Morgan breach offers universal data security lessons

Advisers need to keep client data safe from internal hacks, not just those from outside cybercriminals.
AUG 12, 2014
Client data breaches by a now-fired Morgan Stanley broker offer a glaring heads-up to advisory firms that they need cybersecurity measures that root out internal hacks as well as outside criminals. Morgan Stanley uncovered the online posting of information about 900 of its wealthy clients last month during routine monitoring. It moved quickly to identify broker Galen Marsh, 30, as the culprit and have the data taken down, the Wall Street firm said earlier this week. Morgan Stanley said no client was impacted by the actions of Mr. Marsh, whom the firm fired. He allegedly took data regarding 350,000 wealthy clients and was looking online for a buyer of login and password information. Many advisory firms today would be challenged to prevent such an internal theft. A lot of firms lack an information security plan that maintains client data in a secure location and restricts it to those who need to access that information, said Gary Davis, Jr., MarketCounsel's vice president for practice management. Firms need to have such policies as part of their compliance manual, he said. “Make sure that your firm has a data security plan in place to help manage the privacy of client information and mitigate breaches from occurring,” he said. “No matter what size the firm is, they need to have this in place.” The plan should be more than just a boilerplate that a firm downloads or that is provided by its custodian, he said. It needs to be customized for the firm's unique procedures and business practices. (More: 10 ways advisers can improve their cybersecurity) Another step firms can take when an employee with access to client passwords leaves the firm is to notify clients they should change their password so there's no opportunity for that former employee to illegally access that account, Mr. Davis said. Broker-dealers and custodians typically subscribe to cybersecurity services that monitor online postings, but advisory firms typically don't have the resources to do that, he said. As part of an adviser's due diligence, though, Mr. Davis said it's appropriate for an advisory firm to ask these larger firms about their efforts to safeguard client information. (More: "SEC exam sweep reveals adviser cyberefforts") Joel Bruckenstein, a technology expert and consultant to financial firms, said the human factor “is one of the most difficult to guard against.” He recommends that firms have strict controls over who is allowed to see client data. “For someone who had recently been promoted to being an adviser, I don't see how [Mr. Marsh] could have had needed access to 350,000 client names,” he said in reference to the Morgan Stanley breach. “Best practices would dictate that employees can only see what they need to do their jobs.”

Latest News

The 2025 InvestmentNews Awards Excellence Awardees revealed
The 2025 InvestmentNews Awards Excellence Awardees revealed

From outstanding individuals to innovative organizations, find out who made the final shortlist for top honors at the IN awards, now in its second year.

Top RIA Cresset warns of 'inevitable' recession amid tariff uncertainty
Top RIA Cresset warns of 'inevitable' recession amid tariff uncertainty

Cresset's Susie Cranston is expecting an economic recession, but says her $65 billion RIA sees "great opportunity" to keep investing in a down market.

Edward Jones joins the crowd to sell more alternative investments
Edward Jones joins the crowd to sell more alternative investments

“There’s a big pull to alternative investments right now because of volatility of the stock market,” Kevin Gannon, CEO of Robert A. Stanger & Co., said.

Record RIA M&A activity marks strong start to 2025
Record RIA M&A activity marks strong start to 2025

Sellers shift focus: It's not about succession anymore.

IB+ Data Hub offers strategic edge for U.S. wealth advisors and RIAs advising business clients
IB+ Data Hub offers strategic edge for U.S. wealth advisors and RIAs advising business clients

Platform being adopted by independent-minded advisors who see insurance as a core pillar of their business.

SPONSORED Compliance in real time: Technology's expanding role in RIA oversight

RIAs face rising regulatory pressure in 2025. Forward-looking firms are responding with embedded technology, not more paperwork.

SPONSORED Advisory firms confront crossroads amid historic wealth transfer

As inheritances are set to reshape client portfolios and next-gen heirs demand digital-first experiences, firms are retooling their wealth tech stacks and succession models in real time.