Finra warns brokerages to pay attention to rising cybersecurity threats

Finra warns brokerages to pay attention to rising cybersecurity threats
The broker-dealer self-regulator highlighted a recent government advisory about a ransomware attack and told member firms to brush up on Finra's guidance on the topic from last December.
JUN 20, 2023

Finra is warning brokerages to pay attention to rising cybersecurity threats, highlighting a recent advisory about a ransomware attack.

The Financial Industry Regulatory Authority Inc. sent an alert to its member firms Friday pointing to a Cybersecurity & Infrastructure Security Agency advisory from earlier this month. That alert, which was issued jointly with the Federal Bureau of Investigation, analyzed the tactics, techniques and procedures used by an outfit called the Ransomware Gang that is targeting financial services and other critical sectors.

The cyber criminals took advantage of a weakness in MOVEit, a file transfer system provided by Progress Software, to infiltrate their targets’ technology systems, according to the Finra alert.

“All Finra member firms should review Finra’s cybersecurity alert, regardless of whether [they] use MOVEit,” Amber Allen, executive vice president and general counsel at the consulting firm Fairview and president of Fairview Cyber, wrote in an email.

The alert “represents yet another move by regulators to tighten cybersecurity within the financial industry. Advisors who have not reviewed their cyber programs should do so as soon as possible,” Allen said.

Jim Scheinberg, managing partner at North Pier Search Consulting, said firms can’t afford to brush off Finra’s warning.

“They should be taking this very seriously,” Scheinberg said. “The threat of an attack is very real.”

The broker-dealer self-regulator used the latest ransomware intrusion to highlight its own regulatory notice about ransomware from last December, which provided guidance on how firms can evaluate their cybersecurity practices.

“Finra member firms should work to establish thorough risk assessment programs, tailored policies and procedures, comprehensive testing and ongoing training programs,” Allen said. “Adopting a well-documented incident response plan is critical to a firm’s success give the increase in cybersecurity threats and regulatory focus.”

Both Finra and the Securities and Exchange Commission are zeroing in on cybersecurity. The SEC released last year a cybersecurity proposal for registered investment advisors and followed up earlier this year with a proposal for broker-dealers.

Scheinberg’s firm does due diligence investigations of third-party providers for fiduciary advisory services, investment management and other functions. He said cybersecurity assessments are becoming more important in the outsourcing evaluation process.

“The time to know whether you’re ready for a fire is not when a fire is breaking out in your building,” Scheinberg said.

Cybersecurity also was highlighted as an examination priority this year by both Finra and the SEC.

Latest News

RIA moves: True North adds $353M California RIA as SageView grows North Carolina presence
RIA moves: True North adds $353M California RIA as SageView grows North Carolina presence

Plus, a $400 million Commonwealth team departs to launch an independent family-run RIA in the East Bay area.

Blue Owl Capital, Voya strike private market partnership for retirement plans
Blue Owl Capital, Voya strike private market partnership for retirement plans

The collaboration will focus initially on strategies within collective investment trusts in DC plans, with plans to expand to other retirement-focused private investment solutions.

Top Commonwealth advisor to recruiters: Stop with the cold calls already!
Top Commonwealth advisor to recruiters: Stop with the cold calls already!

“I respectfully request that all recruiters for other BDs discontinue their efforts to contact me," writes Thomas Bartholomew.

Why AI notetakers alone can't fix 'broken' advisor meetings
Why AI notetakers alone can't fix 'broken' advisor meetings

Wealth tech veteran Aaron Klein speaks out against the "misery" of client meetings, why advisors' communication skills don't always help, and AI's potential to make bad meetings "100 times better."

Morgan Stanley, Goldman, Wells Fargo to settle Archegos trades lawsuit
Morgan Stanley, Goldman, Wells Fargo to settle Archegos trades lawsuit

The proposed $120 million settlement would close the book on a legal challenge alleging the Wall Street banks failed to disclose crucial conflicts of interest to investors.

SPONSORED How advisors can build for high-net-worth complexity

Orion's Tom Wilson on delivering coordinated, high-touch service in a world where returns alone no longer set you apart.

SPONSORED RILAs bring stability, growth during volatile markets

Barely a decade old, registered index-linked annuities have quickly surged in popularity, thanks to their unique blend of protection and growth potential—an appealing option for investors looking to chart a steadier course through today's choppy market waters, says Myles Lambert, Brighthouse Financial.