From: Reed Smith
Article by Timothy J. Nagle and Sarah R. Wolff
Starting with the Securities and Exchange Commission’s January 2014 announcement that cybersecurity is a priority in its National Examination Program, SEC Chair Mary Jo White and others at the SEC have continued to stress the significance of the cybersecurity threat in speeches and in congressional testimony. Recently, the Commission hosted a Cybersecurity Roundtable to discuss the issues and challenges that cybersecurity presents for market participants and public companies, as well as for regulators. Panelists from government, financial institutions and public companies participated in four panels on the cybersecurity risk landscapeāpublic company disclosure, resilience of market systems, and issues affecting broker-dealers, investment advisors, and transfer agents. Each panel was moderated by an SEC director with responsibility in that area. As Chair White observed in her opening remarks, the threat of a cybersecurity breach is global, and the public and private sectors must work together to address these threats. Thereafter, she actively participated throughout all of the sessions, and was joined by her fellow commissioners at various times during the almost day-long forum. In his prepared remarks, Commissioner Aguilar called for the establishment of a cross-division Cybersecurity Task Force within the SEC, acknowledging that the Commission “has much to learn about the specific risks that our regulated entities and public companies are facing.”
Much of the discussion was familiar territory to those following cybersecurity issues, particularly in the financial services industry. The panels on cybersecurity risk, market systems and SEC-regulated advisors included discussions related to such issues as:
- The need for the public and private sectors to exchange information and clarity around what can be shared.
- The role that Regulations S-ID (Identity Theft Red Flags rule released in coordination with the Commodity Futures Trading Commission) and S-CI (Systems Compliance and Integrity) can play in addressing cybersecurity threats and aiding resiliency of financial markets.
- The impact of the presidential executive order that was issued last year, andĀ the recent publication by the National Institute of Standards and Technology of a Cybersecurity Framework after consultation with all sectors and industries.
- The concern about the market’s ability to withstand and recover from a concerted cyber attack. Such an event could impact the confidentiality and integrity of trading information, as well as the infrastructure connecting the various trading platforms. Several panelists observed that there is no common “reset” point to which all systems could uniformly return in the event of market shutdown.
Leave a Reply