Small advice firms show increase in cyber-related issues

Small advice firms show increase in cyber-related issues
State regulator exams also indicate fewer problems with fees and other areas.
SEP 09, 2019
State-registered investment advisers are showing more deficiencies related to cybersecurity but are improving their compliance in many other areas, such as books and records, fees and supervision, according to state securities regulators. In its latest coordinated exams of investment advisers, the North American Securities Administrators Association said regulators found cybersecurity problems in 26% of the reviews, compared to 23% in 2017, the last time coordinated exams were conducted. Regulators in 41 states conducted examinations of 1,078 advisers between January and June. They released the results Sunday at the NASAA annual conference in Austin, Tex. This year, 292 advisers were being reviewed for the first time. State-registered advisers have less than $100 million in assets under management. About 67% of those examined had AUM of more than $30 million and 33% had AUM of less than $30 million. Cybersecurity deficiencies included inadequate insurance, lack of vulnerability testing and weak or infrequently changed passwords. [Recommended video: Race is on to boost diversity of the advice business] State regulators have put an increasing emphasis on cybersecurity. It was not even a category in 2015 exams. Earlier this year, however, NASAA released a cybersecurity model rule. "Smaller companies are the low hanging fruit for cybercriminals, and when you consider that more than three-fourths of the nearly 18,000 state-registered investment advisers are 1- to 2-person shops, it is clear how important cybersecurity should be for these small businesses as well," Michael S. Pieciak, NASAA president and Vermont Commissioner of Financial Regulation, said in a statement. The coordinated exams indicated the biggest area of compliance problems for investment advisers was books and records (59.5% of exams showed at least one deficiency) followed by registration (49.5%), contracts (43.9%), cybersecurity and fees (20.7%). But the number of deficiencies in every category other than cybersecurity are lower than they were in the 2015 exams — and in many categories also lower than reported in 2017. "Cybersecurity is the exception because that is a new area," said Mike Huggs, director of the Mississippi Securities Division and head of the coordinated exams. "I would expect deficiencies to be on the rise, as both regulators and registrants are coming to grips and learning about cybersecurity." (More: Ask these cybersecurity questions) But Mr. Huggs said he is pleased to see state-registered advisers stepping up their compliance in other areas. He attributes part of the improvement to regulators' efforts to inform advisers about their expectations. "I don't think we've implemented anything different — except just keeping at it," Mr. Huggs said in an interview. "Seventy percent of what we do out there in the field is teach." The exam results showed advisers are hearing the message. "You're getting the point across," Mr. Huggs told his NASAA colleagues during an annual conference session on the coordinated exams.

Latest News

The 2025 InvestmentNews Awards Excellence Awardees revealed
The 2025 InvestmentNews Awards Excellence Awardees revealed

From outstanding individuals to innovative organizations, find out who made the final shortlist for top honors at the IN awards, now in its second year.

Top RIA Cresset warns of 'inevitable' recession amid tariff uncertainty
Top RIA Cresset warns of 'inevitable' recession amid tariff uncertainty

Cresset's Susie Cranston is expecting an economic recession, but says her $65 billion RIA sees "great opportunity" to keep investing in a down market.

Edward Jones joins the crowd to sell more alternative investments
Edward Jones joins the crowd to sell more alternative investments

“There’s a big pull to alternative investments right now because of volatility of the stock market,” Kevin Gannon, CEO of Robert A. Stanger & Co., said.

Record RIA M&A activity marks strong start to 2025
Record RIA M&A activity marks strong start to 2025

Sellers shift focus: It's not about succession anymore.

IB+ Data Hub offers strategic edge for U.S. wealth advisors and RIAs advising business clients
IB+ Data Hub offers strategic edge for U.S. wealth advisors and RIAs advising business clients

Platform being adopted by independent-minded advisors who see insurance as a core pillar of their business.

SPONSORED Compliance in real time: Technology's expanding role in RIA oversight

RIAs face rising regulatory pressure in 2025. Forward-looking firms are responding with embedded technology, not more paperwork.

SPONSORED Advisory firms confront crossroads amid historic wealth transfer

As inheritances are set to reshape client portfolios and next-gen heirs demand digital-first experiences, firms are retooling their wealth tech stacks and succession models in real time.