Subject: File No. S7-2026-25
From: Rick Liu
Affiliation:

Sep. 9, 2026

VIA ELECTRONIC SUBMISSION
September 9, 2026
Vanessa A. Countryman, Secretary
Securities and Exchange Commission
100 F Street, NE
Washington, DC 20549-1090
Re: Electronic Delivery of Information Under the Federal Securities Laws
File No. S7-2026-25; Release Nos. 33-11430; 34-105921; IA-6980; IC-36252
Dear Secretary Countryman:
I am writing as an individual retail investor to submit a public comment regarding the Securities and Exchange Commission's proposed rule, "Electronic Delivery of Information Under the Federal Securities Laws" (Regulation E-Delivery). While I appreciate the Commission's efforts to modernize communication infrastructure and reduce operational costs for market intermediaries, I have severe concerns regarding how an "electronic-by-default" framework will impact the security of my personal financial data and increase my exposure to criminal hackers.
By removing the requirement for affirmative consent, Regulation E-Delivery will force millions of investors-many of whom may not be digitally sophisticated-into digital channels. This massive shift of sensitive investor data online creates an incredibly lucrative target for cybercriminals. Brokerage accounts, trade confirmations, and annual portfolio disclosures contain highly sensitive information, including account numbers, full legal names, home addresses, and detailed financial balances. Centralizing the default delivery of these documents into online portals and email networks vastly expands the digital "attack surface" for bad actors.
Specifically, I urge the Commission to address the following cybersecurity vulnerabilities before finalizing this rule:
The Insecurity of standard Email Notifications: Email is inherently vulnerable to interception, phishing, and spoofing. If a criminal compromises a retail investor's email account, they gain immediate access to historical financial notifications, links to account portals, and a roadmap to the investor's entire net worth.
Intermediary Data Breaches: Covered entities-ranging from major broker-dealers to small, independent registered investment advisers (RIAs)-possess varying levels of cybersecurity defenses. Smaller firms may lack the resources to defend against sophisticated ransomware attacks or data exfiltration. Defaulting everyone into digital delivery ensures that a breach at any single firm will expose the critical financial data of thousands of unconsenting retail investors simultaneously.
The "Notice and Availability" Vulnerability: Forcing investors to maintain and access multiple online portals to review their disclosures multiplies the number of credentials an individual must manage. This heavily increases the likelihood of credential-stuffing attacks, where hackers use leaked passwords to breach investor accounts across different financial institutions.
To mitigate these severe risks, I request that the Commission modify the final rule to include the following investor protections:
Strict Security Mandates for Covered Entities: The SEC should mandate that any firm relying on Regulation E-Delivery must enforce mandatory, robust security protocols for accessing disclosures. This should include free, user-friendly Multi-Factor Authentication (MFA) and encrypted document delivery options.
A Broad and Frictionless Opt-Out Process: The mechanism to opt out of electronic delivery and return to paper statements must be completely frictionless. Financial institutions should not be allowed to bury the paper opt-out option behind complex website menus or utilize behavioral "dark patterns" designed to discourage investors from choosing physical delivery. The right to free paper statements must be presented clearly, prominently, and repeatedly.
Comprehensive Incident Notification Requirements: In the event that a covered entity suffers a data breach exposing electronic delivery addresses or portal credentials, retail investors must be notified immediately and provided with credit monitoring services funded entirely by the breached entity.
Thank you for your time and for considering the safety and privacy of individual retail investors as you evaluate this consequential rule change.
Sincerely,
Rick Liu
Reno, NV