SEC risk alert calls on advisory industry to do more to shore up cybersecurity

Advisory firms given more details on how examiners want systems protected from hackers.
AUG 08, 2017

Financial advisory firms are getting more advice from federal regulators on steps they should be taking to protect their information systems from hackers. Advisory firms need to do a better job of following their stated cybersecurity policies and they should correct all the vulnerabilities that periodic tests reveal, according to results from a new round of cybersecurity examinations by staff at the Securities and Exchange Commission. Advisers also need to do a better job of keeping the firm's security patches up-to-date, the new SEC exam risk alert said. It contained findings from 75 cybersecurity exams of advisory firms, broker dealers and funds conducted from September 2015 through June 2016. "The staff observed that a few of the firms had a significant number of system patches, that according to the firms, included critical security updates that had not yet been installed," the staff of the Office of Compliance Inspections and Examinations wrote. The importance of timely installation of security patches was highlighted earlier this year when the "WannaCry" ransomware attack hit more than 200,000 computers in 150 countries, encrypting computers and demanding $300 to release each computer. The malware spread through a bug in an old Windows version that Microsoft had issued a "critical" patch to fix two months earlier. (More: Cyberattack should prompt advisers to ask their IT professionals hard questions) The attack in May was especially damaging because it had a mechanism to spread through the network, infecting other computers that hadn't been updated. The SEC issued an alert specific to the issue of ransomware soon after the massive hack. Another area where firms should improve is in maintaining response plans for addressing data breaches and letting clients know about material events. Less than two-thirds of advisers have these plans in place, the alert said. The SEC alert also said broker-dealers were not doing as good a job as advisers and funds at having formal procedures for verifying customers' identities when clients request electronic transfers. (More: Passwords to become passé as more firms back biometrics) Federal regulators generally have been less prescriptive than some states when it comes to giving financial services firms detailed requirements for protecting their systems from attacks. Colorado recently implemented new rules requiring annual assessments, use of secure email, including digital signatures and encryption, and New York also has set specific rules for financial institutions. "The SEC hasn't been very specific about what it wants firms to do on cybersecurity," said Justin Kapahi, vice president for solutions and security at External IT. "I think we'll see a lot more states follow Colorado's lead." In the new alert, the SEC said the firms with robust cybersecurity protections reviewed the effectiveness of their security solutions with penetration tests, tracked access rights of employees, had formal patch management policies, made training mandatory, and established data access controls for mobile devices that used passwords and software that encrypted communications, among other steps.

Latest News

No succession plan? No worries. Just practice in place
No succession plan? No worries. Just practice in place

While industry statistics pointing to a succession crisis can cause alarm, advisor-owners should be free to consider a middle path between staying solo and catching the surging wave of M&A.

Research highlights growing need for personalized retirement solutions as investors age
Research highlights growing need for personalized retirement solutions as investors age

New joint research by T. Rowe Price, MIT, and Stanford University finds more diverse asset allocations among older participants.

Advisor moves: RIA Farther hails Q2 recruiting record, Raymond James nabs $300M team from Edward Jones
Advisor moves: RIA Farther hails Q2 recruiting record, Raymond James nabs $300M team from Edward Jones

With its asset pipeline bursting past $13 billion, Farther is looking to build more momentum with three new managing directors.

Insured Retirement Institute urges Labor Department to retain annuity safe harbor
Insured Retirement Institute urges Labor Department to retain annuity safe harbor

A Department of Labor proposal to scrap a regulatory provision under ERISA could create uncertainty for fiduciaries, the trade association argues.

LPL Financial sticking to its guns with retaining 90% of Commonwealth's financial advisors
LPL Financial sticking to its guns with retaining 90% of Commonwealth's financial advisors

"We continue to feel confident about our ability to capture 90%," LPL CEO Rich Steinmeier told analysts during the firm's 2nd quarter earnings call.

SPONSORED How advisors can build for high-net-worth complexity

Orion's Tom Wilson on delivering coordinated, high-touch service in a world where returns alone no longer set you apart.

SPONSORED RILAs bring stability, growth during volatile markets

Barely a decade old, registered index-linked annuities have quickly surged in popularity, thanks to their unique blend of protection and growth potential—an appealing option for investors looking to chart a steadier course through today's choppy market waters, says Myles Lambert, Brighthouse Financial.