Advisor Armor Advisor Armor

SEC issues proposed cyber rule

The SEC issued a proposed cybersecurity rule applicable to registered investment advisers and registered investment companies, but did not issue the rule to publicly traded companies.

The rule requires notification to the Commission within 48 hours of discovering a significant cybersecurity incident.

The rule also requires extensive policies and procedures, including a written information security plan and incident response plan, to address and respond to cybersecurity threats.

Companies will be required to increase disclosures and recordkeeping around cybersecurity practices, risks, and incidents.

Read More
Advisor Armor Advisor Armor

SEC Chair Gensler Remarks Indicate 2022 Action Expanding Cyber Requirements - How Advisors Should Prepare

U.S. Securities and Exchange Commission (SEC) Chair Gary Gensler made remarks on Jan. 24, 2022, at Northwestern University Pritzker School of Law's Annual Securities Regulation Institute regarding the SEC's work to improve "the … cybersecurity posture and resiliency of the financial sector." Consistent with Holland & Knight's recent SECond Opinions Blog post highlighting the SEC's more aggressive cyber posture in 2021, Gensler indicated that the SEC will consider updating existing cybersecurity disclosure and reporting rules and requirements in 2022 for entities regulated by the SEC and expanding cybersecurity requirements on those entities falling outside the agency's direct regulatory regime.

Read More
Advisor Armor Advisor Armor

SEC Chief Wants Advisors, BDs to Improve ‘Cyber Hygiene’

What You Need to Know

  • Gensler has asked for recommendations on how advisors and BDs can strengthen their cybersecurity and incident reporting.

  • Gensler sees opportunities to expand Regulation S-P, a rule about protecting customers' personal data.

  • He also wants to broaden Reg SCI to more types of firms, like big market makers, BDs and Treasury trading platforms.

Read More
Advisor Armor Advisor Armor

The 2021 Year in Review and What to Expect in Data Security in 2022

This year saw a number of significant changes on both the state and federal levels with regard to data privacy and data security. These changes reflect the increasing focus on the digital landscape to which the global economy has shifted and emphasized a much sharper focus on protecting sensitive information. Indeed, the significance of having strong cybersecurity regulations was emphasized from the top down in the United States, including an emphasis on improving and updating cybersecurity defenses and protections for federal government networks, as outlined in President Biden's May 12, 2021 Executive Order on Improving the Nation's Cybersecurity. This article highlights the legislative and litigation developments in 2021 and discusses what may lie ahead in 2022 for businesses that collect, process, and store sensitive information.

Read More
Advisor Armor Advisor Armor

3 Steps to a Safer RIA

What You Need to Know

  • Of the 6.3 billion global web attacks in 2020, 736 million targeted the financial services business.

  • The most likely cybersecurity threats for a small office are manageable, even for a non-technical employee.

  • Beware of non-computer items that offer gateways to your network, like coffee makers.

Read More
Advisor Armor Advisor Armor

Employees are the first line of cyber defense

Companies of all sizes have adapted to remote and hybrid models for the workplace, and many are making the changes permanent as employees grow accustomed to this new environment. Today’s digital economy presents unique opportunities for small and medium-sized businesses (SMBs) to connect with employees and customers in new and efficient ways but comes with considerable cyber risk.

Read More