Colorado Division of Securities Adopts New Investment Adviser Compliance Program Rule
This is the second in a three-part series discussing the newly amended rules (collectively the “Rules”) adopted by the Colorado Division of Securities (“Division”) effective as of March 30, 2023 (the “Effective Date”) applicable to certain Colorado investment advisers and their registered representatives (“IARs”). The Rules mostly affect investment advisers registered with Colorado State (such advisers, “Colorado Licensed Advisers”).
SEC cyber oversight still priority as concerns grow
The U.S. Securities and Exchange Commission will continue to review broker-dealers’ and advisers’ cybersecurity practices next year, the agency said in a report issued Monday.
“Operational disruption risks remain elevated due to the proliferation of cybersecurity attacks, firms’ dispersed operations, intense weather-related events, and geopolitical concerns,” the agency said in its “2024 Examination Priorities, Division of Examinations” report.
Cybersecurity and Cybersecurity Compliance is Not One Thing…It’s Two
Cybersecurity and Cybersecurity Compliance share the same objective (protecting sensitive data from cyber threats), but they aren’t the same thing. They are related but have different focuses.
Regulatory Compliance & Cyber Insurance from Advisor Armor - “We thought that should be a thing”
Under the proposed SEC Cybersecurity Risk Management Rules, firms would need to have documented processes in place to mitigate and respond to “significant cybersecurity incidents” and report them to the SEC when they happen—including whether any losses are covered by insurance policies…
The SEC Is About To Rock Your World
The SEC is about to upend your firm when it comes to cybersecurity.
Last year, the agency proposed a series of new rules, heading toward approval likely later this year. Although not yet final, they are going to shake up the ways RIAs run their businesses.
SEC Adopts New Cybersecurity Reporting Rules, Setting Up Various Compliance Challenges
The SEC Cybersecurity Rules strive to enhance and standardize disclosures regarding cybersecurity incidents, risk management, strategy, and governance. Public companies subject to the reporting requirements of the Securities Exchange Act of 1934 will be subject to new disclosure requirements regarding (1) cybersecurity incidents, and (2) cybersecurity risk management, strategy, and governance. The rules also significantly expand cyber compliance obligations for registered investment advisers (RIAs), investment companies and broker-dealers.
The SEC's Proposed Cybersecurity Rules: Regulatory Delay Does Not Bless Standing By
Key Takeaways
Since 2022, the U.S. Securities and Exchange Commission (SEC) has proposed several cybersecurity rules applicable to numerous regulated entities that, if adopted, would impose quick notification obligations and heightened disclosure requirements.
Amid significant pushback during the public comment period, the SEC announced it would delay issuance of these rules, which are now expected to be finalized in October 2023 and April 2024.
Because cybersecurity risks will continue to evolve more rapidly than the SEC’s public rulemaking process, public companies, investment advisers, broker-dealers, and other entities that may be impacted by these rules should not wait to address these risks, even in the face of regulatory uncertainty.
After all, the SEC has already brought enforcements actions relating to cybersecurity incidents even in the absence of these proposed rules being finalized, and existing SEC and other regulatory frameworks already require baseline disclosure, notification, and safeguarding measures that these proposed SEC rules seek to enhance.
Third-Party Risk Management: A Critical Task for Cybersecurity and Breach Prevention
We are all familiar with the mantra on the importance of managing third-party risk to prevent anti-corruption, sanctions, money laundering and associated risks. Over the last ten years, however, we have observed a new and important addition to the third-party risk plate – cybersecurity and data breach.
AI Will Heighten Cybersecurity Risks for RIAs
While scams like email impersonation and phishing are nothing new, generative AI has supercharged the risks by introducing new threats, including deepfakes and malicious chatbots.
Remarks of SEC Enforcement Director on Cyber Resilience
Gurbir S. Grewal, Director of the SEC’s Division of Enforcement, spoke on the topic of cyber resilience at the Financial Times Cyber Resilience Summit. Director Grewal defined cyber resilience as a guiding concept: because cybersecurity incidents are likely to occur, companies must be prepared to respond and react appropriately when they do.