Slashdot Mirror


Should Hacked Companies Disclose Their Losses?

derekmead writes "By law, US companies don't have to say a word about hacker attacks, regardless of how much it might've cost their bottom line. Comment, the group of Chinese hackers suspected in the recent-reported Coke breach, also broke into the computers of the world's largest steel company, ArcelorMittal. ArcelorMittal doesn't know exactly how much was stolen and didn't think it was relevant to share news of the attack with its shareholders. Same goes for Lockheed Martin who fended off a 'significant and tenacious' attack last May but failed to disclose the details to investors and the Securities Exchange Commission. Dupont got hit twice by Chinese hackers in 2009 and 2010 and didn't say a word. Former U.S. counterintelligence chief Joel Brenner recently said that over 2,000 companies, ISPs and research centers had been hit by Chinese hackers in the past decade and few of them told their shareholders about it. This is even after the SEC has made multiple requests for companies to come clean about cyber security breaches in their quarterly or annual earnings reports. Because the potential losses, do hacked companies have a responsibility to report security breaches to investors?"

4 of 68 comments (clear)

  1. Of course they should. by vikingpower · · Score: 5, Insightful

    You're responsible toward your shareholders. If you don't have any, at least the board & upper management should be in the know.

    --
    Religous speak to God. Insane are spoken to by God. When all shut up, one can finally hear Shostakovich in peace
    1. Re:Of course they should. by udachny · · Score: 5, Interesting

      Oh, and I forgot to mention something: most people shouldn't be participating in stock market at all. The fact is that participation in the stock market is encouraged by government, which debases your savings with inflation, so you feel that you must do something. Since the interest rates on government bonds is non-existent, I mean it's negative given the inflation rate, you are basically forced into the stock market.

      But this a huge problem, most people do not understand the stock market, so the government hands them over to the financial institutions, that basically lobby the government to push people into their hands.

      My point is: you should NOT invest in things that you personally do not understand or at least didn't do homework on before you jumped into them. Government encourages people to participate in this giant casino and makes it LOOK like it's safe with various regulations. You think you are safe while in reality you are being robbed and the robbery is endorsed by the government itself. You are much better off either starting your own company if you want to invest or at the minimum to go and find out whatever you can about the company you are investing in. Visit the offices, visit the plants, visit the sites, request to see the books, etc.

      If you can't spend the time and you think you can trust somebody to do it for you, I have news for you: you won't be able to choose the best options, you won't be able to choose your account manager based on past performance, because the established industry pushed for the so called 'self-regulations' (FINRA), which are really extension of government power, because you can't operate in that space unless you comply. But that system PREVENTS COMPETITION!

      It ensures that you are going to give your money to the biggest crooks, the ones that are most connected to the government, which is working together with these crooks to steal your money from you by all means possible, while pretending you are protected by gov't.

      There is no competition, no small money manager can start his own brokerage, it's made impossible with regulations and rules and then with FINRA that prevents advertising based on past performance.

      Again: most people shouldn't be in the stock market.

      (I recommend that most people buy something of value, assets that withstand inflation if they can't be sure in what they are investing. But your gov't certainly doesn't want you to do that and the tax code proves it as well).

  2. I dissent. by swschrad · · Score: 5, Insightful

    if the hack causes material changes in business or profitability, a public corporation is required by law to disclose what is known about the effect on continuing operations to the SEC, which 10K form is a public document. especially if a "going concern" warning is required by financial regulations.

    --
    if this is supposed to be a new economy, how come they still want my old fashioned money?
    1. Re:I dissent. by captaindomon · · Score: 5, Insightful

      Exactly. This kind of reporting is already required by the SEC if it causes or could potentially cause a reasonable material change to your books. Same as if a dinosaur ate your CEO, or your data center was wiped out by a giant mutant butterfly. We shouldn't be specifying each individual case in law, the SEC laws are so complex that there are SEC specialist lawyers all over the place already.

      --
      Just because I can hook a shark from a boat, I do no offer to wrestle it in the water.