Social engineering schemes include vishing and smishing; these schemes are becoming more common among employees who use personal devices for work. Fortunately, there are steps your organization can take to remain aware and vigilant about evolving social engineering attack risks.
In recent years, the SEC has heightened its emphasis on cybersecurity requirements for firms. Routine examinations now often involve in-depth requests for information on firms’ cyber and data security practices, which are areas of evolving risk for all market participants.
The OCIE issued a Risk Alert that outlines new compliance risks stemming from the global pandemic. The SEC and OCIE have remained operational and have continued to initiate examinations, including routine examinations of investment advisers.