Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm News

(Client) SEC Focuses on Cybersecurity Weaknesses

Author: Scarinci Hollenbeck, LLC

Date: November 11, 2015

Key Contacts

Back

SEC Focuses on Cybersecurity Weaknesses and Enforces Rule 30(a) of Regulation S-P (“Safeguards Rule”) against Investment Adviser

On Sept 22, 2015, the SEC announced its settlement of an administrative cease-and-desist proceeding through imposition of remedial sanctions against R.T. Jones Capital Equities Management, Inc., an SEC-registered investment adviser.[1]

This is the first enforcement matter establishing a willful violation of Rule 30(a) of Regulation S-P under the Securities Act of 1933, known as the “Safeguards Rule.”[2]  This proceeding is instructive for its itemization of the advisor’s failures over an extensive time period.

Interestingly, although the advisor discovered a possible cybersecurity breach at its third-party-hosted web server, and retained two cybersecurity consulting firms to independently confirm the cyber-attack, assess the scope of the breach and whether personally identifiable information (“PII”) stored on the server had been compromised, the attack  did not appear to have caused any  financial harm to any firm client.  The firm’s failure to have the “basics” of a cybersecurity regime, however, was sufficient for the SEC to impose sanctions.[3]

The SEC determined that the advisor violated the Safeguards Rule, adopted in 2000, and amended in 2005, which requires  adoption of written policies and procedures  reasonably designed to safeguard client’s PII.  The adviser took certain remedial efforts by appointing an information security manager over its PII data security and implemented a written information security policy, which included: (a) moving off of a web server-hosted server, (b) encrypting PII, installing a new firewall and log-in system, and (c) retaining a cybersecurity firm to provide a report/advice on IT security.  These efforts should be viewed as the minimum requirements the SEC’s OCIE and enforcement staff’s expect from a firm’s cybersecurity program.

What are the “takeaways” from this enforcement action?  Firm management CIO’s/CTO’s and CCO’s should take into account when considering the severity of the sanctions imposed against R.T. Jones that during the past 18 months, OCIE published two Risk Alerts on cybersecurity, and the SEC published a “Guidance Update,” and hosted a Cybersecurity Roundtable.[4]  There will not be much room for advisers to attempt to excuse their cybersecurity deficiencies in the context of this educational effort.

Cybersecurity remains a focus of OCIE and Enforcement. The time is  now  to plan and implement a year-end reassessment of  firm cybersecurity breach readiness and Incident Response Plan.  (“IRP”)

Here are “actionable ideas” for assuring  your firm (whether a broker-dealer, or investment adviser) has satisfied Cybersecurity basics:

  • Review the Firm’s Cybersecurity WSP’s and IRP; document the review process with COO/CIO/CTO/CLO, and engage with senior management for change approvals as required.
  • Review third-party vendor/hosts agreements and understand the division of responsibilities between Firm and third-party; correct as determined to be necessary.
  • Review Privacy Policies and BCP; revise as needed.
  • Test (SSAE 16) firewall(s); BYOD coverage, encryption/password basics.
  • Check the Firm’s internal audit examination process for ‘red flags’ of cybersecurity breach, as part of testing.
  • Complete 2015 Cybersecurity Training Program; incorporate Cybersecurity topic in firm’s Annual Compliance Meeting.
  • Consult with IT/Legal Experts, as required.

[1]           Order available at http://www.sec.gov/litigation/admin/2015/ia-4204.pdf; Press Release at http://www.sec.gov/news/pressrelease/2015-202.html.[2]           17 C.F.R. §248-30(a).[3]           The Advisor was also censured and required to pay  a $75,000 civil  penalty.[4]           OCIE’s 2015 Cybersecurity Examination Initiative, IV National Exam Program Risk Alert, Sept. 15, 2015, https://www.sec.gov/ocie/announcement/ocie-2015 – cybersecurity-examination.initiative.pdf.  National Exam Program Risk Alert, Feb. 3, 2015, at https://www.sec.gov/about/offices/ocie/cybersecurity-examination-sweep-summary.pdf.  IM Guidance Update No. 2015-02 (April 2015), at http://www.sec.gov/investment/im-guidance-2015-02.pdf

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
Scarinci Hollenbeck Expands NYC Real Estate and Litigation Practices ADDING Four Litigators post image

Scarinci Hollenbeck Expands NYC Real Estate and Litigation Practices ADDING Four Litigators

NYC Real Estate and Litigation Attorney Ryan O. Miller and Team Join Scarinci Hollenbeck, LLC New York City, NY – August 13, 2025 – Scarinci Hollenbeck, LLC has strengthened its Real Estate and Litigation practices with the addition of four New York City-based attorneys. Ryan Miller, who joins as a partner, is well known for […]

Author: Scarinci Hollenbeck, LLC

Link to post with title - "Scarinci Hollenbeck Expands NYC Real Estate and Litigation Practices ADDING Four Litigators"
Bloomberg Law Podcast Discusses Shaquille O’Neil FTX Settlement With Ron Bienstock post image

Bloomberg Law Podcast Discusses Shaquille O’Neil FTX Settlement With Ron Bienstock

Bloomberg Law Podcast Discusses Shaquille O’Neil FTX Settlement With Ron Bienstock Little Falls, NJ – June 24, 2025 – Scarinci & Hollenbeck, LLC Partner and Chair of the firm’s Intellectual Property and Entertainment & Media departments Ronald S. Bienstock recently joined the Bloomberg Law podcast to discuss Shaquille O’Neal settling a class-action lawsuit over his FTX endorsement. […]

Author: Scarinci Hollenbeck, LLC

Link to post with title - "Bloomberg Law Podcast Discusses Shaquille O’Neil FTX Settlement With Ron Bienstock"
Donald M. Pepe Leads Donation of Laptops to York Street Project post image

Donald M. Pepe Leads Donation of Laptops to York Street Project

Scarinci Hollenbeck Partner Facilitates Donation of 43 Laptops to Jersey City Organization Little Falls, NJ – July 1, 2025 – Scarinci Hollenbeck, LLC is proud to recognize partner Donald M. Pepe’s dedication to the community by facilitating the donation of 43 new Dell laptops to the York Street Project. Don’s commitment and dedication to sourcing […]

Author: Scarinci Hollenbeck, LLC

Link to post with title - "Donald M. Pepe Leads Donation of Laptops to York Street Project"
Feedspot Names Government & Law Blog One of the Top Public Law Blogs post image

Feedspot Names Government & Law Blog One of the Top Public Law Blogs

FeedSpot Recognizes Donald Scarinci’s Government & Law Blog One of the Top 20 Public Law Blogs Little Falls, NJ – May 22, 2025 – Scarinci Hollenbeck, LLC is honored to share that Managing Partner Donald Scarinci’s Government & Law blog has been listed by FeedSpot.com as one of the “20 Best Public Law Blogs and […]

Author: Scarinci Hollenbeck, LLC

Link to post with title - "Feedspot Names Government & Law Blog One of the Top Public Law Blogs"
Scarinci Hollenbeck's Ron Bienstock Speaks at 100th Bomb Group's 2025 Reunion post image

Scarinci Hollenbeck's Ron Bienstock Speaks at 100th Bomb Group's 2025 Reunion

SH Partner and 100th Bomb Group Foundation Legal Counsel Discussed The Nuremberg Trials and the Law May 21, 2025 – Little Falls, NJ – Scarinci & Hollenbeck, LLC is proud to share that partner Ronald S. “Ron” Bienstock recently spoke at the 100th Bomb Group Biennial Reunion, held May 15-18, 2025, in New Orleans. The […]

Author: Ronald S. Bienstock

Link to post with title - "Scarinci Hollenbeck's Ron Bienstock Speaks at 100th Bomb Group's 2025 Reunion"
FeedSpot Names Donald Scarinci’s Constitutional Law Reporter One of the Top 100 Legal Blogs  post image

FeedSpot Names Donald Scarinci’s Constitutional Law Reporter One of the Top 100 Legal Blogs 

Little Falls, NJ – May 1, 2025 – Scarinci Hollenbeck, LLC is proud to share that Managing Partner Donald Scarinci’s Constitutional Law Reporter blog has been listed by FeedSpot.com as one of the “Top 100 Legal Blogs.” No Aspect of the advertisement has been approved by the Supreme Court. Feedspot, a content reader that curates websites of […]

Author: Donald Scarinci

Link to post with title - "FeedSpot Names Donald Scarinci’s Constitutional Law Reporter One of the Top 100 Legal Blogs "

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!