Cybersecurity Troubles At Financial Firms – Seven Regulatory Actions To Consider

From: Mondaq

Article by Kenneth L. Greenberg | Stradley Ronon Stevens & Young LLP

“Those who do not remember the past are condemned to repeat it.” — George Santayana

Frequently in the cybersecurity field, we try to look ahead to anticipate the next threat, that zero-day attack. In this article on cybersecurity, we take a look back and review a handful of regulatory actions initiated by the Securities and Exchange Commission or the Financial Industry Regulatory Authority to glean some lessons learned from cybersecurity vulnerabilities. The SEC is the primary regulator for investment companies, investment advisers and broker-dealers, and FINRA is a self-regulatory organization for broker-dealers.

Regulatory actions initiated by the SEC and FINRA relating to computer/information security are most often grounded in violations of Regulation S-P rather than the SEC’s or FINRA’s anti-fraud enforcement authority.1 Rule 30 of Regulation S-P (referred to as the Safeguards Rule), which implemented the privacy provisions in Title V of the Gramm- Leach-Bliley Act of 19992 provides:

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *