Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

Cybersecurity Preparedness Exams Results Are In!

Author: Scarinci Hollenbeck, LLC

Date: February 10, 2015

Key Contacts

Back

The Securities and Exchange Commission (SEC) recently published the results of its cybersecurity preparedness examinations of more than 100 broker-dealers and investment advisers.

The report highlights that while investment firms are increasingly being targeted by cyberattacks, they are also actively taking steps to address the threats.  The SEC’s Cybersecurity Preparedness Examination Initiative included 57 registered broker-dealers and 49 registered investment advisers, who were selected by the agency to provide perspectives from a cross-section of the financial services industry and to assess various firms’ vulnerability to cyber-attacks.

Examiners specifically gathered information regarding the firms’ practices for: identifying risks related to cybersecurity; establishing cybersecurity governance; protecting firm networks and information; identifying and addressing risks associated with remote access to client information and funds transfer requests; identifying and addressing risks associated with vendors and other third parties; and detecting unauthorized activity.

Below are some of the SEC’s key findings:

  • Cyberattacks are common. A majority of the broker-dealers (88%) and the advisers (74%) stated that they have experienced cyber-attacks directly or through one or more of their vendors.
  • The majority of the incidents are related to malware and fraudulent emails. Approximately half of the examined firms reported receiving fraudulent emails seeking to transfer client funds. More than one-quarter of broker-dealers reported losses related to fraudulent emails of more than $5,000; however, no single loss exceeded $75,000. One adviser reported a loss in excess of $75,000 related to a fraudulent email, for which the client was made whole.
  • Most firms have written policies and procedures in place. A large percentage of examined broker-dealers (93%) and advisers (83%) have adopted written information security policies. However, few address how firms determine whether they are responsible for client losses associated with cyber incidents.
  • Data security is a top concern. Almost all the examined broker-dealers (98%) and advisers (91%) make use of encryption in some form.
  • Most broker-dealers (93%) and advisers (79%) conduct periodic risk assessments, on a firm-wide basis, to identify cybersecurity threats, vulnerabilities, and potential business consequences. However, a much smaller percentage (only 32% of advisers) report that they conduct the same assessments of their vendors.
  • The use of cybersecurity insurance varied by industry. More than half of the broker-dealers maintain policies that expressly cover cybersecurity incidents and losses. In contrast, less than one-quarter of the advisers examined maintain cybersecurity insurance.

In connection with the report, the SEC also released an Investor Bulletin that contains tips for protecting online brokerage accounts from fraud. Recommended precautions include picking a strong password, enabling two-factor authentication, avoiding the use of public computers/public wireless connections to access investment accounts, exercising caution when clocking email links, and regularly reviewing account statements for suspicious activity.

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
A Simple Guide to Industry Roll-Up Acquisitions post image

A Simple Guide to Industry Roll-Up Acquisitions

When done successfully, industry roll-up acquisitions can dramatically grow and strengthen your business. In this post, we break down what an industry roll-up is, why companies pursue it, and what makes it an effective (and sometimes risky) business strategy. What Is an Industry Roll-Up Acquisition? In an industry roll-up acquisition of companies, a buyer acquires multiple companies […]

Author: Dan Brecher

Link to post with title - "A Simple Guide to Industry Roll-Up Acquisitions"
Genesis Mission: How the U.S. Government’s New AI Platform Will Reshape Corporate Innovation, Risk, and Competition post image

Genesis Mission: How the U.S. Government’s New AI Platform Will Reshape Corporate Innovation, Risk, and Competition

The federal government has launched one of the most ambitious scientific initiatives in decades, and it will redefine how companies develop technology, manage risk, and compete. The Genesis Mission, created by Executive Order and driven by the Department of Energy (“DOE”), is intended to accelerate scientific discovery through a national AI platform that links supercomputers, […]

Author: Michael J. Sheppeard

Link to post with title - "Genesis Mission: How the U.S. Government’s New AI Platform Will Reshape Corporate Innovation, Risk, and Competition"
Stablecoins and the GENIUS Act: How New Global Rules Are Reshaping Compliance post image

Stablecoins and the GENIUS Act: How New Global Rules Are Reshaping Compliance

Stablecoins Leave the Grey Zone Stablecoins were supposed to be the “boring” part of crypto: digital dollars that just work. Yet for years they have lived in a regulatory no-man’s-land, classified one day as securities, the next as commodities, and sometimes as something regulators had not even named yet. That uncertainty is finally starting to […]

Author: Bryce S. Robins

Link to post with title - "Stablecoins and the GENIUS Act: How New Global Rules Are Reshaping Compliance"
Don’t Overlook the Importance of Business License Management post image

Don’t Overlook the Importance of Business License Management

If you operate a business without the proper license, you risk fines, insurance issues, reputational harm, and even business closure. Even innocent mistakes, like forgetting to renew a license, can have significant consequences, such as losing your lawsuit for payment of services that are unlicensed, which makes it imperative to have business license management procedures […]

Author: Dan Brecher

Link to post with title - "Don’t Overlook the Importance of Business License Management"
Failing to Comply With NJ Rent Control Exemption May Prove Costly post image

Failing to Comply With NJ Rent Control Exemption May Prove Costly

What Developers Need to Know About New Jersey’s Rent Control Exemption Law to Ensure Entitlement to Exemption for Newly Constructed Multi-family Housing.  A property owner in Jersey City is facing a $400 million federal class action lawsuit alleging that the landlord did not follow the procedural steps required to be eligible for exemption from local […]

Author: Patrick T. Conlon

Link to post with title - "Failing to Comply With NJ Rent Control Exemption May Prove Costly"
Crypto Securities Law: When Tokens Become Investment Contracts post image

Crypto Securities Law: When Tokens Become Investment Contracts

The application of traditional federal securities laws to crypto assets continues to evolve. In some cases, the Securities and Exchange Commission (SEC) considers tokens and other digital assets to be securities. This makes them subject to federal securities law, including the Securities Act of 1933 and the Securities Exchange Act of 1934. This classification has […]

Author: Bryce S. Robins

Link to post with title - "Crypto Securities Law: When Tokens Become Investment Contracts"

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!