Voya cybersecurity blunder should serve as a wake-up call to the entire industry

Voya cybersecurity blunder should serve as a wake-up call to the entire industry
The stakes are high: Procedures have to be reviewed and tested on a regular basis.
OCT 06, 2018
By  crain-api
By now, anyone responsible for cybersecurity at a financial advisory firm is probably tired of hearing about the subject. But the recent $1 million fine levied against Voya Financial Services should serve as a wake-up call to everyone in the industry for several reasons.

Cybercrime details

For one, it describes in detail an actual cybercrime and how it occurred — and how the firm failed not only to prevent it, but to shut it down adequately once being alerted that the breach was happening. The Voya story also represents the first time the Securities and Exchange Commission has fined a company under its Identity Theft Red Flags rule, and puts all firms on notice that the regulator is ramping up cybersecurity enforcement. In other words, expect more fines in the future.

Procedures in place

Like most other firms, Voya had security procedures in place that should have guarded against the breach that occurred back in 2016. In this case, cybercriminals posing as advisers asked for and received usernames and new passwords from Voya support personnel, giving them access to the personal information of 5,600 customers. Even after one of the real advisers who had been targeted in this identity theft scam reported that he had not requested a new password, the scheme was not thwarted. Over the next several days, two more advisers were impersonated. In fining Voya, the SEC said the breach occurred, in part, because its personnel did not have a full understanding of how its own portal worked.

Prevention and response

One hard lesson Voya learned is that having procedures and protocols in place is not enough. Procedures have to be reviewed and tested on a regular basis to make sure personnel are trained and are following protocols correctly — and that the procedures and protocols in place are still effective in both preventing and responding to cyberattacks. (More: How a hacker led to Finra censuring and fining a broker-dealer) Companies also need to be more proactive in anticipating cyberattacks. Thieves can be creative. If you stop them from breaching your systems one way, they will try to get their hands on your protected data using different methods. They won't stop, so companies can't let down their guard.

Need for review

It is not enough simply to draw up a cybersecurity plan and put it on the shelf to show regulators when they ask for it during an exam; it must constantly be updated using the latest information on what cyberthieves are up to. That brings us to yet another lesson. Cybersecurity comes with a cost. But it is a cost that cannot be ignored. The SEC's regulations apply to all firms in the industry, no matter their size. And remember, the stakes are high. Clients and investors will usually forgive a security breach one time. But if it reoccurs, they will flee to a competitor with a better record on security. And who can really blame them?

Latest News

Creative Planning's Peter Mallouk slams 'offensive' congressional stock trading
Creative Planning's Peter Mallouk slams 'offensive' congressional stock trading

"This shouldn’t be hard to ban, but neither party will do it. So offensive to the people they serve," RIA titan Peter Mallouk said in a post that referenced Nancy Pelosi's reported stock gains.

Raymond James hauls Ameriprise advisors managing $1.1B in New York
Raymond James hauls Ameriprise advisors managing $1.1B in New York

Elsewhere, Sanctuary Wealth recently attracted a $225 million team from Edward Jones in Colorado.

Cetera debuts new alts allocation portfolios for accredited investors
Cetera debuts new alts allocation portfolios for accredited investors

The giant hybrid RIA is elevating its appeal to advisors with a curated suite of alternative investment models, offering exposure to private equity, private credit, and real estate.

Steward Partners expands in California with $1.1 billion RIA acquisition
Steward Partners expands in California with $1.1 billion RIA acquisition

The $40 billion RIA firm's latest West Coast deal brings a veteran with over 25 years of experience to its legacy division for succession-focused advisors.

Invictus managers withhold $10M, trigger ERISA asset showdown
Invictus managers withhold $10M, trigger ERISA asset showdown

Invictus fund managers allegedly kept $10 million in plan assets after removal, setting off a legal fight that raises red flags for wealth firms.

SPONSORED How advisors can build for high-net-worth complexity

Orion's Tom Wilson on delivering coordinated, high-touch service in a world where returns alone no longer set you apart.

SPONSORED RILAs bring stability, growth during volatile markets

Barely a decade old, registered index-linked annuities have quickly surged in popularity, thanks to their unique blend of protection and growth potential—an appealing option for investors looking to chart a steadier course through today's choppy market waters, says Myles Lambert, Brighthouse Financial.