Lately I have been getting a lot of requests to demonstrate how a local AI program actually works. So I built the demonstration: a local AI lab, the kind I walked through in What It Actually Looks Like to Run a Local LLM at Your Firm, loaded with a dataset I can share freely because it is public: the SEC’s entire enforcement archive, downloaded in full to local storage. The lab read all of it. This article is both the demonstration and the payoff, because what came back rewrites the standard story about SEC cybersecurity enforcement.
Most writing about this enforcement reacts to one order at a time, in the week it lands. That produces a distorted picture. The cases that get coverage are the ones with the biggest numbers, and the biggest numbers are almost never the cases that resemble your firm.
So we did it differently. The archive in the lab holds every administrative proceeding, litigation release, Commission opinion, ALJ initial decision, and ALJ order the agency has posted from January 2010 through today: 37,299 documents. The lab read the entire corpus for cybersecurity and IT-related conduct, pulling the charged provisions, the findings, and the penalties out of the order text itself; the independent verification pass then re-checked every claim in this article against the source documents.
To be precise about the method, because precision about AI claims matters in ways this article will make clear: we did not train a model, and we did not ask one what it remembered. Every claim below was read out of the source document, and every claim carries the SEC release number so you can pull the order and check us.
Two hundred nine documents matched, consolidating to 191 distinct enforcement matters: 102 in the off-channel messaging program, and 89 others that range from registered-firm safeguards cases to prosecutions of the hackers themselves. Set those prosecutions, the public-company disclosure cases, and the procedural orders aside, and roughly three dozen registered-firm cases carry the lessons that follow. And the single most useful thing the whole record teaches is this: there is no cybersecurity rule in these orders, and there is no case charging a registered firm for the fact of being breached. Not one, in sixteen years. The Commission charges four things, all of them documentary: safeguards policies that were not reasonably designed under Rule 30(a) of Regulation S-P, identity theft programs that did not function under Rule 201 of Regulation S-ID, failures to preserve electronic communications under Exchange Act Rule 17a-4 and Advisers Act Rule 204-2, and books and records that stopped being current after an incident. A breach is neither necessary nor sufficient. Three firms paid a combined $2.55 million in one day in 2022 with no intrusion alleged at all.
That finding is not trivia. It tells you exactly how to prepare, and it is the opposite of how most firms prepare.
The rest of this article is free to read with a BrainTrust membership; joining takes about a minute, and no credit card is required.