Stein urges SEC action on cyber-risk disclosure

SEC commissioner Kara Stein has called for her agency to boost corporate disclosures about the risks issuers face in the cyber-security arena, and has taken a swipe at dual-class share structures.

‘We at the commission have not yet adequately pressed forward. While the commission’s staff have released disclosure guidance for public companies to consider when dealing with cyber-risks and breaches, the commission can and should do more,’ Stein says in a recent speech.

She argues that the commission should consider introducing rules that would require disclosure of a firm’s enterprise-wide consideration of cyber-risks. The commission should also develop rules to ensure market intermediaries, including broker-dealers and investment advisers, develop and implement policies and procedures to protect investors’ personal information, Stein adds.

She notes that shareholders are advocating – often via governance proposals – for companies to release more information about their cyber-security practices: ‘But good information remains scarce. Unfortunately, corporate disclosures are far from robust and largely consist of boilerplate language that fails to provide meaningful information for investors.’

Companies and shareholders agree cyber-security is one of the most important corporate issues, but it is unclear why companies are not doing more to implement robust cyber-security frameworks and provide useful disclosures regarding the risk of data loss, Stein says. The problem, she suggests, is that companies tend to view cyber-threats as a technology problem rather than a business risk.

‘As we have seen time and time again, cyber-security, and the related threats of unintentional loss of data, is a governance challenge for all of us, and it requires a change in culture and approach,’ she adds. ‘Cyber-security has been viewed by many as simply an IT problem, hoisted on the shoulders of a company’s chief information officer. Too often, this has led to a failure to integrate cyber-security into a firm’s enterprise risk-management framework.

‘To be sure, some companies are focused on cyber-threats and recognize their potential economic threat. But companies need to do more than simply recognize the problem. They need to heed the calls of their shareholders and treat cyber-threats as a business risk.’

Dual-class shares
Elsewhere in the speech, Stein addresses the issue of dual-class share structures – which fellow commissioner Robert Jackson also discussed publicly last week, arguing that keeping them in place permanently goes against US values by creating ‘corporate royalty.’

Similarly, Stein in her speech describes dual-class structures as ‘inherently undemocratic, disconnecting the interests of a company’s controlling shareholders from its other shareholders.’ This disassociation of interests can grow over time when certain shareholders, but not others, have the right to vote over fundamental corporate matters such as board matters, she argues.

She notes that such arrangements are prohibited in some countries, but adds that ‘we are still inexplicably letting dual-class share structures persist. While some say dual-class capital structures are designed to prevent a takeover or shareholder activism, they also may provide a means to evade management and board accountability.

‘Structures where a minority of insiders lock out the interests and rights of the majority may also have collateral effects on our capital markets. They may be harmful not just for those companies, their shareholders and their employees, but also for the economy as a whole.’

Upcoming events

  • Briefing – Are investors finding your IR content in AI?
    Wednesday, December 17, 2025

    Briefing – Are investors finding your IR content in AI?

    In partnership with WHEN 8.00 am PT / 11.00 am ET / 4.00 pm GMT / 5.00 pm CET DURATION 45 minutes About the event AI is transforming how investors and analysts access company information. Increasingly, earnings reports, disclosures and IR websites are being read first by algorithms and large…

    Online
  • Forum – AI & Technology Europe
    Thursday, March 12, 2026

    Forum – AI & Technology Europe

    About the event Stay ahead. Harness AI. Transform IR. In today’s rapidly evolving financial landscape, AI is transforming how IROs engage with investors, analyze market sentiment and deliver insights. Yet, many IR teams face challenges in understanding and employing these tools effectively. WHEN WHERE America Square Conference Centre, London The…

    London, UK
  • Think Tank – West Coast
    Thursday, March 19, 2026

    Think Tank – West Coast

    Our unique format – Exclusively for in-house IRO’s The IR Impact Think Tank – West Coast will take place on Thursday, March 19, 2026 in Palo Alto and is an  invitation-only event exclusively for senior IR officers. Our think tanks are free to attend and our unique format enables participants to network extensively, and discuss, debate and dissect…

    Palo Alto, US

Explore

Andy White, Freelance WordPress Developer London