Just a few days ago, a state-linked hacking group claimed responsibility for a disruptive cyberattack on a Fortune 500 medical technology company with no ransom demand and no negotiation, calling it retaliation for a U.S. military strike. The risk of this type of politically-motivated cyberattack may increase given the increasingly volatile geopolitical environment. To combat this, the President recently signed an executive order targeting cybercrime carried out by transnational criminal organizations, aimed at improving federal coordination in combatting cybercrime. Now is an important time for boards and management teams to focus on crisis and risk management, including durable operational resilience planning. This alert provides perspectives about current best practices on incident preparedness in the face of such threats, explains how this preparedness can be supplemented by an operational resilience framework, discusses the practical implications of the executive order, and lays out a governance hygiene checklist to guide your next cybersecurity oversight discussion.Continue Reading Cybersecurity in the Age of Cyber Warfare: Governance Reminders for Public Company Boards
Synne D. Chapman
Synne D. Chapman’s practice focuses on domestic and international corporate and financial transactions, particularly capital markets transactions, disclosure, and corporate governance.
SEC Announces Changes to Rule 14a-8 No-Action Letter Process
The SEC’s Division of Corporation Finance just announced that it will largely step back from the shareholder proposal no-action letter process for the current proxy season (October 1, 2025 – September 30, 2026). The Division cited three reasons: resource constraints following the recent government shutdown, a high volume of registration statements competing for staff attention, and the extensive existing body of guidance already available to companies and proponents. The announcement aligns with the deregulatory approach we flagged in September when discussing potential reforms to the shareholder proposal process under the current SEC.Continue Reading SEC Announces Changes to Rule 14a-8 No-Action Letter Process
New SEC Disclosure Rules for Cybersecurity Incidents and Governance and Key Takeaways
On July 26, 2023, the U.S. Securities and Exchange Commission (the “SEC” or “Commission”) adopted rules to enhance and standardize disclosure requirements related to cybersecurity incident reporting and cybersecurity risk management, strategy, and governance.Continue Reading New SEC Disclosure Rules for Cybersecurity Incidents and Governance and Key Takeaways