Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

What Ever Happened to the SEC’s Cybersecurity Sweep?

Posted on February 4, 2015September 26, 2017 by Doug Cornelius
Print Friendly, PDF & Email

univac

The Securities and Exchange Commission put the financial sector in a tizzy when it announced a sweep exam addressing cybersecurity last April. Along with the announcement came a detailed document request list that would make most compliance officers’ heads spin.

The problem with the cybersecurity sweep is that it seems to be coming from the wrong people and is addressed to the wrong people. When I think of the Securities and Exchange Commission I don’t think of hacking and data security. I think of lawyers and accountants. When I think of financial services compliance officers, I also think of lawyers and accountants.

Maybe that is overly specific. But I don’t think of cybersecurity experts in either case.

It’s not that cybersecurity is not important to the industry. It’s very important. Clients must have faith that their investments will not be stolen. Historically, the role of the SEC has been to make sure the financial professional is not stealing from its clients. Cybersecurity imposes a requirement that unknown hackers are not stealing from the financial professional’s clients.

The cybersecurity sweep went to 57 registered broker dealers and 49 registered investment advisers and looked at the legal, regulatory, and compliance issues.

The SEC’s Risk Alert on Cybersecurity details the findings.

I’m going to guess that that each bullet point is now a new standard that a firm will need to meet. The alert does not say so, but I’m going to use it as a blueprint for an additional review of cybersecurity.

Sources:

  • SEC Alerts Investors, Industry on Cybersecurity
  • Risk Alert-Cybersecurity
  • Investor Bulletin-Cybersecurity

Share this:

  • Print (Opens in new window) Print
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on X (Opens in new window) X
  • Email a link to a friend (Opens in new window) Email

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • PERE 100 and SEC Registration
  • Neither Admit Nor Deny To Be No Longer
  • What Will Form PF Look Like Next Year?
  • Is It a Chipset or Is It a Security?
  • When the Lawyer Is Breaking Bad
  • Will Investors Have an Appetite for Semi-Annual Reporting?
  • Special Forces Trading on Insider Knowledge
  • Prediction Markets and Compliance Programs
  • The One with the Line That Goes Straight Up and Right
  • The One with the Crypto Paying for a Mega-Shilling Package

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.