Even for officers of publicly-traded companies, it should not be difficult to avoid committing securities fraud if you're not actually attempting to make money in ways you shouldn't.
So, this isn’t about committing securities fraud, it’s about writing something that shows that the company knows that something bad is going on. It’s about evidence.
Also it is very common and easy for people to speculate wildly about what might be going on, to make jokes, and to use legal terms they don’t really understand. This is Hacker News; you know this. In court, such nonsense may make it look like you actually knew something.
This seems to be an allusion to Matt Levine’s writing that “everything is securities fraud”.
It’s not as cynical against companies as you think. The overall point is that sometimes there’s a lot blurrier line between legitimate activities and what someone could interpret as securities fraud than you’d expect.
This is not the case. They can and will take any information in the worst possible light. They want fine and convictions not for the fair decision to be made.
You are saying they want slam dunk cases, but are apparently obtaining these outcomes using evidence that can go either way? You don't see the contradiction there?
The judicial system is adversarial by nature. The goal of the prosecution is to put forward its best possible case that basically means assuming the worst of any piece of evidence.
The training included a case study where a drug company was sued for side effects. The key piece of evidence? A company lawyer just happened to write in an email "maybe we got the dose wrong?".
The lawyer had zero medical training, zero access to any of the data and frankly was completely unqualified to make such a statement.
But this email was presented during the trial to the jury and the company lost the suit.
The point is - you won't get a chance to provide context for things written in emails. They will be taken at face value and framed in the worst possible light.
Seems like a pretty good policy to not make a permanent record of conjecture and half-baked theories that could come back to bite you later?
In some industries (e.g. defense contracting), getting a concrete answer for where you can and can’t store certain information can be a nightmare. And often times there isn’t even a definitive answer.
So from a risk perspective, it’s easier to have a policy of minimizing the things you write down in emails and documents. You obviously need to write some things down and need a policy for those things, but if you’re just conveying a few paragraphs of information, a brief face-to-face conversation is much lower risk than writing the same notes down in SharePoint somewhere and hoping that you don’t screw up the security markings.
I guess I’ve never seen this as an official directive from management, but it’s been the reality at a few places where I’ve worked and it was never because anything shady was going on.