How the SEC will police advisers' lax cybersecurity

The SEC may be refining its approach to spurring good cybersecurity practices in advisers, but its expectations aren't slackening.

There's been "a conscious decision" at the agency to lead through the exam process, rather than enforcement, said David Glockner, regional director of the SEC's Chicago office.

"There've been a handful of enforcement cases in this area," Glockner said, "but if you step back and think about it, there are way more incidents, way more issues that pop up in exams than there are enforcement referrals or enforcement actions."

But even if the commission will discipline advisers sparingly and bring actions in the most egregious cases, officials want advisers to demonstrate that they are taking the issue seriously. Examiners will expect to review a firm's policies and procedures for protecting against data breaches and other threats to sensitive information.

SEC_RealEstate_Bloomberg

Amit Ranjan is Executive Vice President, Global Head of Data and Risk Analytics at Xceedance, a global consulting, technology, and operations leader for insurance organizations. With 25 years of diverse experience, he oversees catastrophe modeling, actuarial and data insight services. He specializes in leveraging advanced modeling techniques, statistical analysis, and data-driven strategies to optimize underwriting, pricing, and portfolio management.

59m ago
Amit Ranjan

David Klasing Esq. CPA M.S.-Tax, is founder and managing attorney at the Tax Law Offices of David W. Klasing. He has earned dual California licenses that enable him to simultaneously practice as an attorney and as a CPA in the practice areas of taxation, estate planning and business law. He provides businesses and individuals with tax representation, planning and compliance services, and criminal tax representation. He has more than 20 years of professional tax, accounting and business consulting experience, coupled with extensive knowledge about federal and state tax codes, regulations and case law.

1h ago
David Klasing

Nicole is a strategic HR leader with demonstrated experience collaborating with all levels of leadership to drive successful People initiatives in dynamic and fast-paced environments. Known as an out-of-the-box thinker who offers creative and effective solutions to support an exceptional employee experience and drive high performing teams.

Her industry experience includes technology, wellness, consumer goods, entertainment, and aerospace & defense. Experienced with global organizations, both private and public, spanning start-up to established large firms. She is skilled in engaging complex, evolving, distributed, and diverse employee populations to achieve business results.

3h ago
Nicole MacMillian

As a starting point, officials recommend advisers take an inventory of their digital assets to determine the various entry points that hackers could take to infiltrate their systems, including a thorough vetting of all the outside vendors a firm contracts with.

Compliance slideshow

Regulators have revealed what kind of issues advisors must address if faced with a review.

1 Min Read

To ensure that personnel throughout the firm are cognizant of the myriad cyber threats, the SEC urges firm leaders to elevate the issue as a business priority, appealing for a tone at the top that prevents cybersecurity issues from being marginalized as simply a matter for the IT department.

But in some firms, there remains a tension between business and cybersecurity concerns, according to Steven Levine, an associate regional director at the SEC's Chicago office.

Levine has warned about the compliance and supervision challenges facing the growing number of advisory firms that have adopted the broker-dealer model of maintaining a home office and multiple branches.

Often, branch managers look to bring in high-producing industry veterans who might resist the firm's cybersecurity policies and procedures, which puts additional onus on the chief compliance officer to lay down the law, Levine says.

For reprint and licensing requests for this article, click here.
Cyber security Compliance Regulatory actions and programs SEC
MORE FROM FINANCIAL PLANNING