SEC alerts advisers on WannaCry ransomware cyberattacks

Regulator stresses vulnerability testing and timely system upgrades.
MAY 17, 2017

The Securities and Exchange Commission staff issued a cybersecurity alert to broker-dealers, advisers and investment funds Wednesday in the wake of the pervasive ransomware cyberattack over the past five days known as "WannaCry." The alert from the Office of Compliance Inspections and Examinations emphasized the importance of firms conducting penetration tests and vulnerability scans on critical systems and stressed the necessity of upgrading systems on a timely basis. The ransomware attack that was unleashed last week was especially damaging because it had a mechanism to spread through networks, looking to infect other computers that hadn't been updated to stop the worm. The regulator said it doesn't expect firms to anticipate and prevent every cyberstrike, but it highlighted the importance of thinking about these issues in advance of an incident. (More: Cyberattack should prompt advisers to ask their IT professionals hard questions) "Appropriate planning to address cybersecurity issues, including developing a rapid response capability, is important and may assist firms in mitigating the impact of any such attacks and any related effects on investors and clients," the alert said. WannaCry infects computers with malicious software that encrypts users' files and demands payment to regain access to the data. The ransomware attack hit more than 200,000 computers in 150 countries in recent days. (More: Online security ETFs surge in face of cyberattacks) The SEC staff alert said a recent OCIE examination of 75 firms found that 5% of broker-dealers and 26% of advisers and investment funds did not conduct periodic risk assessments of critical systems to uncover vulnerabilities, potential business consequences and other cybersecurity threats. The alert also recommended firms review the U.S. Department of Homeland Security's Computer Emergency Readiness Team's warning about cybersecurity actions firms might want to consider in reaction to the latest ransomware incident.

Latest News

SEC to lose Hester Peirce, deepening a commissioner crisis
SEC to lose Hester Peirce, deepening a commissioner crisis

The "Crypto Mom" departure would leave the SEC commission with just two members and no Democratic commissioners on the panel.

Florida B-D, RIA owner pitches bold long-term plan to sell to advisors
Florida B-D, RIA owner pitches bold long-term plan to sell to advisors

IFP Securities’ owner, Bill Hamm, has a long-term plan for the firm and its 279 financial advisors.

Fintech bytes: Vanilla, Wealth.com forge new estate planning partnerships
Fintech bytes: Vanilla, Wealth.com forge new estate planning partnerships

Meanwhile, a Osaic and Envestnet ink a new adaptive wealthtech partnership to better support the firm's 10,000-plus advisors, and RIA-focused VastAdvisor unveils native integrations with leading CRMs.

Fiduciary failure: Ex-advisor who sold practice fined after clients lost millions
Fiduciary failure: Ex-advisor who sold practice fined after clients lost millions

A former Alabama investment advisor and ex-Kestra rep has been permanently barred and penalized after clients he promised to protect got caught in a $2.6 million fraud.

Why the evolution of ETFs is changing the due diligence equation
Why the evolution of ETFs is changing the due diligence equation

As more active strategies get packaged into the ETF wrapper, advisors and investors have to look beyond expense ratios as the benchmark for value.

SPONSORED Are hedge funds the missing ingredient?

Wellington explores how multi strategy hedge funds may enhance diversification

SPONSORED Beyond wealth management: Why the future of advice is becoming more human

As technical expertise becomes increasingly commoditized, advisors who can integrate strategy, relationships, and specialized expertise into a cohesive client experience will define the next era of wealth management