The FCA’s observations
The FCA’s observations address the key questions issuers face: whether information about an incident is inside information, when it must be disclosed, whether disclosure can be delayed, what further disclosure may be needed as matters develop and whether information can be shared with the authorities. It also goes further and suggests that inside information may arise from discovering either a historical compromise or identifying significant vulnerabilities before any attack has occurred. This latter point is a notable extension.
Initial assessment
The FCA emphasises that not every cyber incident will be inside information. Issuers should assess each incident on its facts from the point at which they first become aware of it. The key question is whether the information about the incident meets the Article 7 definition of inside information: namely, information of a precise nature relating, directly or indirectly, to the issuer that has not been made public and would be likely to have a significant effect on share price if disclosed.
Information will not necessarily be obviously precise from the moment an incident is detected. In the earliest stages, an issuer may know only that something is wrong. However, because MAR requires only that information is specific enough to enable a conclusion to be drawn as to the possible effect of that event on the share price, information may become precise well before the full consequences of an incident are understood.
Perhaps the most notable statement in this part of PMB 66 is the FCA's suggestion that it "may be prudent to begin from the assumption" that information about a cyber incident could constitute inside information. While this does not alter the legal test, it signals that issuers should be prepared to justify any decision that an incident does not amount to inside information.
In carrying out the assessment, the FCA suggests that issuers consider:
- the scale and nature of the incident, including whether sensitive client, customer or commercial data has been compromised;
- the reputational impact; and
- any immediate or anticipated disruption to the issuer's operations or financial position,
and acknowledges that issuers are afforded a short period of time if necessary to clarify the situation before making their disclosure. Where there is a danger of inside information leaking before the facts and their impact can be confirmed, a holding announcement may be needed – something the FCA notes may be particularly relevant for retailers whose online and/or payment channels are affected. This will apply equally to issuers in other sectors where the operational impacts of an attack will quickly become publicly apparent.
Delaying disclosure
MAR permits disclosure to be delayed where the conditions in Article 17(4) are satisfied, i.e. if immediate disclosure would likely prejudice a legitimate interest of the issuer and provided delay of disclosure is not likely to mislead the public and the issuer is able to ensure the confidentiality of the information.
The FCA notes that delay may be particularly relevant where negotiations with an attacker are ongoing and immediate disclosure could prejudice those negotiations. However, as the FCA points out, any attacker is likely to hold the same information, so issuers must keep confidentiality under continuous review. This will depend on the identity of the attacker, the known nature and motive of the attack and whether the attacker is likely to publicise it. For example, this is more likely if the attacker is a hacktivist as opposed to a nation state which is known usually to conduct attacks to gather intelligence.
This is something that an issuer and its brokers are unlikely to be able to assess themselves, so there may be an urgent need to obtain reliable threat intelligence on the attacker and its past conduct to be able to assess the likelihood of information being made public.
Subsequent disclosures
Issuers must continuously monitor whether developments trigger a further obligation to announce. Inside information may arise as an incident develops – for example, concerning the ongoing impact on operations, the likely duration of the incident or reputational damage – and even after the incident has been resolved, where the financial impact ultimately becomes material. This could include remediation costs, increased cyber protection costs or the need to revise previously stated outlook or financial targets. The costs of a serious cyber incident can be very significant indeed, particularly where key systems are unavailable for an extended period. The FCA also reminds issuers that they cannot justify non-disclosure by offsetting the negative financial impacts of an incident against expected future outperformance.
Sharing information with government, law enforcement and regulators
In a serious cyber incident, information will often be shared with outside bodies at an early stage. The deadlines for this can be very tight. For example, personal data breaches must generally be reported to the Information Commissioner’s Office within 72 hours and, if the Cyber Security and Resilience Bill is enacted in its current form, in-scope entities will have to notify their regulator and the NCSC within just 24 hours. Where that information is inside information, the issuer must consider whether sharing it is lawful under Article 10 of UK MAR. As the FCA puts it, the question is whether the disclosure is necessary and whether the person making it is acting in the normal exercise of their employment, profession or duties. The FCA's most helpful observation concerns the NCSC. It indicates that disclosure of inside information to the NCSC in connection with its functions, or to information-sharing communities that it oversees, may support the view that the issuer is acting in the normal exercise of its duties.
Historical compromises and current vulnerabilities
PMB 66 also covers two situations where there is no live attack.
First, an issuer that discovers a past compromise should assess whether information about that event currently constitutes inside information and, if so, whether disclosure can be delayed.
Second, the FCA states that vulnerabilities in an issuer's cyber defences "could in themselves amount to inside information", even where there is no active incident. As disclosing those vulnerabilities could increase the risk of attack, the FCA suggests that it may be possible to delay disclosure.
The point on vulnerabilities is particularly striking. In practice, many vulnerabilities will struggle to satisfy the Article 7 test. A weakness that may or may not be exploited is unlikely to be sufficiently precise, and assessing whether it is likely to have a significant effect on the issuer's share price may be difficult, if not impossible. More fundamentally, the FCA's observations on the ability to delay disclosure in these circumstances depart from the usual rationale for doing so under MAR. Ordinarily, delay protects a legitimate interest while a process runs its course, with disclosure expected once that process has concluded. Here, however, the issuer's interest may be in remediating the vulnerability before it becomes public at all. If the vulnerability is fixed before disclosure, the information may cease to be inside information, meaning that no announcement is ever made.
The suggestion that identified vulnerabilities could constitute inside information has significant implications for issuers’ processes for identifying and assessing potential inside information, implementing access controls, maintaining insider lists and handling information, so further clarification from the FCA on this point would be welcome.
Comment
PMB 66 delivers useful clarity on the short period available to establish the facts and assess what disclosures may be required and on the ability to engage with bodies such as the NCSC. At the same time, the FCA's suggestion that issuers should begin from the premise that a cyber incident may constitute inside information, coupled with its focus on the risk of attacker-led disclosure, means that issuers need robust processes to ensure that significant incidents are quickly identified and assessed from a MAR perspective. Issuers should also expect decisions not to announce an incident, or to delay disclosure, to attract closer scrutiny.
For listed companies, MAR should be considered from the outset of an incident. Although IT teams, forensic advisers and incident-response specialists will naturally lead the immediate response, decisions taken in the first few hours can carry significant MAR implications. Customer communications, for example, may themselves trigger disclosure obligations and should therefore be reviewed through a MAR lens before they are issued. The teams responsible for market disclosure, regulatory engagement and any communications with the attacker should also work closely together to ensure that the MAR analysis is continually aligned with what is being assessed elsewhere. Where a threat actor begins threatening publication, any decision to delay disclosure should be revisited promptly.
A&O Shearman runs tabletop exercises that take boards and legal teams through a simulated cyber incident and the associated MAR issues. The exercises cover the initial holding announcement, a ransom demand, threats by the attacker to publish stolen information and post-incident market communications, testing at each stage whether the MAR analysis has been properly assessed, documented and revisited as new information emerges. Please contact us if this would be of interest.