August 22, 2023

The Upcoming Proxy Disclosure Conference: My Conversation with Erik Gerding

You can get all of the latest insights by joining me on Wednesday, September 20 for my interview with Erik Gerding, Director of the SEC’s Division of Corporation Finance. Erik will share his views on the latest developments and priorities for the Corp Fin Staff, and his expectations for the upcoming proxy season. We are very fortunate to have Erik joining us for the “2023 Proxy Disclosure Conference” given all that is going on at the SEC right now. My interview with Erik is a great way to kick off three days of drilling down on all of the things you need to know for your SEC disclosures and executive compensation matters in these turbulent times.

You know the drill by now – our “Proxy Disclosure & 20th Annual Executive Compensation Conferences” are coming up virtually September 20-22nd. Register online today through our membership center or by emailing sales@ccrcorp.com. Or, you can call us at 800-737-1271. Don’t forget that the “2023 Practical ESG Conference,” which is taking place on September 19, can be conveniently bundled with the “Proxy Disclosure & 20th Annual Executive Compensation” Conferences.

– Dave Lynn

August 21, 2023

Cybersecurity Disclosure Rules: Don’t Panic!

While the SEC’s adoption of cybersecurity disclosure requirements last month was a long time in the making, that actual adoption of the rules and the relatively short compliance deadlines seems to have prompted some level of panic at public companies. Based on how the final rules came out, I hope to offer some reassuring words that your path to compliance with these requirements can build on your pre-existing efforts rather than recreating the wheel. To that end, I ask and answer some of the questions that have been emerging about the new rules. Please read them and take a few deep breaths.

Do I need to create new disclosure controls for Item 1.05 of Form 8-K?

Companies will be required to disclose, within four business days after determining that an incident is material pursuant to new Item 1.05 of Form 8-K (subject to limited exceptions), any cybersecurity incident that a company experiences that is determined to be material, describing the material aspects of its: (i) nature, scope, and timing; and (ii) the impact or reasonably likely impact of the incident on the company, including on the company’s financial condition and results of operations.

The disclosure controls necessary to escalate cybersecurity incidents and evaluate whether they are material and must be disclosed should already be in place at public companies. The SEC’s 2018 interpretive release strongly encouraged the filing of a Form 8-K when a cybersecurity incident is determined to be material, and subsequent SEC enforcement cases focused on the timing of current disclosure about cybersecurity incidents and the disclosure controls that were in place to facilitate that disclosure. As a result of these developments, companies have implemented procedures to identify cybersecurity incidents, escalate them to management, and have management evaluate the materiality of those incidents to determine whether they must be disclosed. Item 1.05 of Form 8-K now formalizes the Form 8-K filing requirements and assigns a four-business-day deadline to the disclosure obligation.

For foreign private issuers, not much has changed in terms of the current disclosure framework. The SEC did amend General Instruction B of Form 6-K to reference material cybersecurity incidents in the list items that may trigger a current report on Form 6-K. The SEC notes in the adopting release that, “for a cybersecurity incident to trigger a disclosure obligation on Form 6-K, the registrant must determine that the incident is material, in addition to meeting the other criteria for required submission of the Form.”

The new disclosure obligation may require some fine tuning to pre-existing disclosure controls and procedures to reflect the disclosures that must be provided in response to the new Form 8-K item, as well as the process for tracking whether the Item 1.05 Form 8-K must be amended to reflect information that is not determined or is unavailable at the time of the required initial filing. Further, companies will need to assess whether the controls will facilitate a Form 8-K filing within four business days of determining that the incident is material.

Spoiler alert: In the vast majority of cybersecurity incidents that I deal with in my practice, it is ultimately concluded that the cybersecurity incident is not material under established standards for evaluating materiality. As a result, I do not expect to see a flood of Item 1.05 Form 8-Ks streaming into the SEC after the December 18, 2023 compliance date.

Should my approach to determining whether a cybersecurity incident is material change?

The approach to materiality is the same as it has always been. The SEC did not adopt any bright lines to be applied in determining whether an incident is material and therefore must be disclosed under new Item 1.05 of Form 8-K, leaving it to us to apply established standards of materiality. Consistent with past pronouncements, the Commission has indicated that the materiality standard that companies should apply in evaluating whether a Form 8-K would be triggered under Item 1.05 would be consistent with the caselaw standards that we are familiar applying in this context.

For the purpose of evaluating whether a Form 8-K is required to be filed pursuant to Item 1.05 of Form 8-K, information about a cybersecurity incident is considered “material” if there is a substantial likelihood that a reasonable investor would consider it important in making an investment decision or if the information would have been viewed by the reasonable investor as having significantly altered the “total mix” of information made available to the investor. As part of a materiality analysis, the company should consider the indicated probability that an event will occur and the anticipated magnitude of the event in light of the totality of company activity. No single fact or occurrence is determinative as to materiality, which requires an inherently fact-specific inquiry.

I advise that it is best to create your framework for evaluating the materiality of cybersecurity incidents ahead of time, and test that framework when you conduct tabletop exercises or otherwise evaluate your incident response plan. Once you have the framework sorted out and documented, then I don’t think it is necessary to document your specific evaluation of individual incidents, unless that is something that you would normally do in your Form 8-K process.

Do I need to change my board and management practices regarding cybersecurity?

While it is certainly always a good idea to evaluate your board and management practices around the oversight and management of cybersecurity risks to always put your best foot forward on this topic, nothing about the new disclosure requirements should necessarily drive a revamp of the company’s approach. In the adopting release, the SEC notes “that the purpose of the rules is, and was at proposal, to inform investors, not to influence whether and how companies manage their cybersecurity risk.” As originally proposed, the disclosure requirements could be read as normative standards for board oversight and management involvement, but in the final rules the SEC has taken a much more principles-based approach. Based on this pivot, one might expect to see a few paragraphs about cybersecurity risk management, strategy, and governance in upcoming Form 10-Ks rather than pages of disclosure. And those paragraphs are going to be pretty high level in terms of their description of the process, as even the SEC does not want companies to hand threat actors the “keys to the kingdom” through their Form 10-K disclosure. At this point, the best approach is to begin drafting the required disclosure so you can evaluate whether there are any areas that you want to shore up before going live in your Form 10-K.

Do the new rules supersede the SEC’s past guidance?

While some aspects of the 2018 interpretive guidance have now been incorporated into SEC’s rules (in particular the construct for current reporting on Form 8-K), companies still must consider that guidance in determining what to disclose under items that were not amended with this latest rulemaking effort, including: (i) risk factors; (ii) legal proceedings; (iii) MD&A; (iv) financial statements; (v) effectiveness of disclosure controls and procedures; and (vi) corporate governance (including disclosure in the proxy statement).

Don’t forget that we will be giving practical action items for these new rules at our “Proxy Disclosure & 20th Annual Executive Compensation Conferences” – coming up virtually September 20-22nd. Register online today through our membership center or by emailing sales@ccrcorp.com. Or, you can call us at 800-737-1271. You can also find the latest guidance on the new cybersecurity disclosure requirements in our “Cybersecurity/Privacy Rights/Security Breaches/Data Governance” Practice Area on TheCorporateCounsel.net. If you are not a member of TheCorporateCounsel.net, sign up today!

– Dave Lynn

August 21, 2023

Cybersecurity Enforcement: The Trends to Watch

The SEC’s Division of Enforcement has conducted a lot of investigations of cybersecurity incidents in recent years, but it is important to keep in mind that there have been only four Enforcement actions brought against companies in the five years since the 2018 interpretative release.

Here are some of the notable takeaways from those actions:

1. The four actions focus on material misstatements and omissions regarding cyber incidents and deficiencies in cybersecurity disclosure controls and procedures.

2. Three of the four actions involve negligence charges stemming from materially misleading disclosures and omissions regarding cybersecurity incidents and risks, but not intentional or reckless fraud.

3. All four actions involve charges related to deficiencies in disclosure controls and procedures.

4. These actions all involve unauthorized access and/or theft of sensitive personally identifiable information.

5. The companies that were the subject of these actions settled to administrative charges on a “neither admit nor deny” basis.

The SEC does have ongoing investigations of cybersecurity incidents, including those related to the Solarwinds breach, and I do expect that we will continue to see the SEC bring actions based on the old interpretive guidance and pre-existing requirements even when the new rules go into effect.

– Dave Lynn

August 21, 2023

Looking Forward to Our Conferences: My Take

Well folks, we are less than a month away from our September conferences, and that means I am going to be spending my week on the blog reminding you of why you need to sign up for this big event. Today I am going to focus on the “2023 Practical ESG Conference,” which takes place virtually on Tuesday, September 19, 2023.

The 2023 Practical ESG Conference will deliver usable, practical guidance on current ESG developments in a candid and conversational format. We have assembled an extraordinary group of speakers and you will not want to miss any of these sessions:

• ESG Hot Topics – Forewarned is Forearmed
• What your DEI Leader Wants You to Know
• Your Evolving Climate Disclosure: Data Perils & Protections
• Anti-ESG: Practical Steps to Navigate the Crosshairs
• The Great Debate: Does DEI Belong in HR, ESG, or Somewhere Else?
• Greenwashing 2.0: New Ways to Tackle Your Company’s ESG Embellishments
• ESG Oversight: How to Protect Your Board & Audit Committee From a Litany of Risks

I am particularly looking forward to joining a great group of panelists – Doug Parker from Ecolumix, Mark Trexler from The Climate Web and Kristina Wyatt from Persefoni – for the panel “Your Evolving Climate Disclosure: Data Perils & Protections.” This panel will provide an overview of top concerns on GHG data collection, validation and management and how you can reduce your reporting risk.

The “2023 Practical ESG Conference” can be conveniently bundled with the “Proxy Disclosure & 20th Annual Executive Compensation” Conferences. With all that is going on, this is definitely the year to participate in our Conferences – you do not want to miss all of the insights that our incredible group of speakers bring to the table. Sign up today!

– Dave Lynn

August 18, 2023

Inflation: Corp Fin Wants Detail and Quantification in MD&A

Bloomberg recently reported that inflation has been a hot topic in SEC comment letters — particularly the depth and detail of the discussion of inflation in MD&A. That shouldn’t come as a surprise — for one, it had been a long while since we’ve really had to flex our MD&A disclosure muscles when it comes to inflation. But also, just before inflation became a problem for the first time in a long time in the US, the SEC amended Item 303 of Regulation S-K to remove the express requirement to address the impact of inflation on the basis that other MD&A requirements would require a discussion of material inflationary impacts (for example, as a known trend or uncertainty or to explain material changes in line items from period to period). The 2020 Proposing Release for the MD&A amendments stated that a specific reference to inflation and changing prices “may give undue attention to the topic.” But here we are in an environment where attention is deserved.

Cooley’s Cydney Posner pulled recent comment letters on the topic and, in this post, shared additional color & sample comments:

In regular comments on SEC filings to a diverse mix of companies, Corp Fin has asked companies to discuss in more detail the impact of inflationary pressures, including at times, with quantification.  From a quick EDGAR search, I found, for example, a comment from Corp Fin related to a risk factor that discussed inflation, asking the company to “update this risk factor in future filings if recent inflationary pressures have materially impacted your operations. In this regard, identify the types of inflationary pressures you are facing and how your business has been affected.”

In another case, where a company disclosed that its costs of necessary commodities, labor, energy and other inputs had significantly increased and were expected to continue to affect the business, the staff asked for more detail, requesting that the company revise its disclosure to quantify the impact of inflation, including providing year-over-year comparisons of the impact, and provide more detail regarding the company’s efforts to offset cost pressures through price increases, including the success of those efforts. In another instance, commenting on MD&A disclosure that inflation had negatively affected results of operations as a consequence of increased cost of sales and operating expenses, Corp Fin asked the company to “quantify and disclose the impact of the inflationary pressures you are experiencing on cost of sales, gross margins and operating expenses,” quantifying increases in transportation and fuel costs, materials, commodities and packaging costs, as well as production inefficiencies and geographical sales mix.

Another comment asked a different company to expand on how the impact of higher rates of regional inflation and raw material supply in certain regions affected the company’s operations, potentially affecting its operating segment analysis. In yet another example, the staff observed that when the financials reflect material changes from period-to-period in one or more line items, or where material changes within a line item offset one another, the company is still required to describe the underlying reasons in quantitative and qualitative terms. The staff then asked the company to “quantify the impact of each factor or component associated with material changes, including the impact of inflation associated with any material changes.”

Inflation was already a trending comment letter topic in 2022 when it was at its peak, but comments seemed to focus more on risk factors and, in particular, the ever-important-to-avoid hypothetical risk factor trap. Cydney notes that these comments — now MD&A focused — are still coming, even as inflation slows.

– Meredith Ervine

August 18, 2023

Beware! Emojis May Also be Fraud

John recently blogged that emojis can create binding contracts and advised us to think long and hard before clicking “send” on that email or text with a cute little emoji. In fact, you may want to cut out emojis completely — at least in your professional life — especially if you’re a public figure. This Bryan Cave blog discusses a recent U.S. District Court decision rejecting a motion to dismiss a claim that a large investor in Bed Bath & Beyond, well-known to the meme-stock world, used a tweet with an emoji to orchestrate a pump and dump scheme.

On August 12, 2022, CNBC tweeted a negative story about the company, accompanied by a picture of a woman pushing a shopping cart at a Bed Bath store. In response, Cohen tweeted a reply: “At least her cart is full” with what was described as a “smiley moon emoji.” The court stated: “Some online communities understand the smiley moon emoji to mean ‘to the moon’ or ‘take it to the moon.’  .  .   .  In other words, according to Plaintiff, Cohen was telling his hundreds of thousands of followers that Bed Bath’s stock was going up and that they should buy or hold.”

He then filed a close-in-time, but potentially unrelated, amendment to his Schedule 13D which indicated that it “was triggered solely due to a change in the number of outstanding Shares of the Issuer” and made no mention of any plans to sell. Two days later, he filed another amendment reporting the sale of all of his Bed Bath shares.

With respect to the emoji, the blog summarizes the court’s conclusions as follows:

– Although an emoji may be ambiguous, its meaning can be clarified “by the context in which [it] is used.”
– “Emojis may be actionable if they communicate an idea that would otherwise be actionable.”
– The plaintiff “plausibly alleged that the moon tweet relayed that Cohen was telling his hundreds of thousands of followers that Bed Bath’s stock was going up and that they should buy or hold. In the meme stock ‘subculture,’ moon emojis are associated with the phrase ‘to the moon,’ which investors use to indicate ‘that a stock will rise.’ So meme stock investors conceivably understood Cohen’s tweet to mean that Cohen was confident in Bed Bath and that he was encouraging them to act” [citations omitted].
– The tweet is actionable because “plausibly material,” rather than “mere puffery,” as evidenced by investors’ reliance in driving up the stock price. Further, “[i]nvestors may have reasonably seen Cohen as an insider sympathetic to the little guy’s cause,” by interacting with followers on Twitter, his large stake and public interactions with the company.

It’s worth noting that the plaintiffs claimed that the first 13D amendment and related Form 144 were also misleading. In response to the 13D claim, the defense pointed out that Section 13(d) has no private right of action for damages. To this the court replied, “No matter. Even if that is right, it does not follow that 10(b) claims may not be based on misleading 13D filings. Those are two separate questions.”

– Meredith Ervine 

August 18, 2023

Activism: Are Diverse Boards a Vulnerability?

Here’s something that John blogged last week on DealLawyers.com:

The Activist Investor’s Michael Levin flagged a recent Institutional Investor article that claims that activist hedge funds look at the diversity of a board when identifying potential targets for their campaigns.  Here’s an excerpt:

Activist hedge funds are paying attention to board diversity — and are using that information to decide on their next targets. New research shows that activist investors are more likely to succeed when boards are less united and slower to act — two characteristics that are common among diverse boards, where members come from different backgrounds and tend to bring different perspectives. The study found that hedge funds exploit differences of opinion among board members, as well as their more deliberate decision-making processes, to sway shareholder votes in their favor.

The article quotes one of the study’s authors as saying that although diversity provides many benefits, diverse boards take longer to come to a consensus than boards comprised of members of the “old boys network.”  Boards and their advisors should keep this vulnerability in mind when evaluating their potential to be targeted by activist hedge funds and in their activism preparedness efforts.

On a related note, make sure to mark your calendar for our upcoming joint webcast with PracticalESG.com “Corporate DEI Programs After Students for Fair Admissions v. Harvard” on Thursday, August 31, 2023, at 2 pm Eastern. J.T. Ho, Co-head of Public Companies & ESG practice at Orrick, Ngozi Okeh, DEI Editor at PracticalESG.com, and Travis Sumter, Labor & Employment Attorney at NextRoll, will discuss the increasingly complex surroundings in which corporate DEI programs operate. If you’re not already a member with access to this webcast, sign up online for a no-risk trial or email sales@ccrcorp.com.

 Meredith Ervine

August 17, 2023

Crypto Decision in Ripple Labs: Approach Already Rejected in Terraform

In mid-July, I blogged about the SDNY’s long-awaited order in SEC v. Ripple Labs, (SDNY 7/23), suggesting that the decision may not be the massive victory for crypto that some were calling it and lamenting that the Ripple decision was just one development in the crypto saga — certainly not bringing the regulatory clarity some had hoped. The latest crypto decision, also from the SDNY — SEC v. Terraform Labs, (SDNY 8/23) — supports these points. This Mayer Brown alert describes the decision:

Judge Jed Rakoff ruled this week in favor of the SEC on a motion to dismiss, finding the SEC’s amended complaint adequately pled that the crypto assets sold by Terraform Labs and its founder and Chief Executive Officer Do Keyong Kwon qualify as “investment contracts” under the Howey precedent. While this decision represents only a preliminary review of the issues and accepts the SEC’s allegations as true (for purposes of the motion), it provides useful commentary as well as some counterpoints to the Ripple analysis […]

Judge Rakoff appeared to agree with Judge Torres that digital assets do not constitute securities unless their offering, sale or use were tied to an economic benefit being conveyed upon the purchaser. However, Judge Rakoff also stated that a crypto asset that is not a security at one point in time may, as its circumstances and those of its related protocol(s) change, become an investment contract—i.e., a security—that is subject to SEC regulation.

The part of the decision certain to attract the most attention is Judge Rakoff’s explicit rejection of the approach used by Judge Torres in the recent Ripple ruling, which drew a distinction between digital assets based on the manner in which they were sold (primary issuance to institutional investors vs. secondary transactions involving retail investors). In doing so, Judge Rakoff stated that the Howey precedent does not differentiate among purchasers, because the manner in which digital assets are purchased would not change a purchaser’s reasonable belief in the promise of future profits. In the Terraform case, the SEC alleged that the defendants actively encouraged both retail and institutional investors to buy crypto assets while touting their ability to maximize returns on investors’ tokens.

This Jenner & Block alert gave the TL;DR on both decisions. Here it is:

Recent decisions appear to agree that:
– tokens, themselves, are not securities;
– some token sales are securities offerings, particularly those made directly from the issuer to a purchaser.

Recent decisions appear to disagree on whether or in what circumstances token sales are securities transactions in a secondary market;

The SEC sought leave to appeal the Ripple case, which may provide more substantial guidance next year.

– Meredith Ervine 

August 17, 2023

Cyber Report: Our Defenses Are (Still) Being Outsmarted (by Teenagers)

Consider this for upcoming board and committee discussions — especially since cybersecurity disclosures are already bound to be on your agenda. Last week, the Department of Homeland Security announced the release of a report summarizing findings by the Cyber Safety Review Board regarding certain cyber incidents in 2021 and 2022 involving a particular threat actor group that impacted dozens of well-resourced organizations. The CSRB engaged nearly 40 organizations and individuals to discuss these incidents, including threat intelligence firms, incident response firms, targeted organizations, law enforcement, individual researchers and subject matter experts.

This post on the Jackson Lewis Workplace Privacy, Data Management & Security Report blog summarizes key highlights, specifically:

– The multi-factor authentication (MFA) widely used today is insufficient; one-time passcodes and push notifications sent via SMS can be intercepted, making application or token-based MFA methods preferred
– Employees can be compromised with monetary incentives and have handed over access credentials, approved upstream MFA requests, conducted SIM swaps, and otherwise assisted attackers in gaining access to an organization’s systems
– Threat actors also leverage third-party service providers to target downstream customers through secure file transfer services

Yikes! Some of these findings were surprising (to me) and — at least for some companies — may be worthy of board time and attention, including a discussion about how management is addressing these risks. To that end, here’s a further excerpt from the blog:

The Board outlines several recommendations, some are more likely to be within an organization’s power to mitigate risk than others. The recommendations fall into four main categories

– strengthening identity and access management (IAM);
– mitigating telecommunications and reseller vulnerabilities;
– building resiliency across multi-party systems with a focus on business process outsourcers (BPOs); and
– addressing law enforcement challenges and juvenile cybercrime.

As noted above, one of the strongest suggestions for enhancing IAM is moving away from passwords. The Board encourages increased use of Fast IDentity Online (FIDO)2-compliant, hardware backed solutions. In short, FIDO authentication would permit users to sign in with passkeys, usually a biometric or security key. Of course, biometrics raise other compliance risks, but the Board observes this technology avoids the vulnerability and suboptimal practices that have developed around passwords.

Another recommendation is to develop and test cyber incident response plans. As we have discussed on this blog several times (e.g., here and here), no system of safeguards is perfect. So, as an organization works to prevent an attack, it also must plan to respond should one be successful.

I also want to note that the title of this blog isn’t just clickbait. The opening message of the report references the 1983 movie WarGames and identifies parallels with modern-day real life, including that “teenagers are compromising well-defended organizations using a creative application of many techniques.”

– Meredith Ervine

 

August 17, 2023

The Other Tesla Compensation Litigation

Over on The Advisors’ Blog on CompensationStandards.com, I recently blogged about a settlement agreement in a compensation-related derivative suit that really is one for the books. The litigation challenged the reasonableness of Tesla’s director compensation, and the settlement includes the clawback & forfeiture of compensation valued at $735 million. The blog post describes the mechanics of the clawback terms and discusses what this means for the director defendants.

In a follow-up blog, Liz gave more detail on the “corporate governance reforms” also contemplated by the settlement, including a “director say-on-pay” vote, which — although not a widespread practice — Liz explains, isn’t necessarily a new thing.

– Meredith Ervine