Exclusive: SEC left computers vulnerable to cyber attacks - sources
(Reuters) - Staffers at the U.S. Securities and Exchange Commission failed to encrypt some of their computers containing highly sensitive information from stock exchanges, leaving the data vulnerable to cyber attacks, according to people familiar with the matter.
Context & Ripple Effects
The report lands a year after hackers penetrated Nasdaq's computers, an episode that put exchange-level cyber defenses on the regulatory agenda. Now the sources cited by Reuters point the vulnerability inward: staffers at the SEC itself allegedly left machines holding highly sensitive stock-exchange data unencrypted — a claim flagged as sourced, not confirmed by the agency.
The pickup list — DailyTech, The Inquirer, The Verge, Softpedia — shows the story traveled well beyond the markets press, which matters because the SEC's authority over issuer disclosure and exchange operations depends on being seen as a competent custodian of the very data it collects.
First-order effects
- If the sourcing holds, the SEC faces an immediate remediation job — encrypting or isolating machines that hold exchange data — while its credibility in pressing exchanges and issuers on their own cyber hygiene takes a direct hit.
Second-order effects
- Exchanges whose nonpublic information sat on unencrypted SEC hardware now have a fresh argument that the regulator should be held to the security standards it demands of regulated firms, complicating any SEC push for mandatory cyber disclosures.
Third-order effects
- Taken together with the Nasdaq intrusion, the episode points toward market-infrastructure security debates that include the overseer itself — with Congress and the industry increasingly able to question whether the SEC's own systems meet the bar it sets for others.
The trend: Cybersecurity scrutiny of U.S. financial markets is expanding from exchanges and issuers to the regulators that supervise them, making agencies' own operational security part of the policy fight.