The Devil Really is in the Details: The SEC Proposed Rule on Cybersecurity Risk Management for Investment Advisors, Registered Investment Companies and BDCs
Late last month the Securities and Exchange Commission (“SEC”) charged JP Morgan, UBS and Trade Station with violations of Regulation S-ID based on a range of inadequacies in their identity theft red flag policies and procedures. https://www.sec.gov/news/press-release/2022-131 The violations at issue might seem less than critical, such as not updating policies, merely copying over examples of red flags from Reg S-ID’s Appendix A, not incorporating specific policies into the red flag program, covering all accounts instead of conducting specific account assessments, and not providing sufficient detail in board reports. Although the SEC did not note any failure by these broker-dealers and investment advisors to actually detect and respond to identity theft red flags, the resulting orders and fines (up to $1.2 million), underline the SEC’s seriousness about protecting investors from cybercrime by requiring broker dealers and investment advisors to up their game and focus on the details.
3 Insights From the Fidelity RIA Benchmarking Study
Fidelity conducted an RIA Benchmarking Study to identify and analyze key performance metrics for RIAs. The intended goal was to evaluate individual performance rates and provide recommendations for improving revenue streams and growing clientele.
SEC fines J.P. Morgan, UBS, TradeStation total of $2.5 million for lax ID theft prevention
The Securities and Exchange Commission announced Wednesday that it imposed a total of $2.5 million in fines on J.P. Morgan Securities, UBS Financial Services Inc. and TradeStation Securities Inc. for deficiencies related to their efforts to protect customers from identity theft.
SEC Boosts its Bandwidth, Nearly Doubles the Size of the Division of Enforcement’s Crypto Assets and Cyber Unit
On May 3, 2022 the Securities and Exchange Commission (the “SEC”) announced the addition of 20 new positions to the Division of Enforcement’s newly renamed Crypto Assets and Cyber Unit (formerly known as the Cyber Unit), expanding the Crypto Assets and Cyber Unit to 50 positions (the “Announcement”).[i] With its expanded numbers, the Crypto Assets and Cyber Unit will continue to identify cybersecurity disclosure and control issues and will focus on investigating:
Behavioral psychology training reduces cybersecurity risks
Cybersecurity is now battling a human problem just as much, if not more, than a technical one.
According to Verizon’s 2021 Data Breach Investigations Report, 85% of successful cyberattacks now involve a human element. Combine that with the fact that even the very best technology can only thwart about 93% of attacks, and that leaves a large hole in an organization’s basic security hygiene. This gap forces employees to make split decisions that can affect security, and failure to choose correctly puts disaster just a click away.
New RIA? Time to prep for an SEC audit!
If you haven’t planned for an SEC audit, you should.
Why? Because you are likely to face one. Advances in technology and the adoption of a data-centric approach have made it fast and easy for the SEC to comprehensively audit even the smallest firm, regardless of its location.
Compromised Email Account Leads to Data Breach at Private Client Services, LLC
Recently, Private Client Services, LLC (“PCS”) confirmed that the company experienced a data breach after an unauthorized party gained access to sensitive consumer information through a compromised employee email account. According to the PCS, the breach resulted in the names, Social Security numbers, driver’s license numbers and state identification numbers being compromised. On May 27, 2022, PCS filed official notice of the breach and sent out data breach letters to all affected parties. In total, the company sent out 22,554 letters.
SEC Cyber Regulation Efforts: A Mid-Year Review
2022 is not even halfway over, and the Securities and Exchange Commission (SEC) has already made it a banner year for the SEC’s efforts to shape cybersecurity policy. This alert highlights this year’s cyber developments to date and the SEC’s likely future regulatory efforts in this space.
Carrot or Stick? States Try Incentives to Increase Cybersecurity
Several states are offering legal safe harbors to businesses that follow industry-recommended cybersecurity frameworks, in a carrot-not-stick approach intended to encourage better defenses.
SEC Bolsters Teams Tackling Cybersecurity - Is Your Firm Ready
The Securities and Exchange Commission has bolstered the size of its teams dealing with cybersecurity and cryptocurrency, according to the associate director of its enforcement division. Last year, the Securities and Exchange Commission sanctioned eight firms for cybersecurity failures.