SEC Emphasizes Cybersecurity Preparedness in Wake of Global Ransomware Attack

Ballard Spahr LLP
Contact

Ballard Spahr LLP

The U.S. Securities and Exchange Commission's Office of Compliance Inspections and Examinations (OCIE) has issued a Risk Alert in the wake of the widespread WannaCry ransomware attack that has inflicted hundreds of thousands of users since last week.

The OCIE stated that the Risk Alert was intended to highlight "the importance of conducting penetration tests and vulnerability scans on critical systems and implementing system upgrades on a timely basis."Specifically, the Risk Alert recommends that broker-dealers and investment management firms review the U.S. Computer Emergency Readiness Team’s Alert TA17-132A "Indicators Associated With WannaCry Ransomware" and evaluate whether applicable Microsoft patches for Windows XP, Windows 8, and Windows Server 2003 operating systems are properly and timely installed.

The Risk Alert also discussed a recent survey of 75 SEC registered broker-dealers, investment advisers, and investment companies conducted by OCIE's National Examination Program staff. The survey assessed the entities' cybersecurity preparedness, finding "a wide range of information security practices, procedures, and controls across registrants that may be tailored to the firms' operations, lines of business, risk profile and size." Specifically, the survey found:

  • 26 percent of advisers and 5 percent of broker-dealers did not conduct periodic risk assessments of critical systems to identify cybersecurity threats and vulnerabilities;

  • 57 percent of investment management firms and 5 percent of broker-dealers did not conduct penetration testing; and

  • 10 percent of broker-dealers and 4 percent of investment management firms had a significant number of critical and high-risk security patches that were not properly updated (editorial note: this is the type of cyber hygiene failure that led to the WannaCry ransomware attack of last week).

OCIE also reiterated its April 2015 Cybersecurity Guidance in which it recommended that investment companies and advisers take the following actions:

  • Conduct a periodic assessment of:

    • the nature, sensitivity, and location of information that the firm collects, processes and/or stores, and the technology systems it uses;

    • internal and external cybersecurity threats to and vulnerabilities of the firm’s information and technology systems;

    • security controls and processes currently in place;

    • the impact should the information or technological systems become compromised; and

    • the effectiveness of the governance structure for the management of cybersecurity risk. An effective assessment would assist in identifying potential cybersecurity threats and vulnerabilities so as to better prioritize and mitigate risk.

  • Create a strategy that is designed to prevent, detect, and respond to cybersecurity threats. Such a strategy could include:

    • controlling access to various systems and data via management of user credentials, authentication and authorization methods, firewalls and/or perimeter defenses, tiered access to sensitive information and network resources, network segregation, and system hardening;

    • data encryption;

    • protecting against the loss or exfiltration of sensitive data by restricting the use of removable storage media and deploying software that monitors technology systems for unauthorized intrusions, the loss or exfiltration of sensitive data, or other unusual events;

    • data backup and retrieval; and

    • the development of an incident response plan. Routine testing of strategies could also enhance the effectiveness of any strategy.

  • Implement the strategy through written policies and procedures and training that provide guidance to officers and employees concerning applicable threats and measures to prevent, detect, and respond to such threats, and that monitor compliance with cybersecurity policies and procedures. Firms may also wish to educate investors and clients about how to reduce their exposure to cybersecurity threats concerning their accounts.

The OCIE's Risk Alert once again highlights the importance of cybersecurity preparedness in this field. The Risk Alert comes only weeks after the Colorado Division of Securities published proposed rules directed at establishing cybersecurity requirements for broker-dealers and investment advisers. The Colorado Division of Securities conducted a public hearing on the proposed rules on May 2, 2017, and received comments on May 9, 2017. The final rules are expected to be published in June.

For a summary of the WannaCry attack and the steps companies can take to avoid future cybersecurity incidents, read Ballard Spahr’s Alert "Is Your Organization Ready for a Systemwide Ransomware Attack?"

 

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Ballard Spahr LLP | Attorney Advertising

Written by:

Ballard Spahr LLP
Contact
more
less

Ballard Spahr LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide