In the wake of a breach at Wyndham Worldwide that has resulted in a lawsuit against the company from the FTC, questions have emerged about why there was no SEC filing from the hotel and resort chain – given the guidance and recommendations published by the commission last year.
Last October, U.S. Securities and Exchange Commission’s Corporation Finance division released guidance to publically traded companies on cybersecurity incident disclosure. As things stand, the SEC stated, there are no requirements that mention cybersecurity. Yet, publically traded companies “should disclose the risk of cyber incidents if these issues are among the most significant factors that make an investment in the company speculative or risky.”
As mentioned, no such report has been filed with the SEC by Wyndham. The AP is reporting that Senator Jay Rockefeller is adding a provision to cybersecurity legislation that would give the SEC’s previously published guidance some teeth. According to the report, Rockefeller would direct the SEC’s commissioners to clearly define when companies must disclose breaches and outline the steps they are taking to protect corporate assets, including networks and data.
It isn’t clear if the legislation will pass or if the SEC will get any leverage to force companies to report breaches. As things stand now, they don’t have to and as such, they won’t. No company wants to talk about their failures.
As for Wyndham, the questions over their lack of commentary to the SEC (which they dispute, claiming that the notices on their corporate websites were enough) is only one issue, they still have a lawsuit to deal with.
The FTC is suing the hotel and resort chain for security failures that resulted in three breaches in less than two years.
Wyndham Worldwide spokesperson Micahel Valentino told SecurityWeek that the company cooperated fully with the FTC’s investigation, and the accusations being levied are without merit.
“At the time of these incidents, we made prompt efforts to notify the hotel customers whose information may have been compromised, and offered them credit monitoring services,” he said in a statement. “To date, we have not received any indication that any hotel customer experienced a financial loss as a result of these attacks. Since these events, we have made significant enhancements to our information security, and have assisted franchised and managed Wyndham Hotels and Resorts-brand hotels in enhancing their information security.”
More from Steve Ragan
- Anonymous Claims Attack on IP Surveillance Firm Brickcom, Leaks Customer Data
- Workers Don’t Trust Employers with Personal Data: Survey
- Root SSH Key Compromised in Emergency Alerting Systems
- Morningstar Data Breach Impacted 184,000 Clients
- Microsoft to Patch Seven Flaws in July’s Patch Tuesday
- OpenX Addresses New Security Flaws with Latest Update
- Ubisoft Breached: Users Urged to Change Passwords
- Anonymous Targets Anti-Anonymity B2B Firm Relead.com
Latest News
- Germany Appoints Central Bank IT Chief to Head Cybersecurity
- OpenSSL Ships Patch for High-Severity Flaws
- Software Supply Chain Security Firm Lineaje Raises $7 Million
- ICS Cybersecurity Firm Opscura Launches With $9.4 Million in Series A Funding
- Vulnerability Provided Access to Toyota Supplier Management Network
- Patch Released for Actively Exploited GoAnywhere MFT Zero-Day
- Linux Variant of Cl0p Ransomware Emerges
- VMware Says No Evidence of Zero-Day Exploitation in ESXiArgs Ransomware Attacks
