Intercontinental Exchange, Inc.
Approved Evidence
Intercontinental Exchange paid $10 million for failing to timely report cyber intrusion to SEC
The SEC charged Intercontinental Exchange and nine wholly owned subsidiaries, including the New York Stock Exchange, with failures relating to the regulatory reporting of a cybersecurity intrusion. In April 2021 a third party informed ICE that it could be affected by a previously unknown vulnerability in a virtual private network device. ICE quickly determined that a threat actor had inserted malicious code into a VPN device used for remote access to its corporate network. The SEC found that ICE personnel nevertheless failed for several days to notify legal and compliance staff at subsidiaries subject to Regulation Systems Compliance and Integrity. As a result, those subsidiaries did not timely assess and report the cyber intrusion to SEC staff as required. ICE and its subsidiaries consented to a cease-and-desist order, and ICE agreed to pay a $10 million civil penalty. Primary source: SEC — Intercontinental Exchange and NYSE Affiliates Charged Over Cyber Intrusion Reporting: https://www.sec.gov/newsroom/press-releases/2024-63