Regulation S-P requires registered investment advisers, investment companies, and broker-dealers to provide notice to customers and maintain written records of policies and procedures related to information privacy.
On December 20, 2018, the Financial Industry Regulatory Authority (FINRA) released a Report on Selected Cybersecurity Practices (the “2018 Report”). In it, FINRA outlines five topics of focus.
The SEC’s Office of Compliance Inspections and Exams (“OCIE”) has announced that cybersecurity will continue to be a focal point for its examinations in 2019.
On December 14th, 2018, the SEC’s OCIE released a Risk Alert reminding advisers of their obligations regarding the use of electronic messaging.
SEC charges broker-dealer for failure to provide adequate cybersecurity policies and procedures. Contact us for help developing SEC-compliant policies.
The National Institute for Standards and Technology (NIST) released an updated version of its Cybersecurity Framework, known as version 1.1.
On March 22nd, Peter Driscoll, OCIE Director, announced plans for its third cybersecurity sweep exam in four years. The next cyber initiative will focus on advisers who maintain remote offices and advisers that have merged firms.
Cisco’s Talos Intelligence Group has identified a targeted cyber-attack focusing on specific organizations.
The SEC provided an update on its ongoing staff investigation of the 2016 cyber intrusion into the EDGAR system.
On September 25, 2017, the SEC announced the creation of the Enforcement Division’s Cyber Unit and Retail Strategy Task Force.