE parent Intercontinental Exchange $10 million for failing to promptly report cyberattack
The U.S. Securities and Exchange Commission (SEC) announced that Intercontinental Exchange (ICE) agreed to pay a $10 million fine to settle charges that it caused nine wholly-owned subsidiaries, including the New York Stock Exchange, to violate cybersecurity reporting rules. The issue stemmed from April 2021, when ICE personnel failed to report a cyber intrusion to the SEC within 24 hours, instead taking four days to assess before internally determining the impact was minor. SEC Enforcement Director Gurbir S. Grewal emphasized that for critical market intermediaries, "every second counts" in cybersecurity incidents, and "four days can be an eternity." ICE responded that the incident was an unsuccessful cyber access attempt three years ago with zero impact on market operations, and the dispute centered on the reporting timeline. Two SEC commissioners, Hester Peirce and Mark Uyeda, criticized the fine as an "overreaction."

News Flash Summary
- Intercontinental Exchange has agreed to pay a $10 million fine to settle charges brought by the U.S. Securities and Exchange Commission (SEC). The SEC announced on Wednesday that ICE caused nine of its wholly owned subsidiaries, including the New York Stock Exchange it owns, to violate regulations requiring them to notify the SEC within 24 hours of discovering a "cyber intrusion," unless they could immediately determine that the incident had no impact or only a "de minimis" impact on operations or market participants.
- The matter stems from an incident in April 2021. According to the SEC's order, after ICE personnel determined that a "threat actor" had inserted malicious code into a virtual private network device used for remote access to the company's network, they did not notify their subsidiaries' legal and compliance officers. Instead, they spent four days assessing the impact and internally concluded it was a minor incident.
- "The respondents in today's enforcement action include the world's largest stock exchange and numerous other well-known intermediaries, which, given their roles in the market, are subject to strict reporting requirements when they experience cyber incidents," said Gurbir S. Grewal, Director of the SEC's Division of Enforcement, in a statement. "In cybersecurity, especially for incidents at critical market intermediaries, every second counts, and four days can be an eternity."
In-Depth Analysis
The settlement reveals the monetary costs of cyber threats, including fines for failing to comply with regulations requiring timely disclosure.
With new SEC rules recently taking effect, the regulatory compliance burden after cyberattacks is also increasing. The new rules require companies to determine the materiality of a cybersecurity incident "without unreasonable delay" after discovering it, and if deemed material, they generally must file an Item 1.05 Form 8-K within four business days of that determination.
In the ICE case, under Regulation Systems Compliance and Integrity (Regulation SCI), subsidiaries were required to immediately notify the SEC if they could not immediately determine that a cyber intrusion had a de minimis impact. Under that rule, subsidiaries must immediately contact SEC staff and report the issue, and unless they can determine the impact is minor, they must provide an update within 24 hours. Because ICE failed to inform its subsidiaries of the incident, the subsidiaries failed to comply with the rule.
In an emailed statement to CFO Dive, an ICE spokesperson said the settlement relates to "an unsuccessful attempt to access the network three years ago. That attempted intrusion had zero impact on market operations. The dispute centered on the reporting timeline for such incidents under Regulation SCI."
The fine drew criticism from SEC commissioners Hester Peirce and Mark Uyeda, who expressed opposition in statements on the SEC's website. "Entities subject to Regulation SCI should comply with the rule's notification requirements and report SCI events to the Commission; however, imposing a $10 million civil penalty on ICE because a subsidiary failed to notify the Commission of an isolated, de minimis event is an overreaction. Unfortunately, such responses are increasingly common in the Commission's enforcement actions."
Without admitting or denying the SEC's findings, ICE and its subsidiaries, including Archipelago Trading Services, the New York Stock Exchange, NYSE American, NYSE Arca, ICE Clear Credit, ICE Clear Europe, NYSE Chicago, NYSE National, and the Securities Industry Automation Corporation, agreed to cease-and-desist orders, and ICE also agreed to pay the fine.