Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • SEC hack acts as another security wakeup call current page
Link copied

SEC hack acts as another security wakeup call

Oct 20, 2017
Author:
James Maude Headshot 2024
James Maude
Field Chief Technology Officer
Blog banner default
SEC hack acts as another security wakeup call
James Maude Headshot 2024
James Maude
Field Chief Technology Officer

The U.S. Securities and Exchange Commission (SEC) has revealed that it’s fallen victim to a hack. In its recent “Statement on Cybersecurity, published by its Chairman, Jay Clayton, it was revealed that its controversial Electronic Data Gathering, Analysis, and Retrieval (EDGAR) system had been compromised last year and "may have provided the basis for illicit gain through trading".

Unfortunately, this is not the first time the SEC has exposed financial data. In 2014, the SEC inspector general revealed that hundreds of agency laptops, potentially containing sensitive market data, could not be accounted for. If you look at the SANS institute’s CIS critical security controls, number 1 on the list is “Inventory of Authorized and Unauthorized Devices”. Put simply, you can secure what you don’t know about.

CIS

What about the more recent EDGAR breach? This system was designed to handle electronic filings of corporate statements. These statements relate to finances and events that may impact the business and include draft documents. The system is designed to ensure fairness by releasing all the relevant data to the public at the same time preventing individuals trading on advanced information.

As a result of the breach, it is believed that hackers may have accessed advanced information to gain an advantage in trades. Interestingly the breach occurred due to a software vulnerability in a test version of EDGAR. This is where alarm bells start ringing in terms of security best practice. In this case, it appears that a test system was connected to live SEC data and made publicly accessible. Given that test systems are generally not secured to the same level as production systems this is a huge red flag.

If we again look again at the CIS controls we see that secure configuration and vulnerability assessment and remediation are key controls to prevent an attacker easily exploiting a system. In this case ensuring that any system with access to sensitive data is secured. Moving beyond that it is important to harden the system by having an inventory (allow list) of authorized software and control administrative privileges. These last steps are key to stopping attackers leveraging a vulnerability to easily install backdoors and abuse privileged accounts access to data.

Given that the vulnerability was only patched after the breach was discovered it appears that just like the Equifax incident, this is a classic example of organizations failing to get the basics right around securing systems. No matter if a system is test or production if it contains business information it needs to be secured properly. Repeatedly it has been proven that applying the top 5 CIS controls or as an alternative the ASD top 4, mitigate the majority of cyber threats that seem to plague organizations globally.

Although it appears that the SEC has a good deal of work to do in improving their security posture this is hopefully a wakeup call to other organizations who may be sitting on a time bomb of unpatched systems, unauthorized applications and excessive use of admin privileges.

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • Named Leader in KuppingerCole Leadership Compass for Privilege Management
    Jan 5, 2016 Named Leader in KuppingerCole Leadership Compass for Privilege Management
    Blog
    1m
  • BeyondTrust Receives 5 Star Rating from SC Magazine
    Feb 4, 2014 BeyondTrust Receives 5 Star Rating from SC Magazine
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.