Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

Cybersecurity: a growing risk imperative #CFOandCOO

Posted on May 18, 2016 by Doug Cornelius
Print Friendly, PDF & Email

I’m attending the PERE CFOs & CCOs Forum. These are my notes from the session.

PERE

On a scale of 1 to 5 the attendees created a classic bell curve on how confident we felt about our cybersecurity programs, with most choosing “3.”

The panel labeled social engineering as the upcoming threat. There were several stories of fake invoices coming from outside the firm, spoofed to look like it was coming from within the firm. The other example was malware injected into the it system by a junior person opening a malware file sent through email.

Cybersecurity should be part of the regular compliance training. Focus spoofing and phishing prevention training on those who can move funds or authorize funds to move.

Cybersecurity is now a common item on SEC exams. Be ready to answer questions.

Hackers tend to be opportunistic. They need to see a weakness or they are more likely to move on to another target. The scary problem is when our firm is specifically targeted.

The panelists seem to have some strict rules on the use of personal email. The challenge is that younger workers are used to collaborative tools and easier access to information.

For mobile devices, the standard is to be able wipe the phone remotely in case it is lost to keep information secure. Make sure everyone knows to quickly report a lost phone.

Cybersecurity is part of fundraising. It is a very common item on investors’ due diligence questionnaires. Although probing beyond the questions tends to be limited.

Cyberinsurance is becoming more common. The coverage is expanding. It covers losses. It does not necessarily cover all of the incident response.

Share this:

  • Print (Opens in new window) Print
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on X (Opens in new window) X
  • Email a link to a friend (Opens in new window) Email

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • The SEC 2026 Rulemaking Agenda
  • The Alignment Gap: Rethinking Costs in Private Equity Fund Formation
  • PERE 100 and SEC Registration
  • Neither Admit Nor Deny To Be No Longer
  • What Will Form PF Look Like Next Year?
  • Is It a Chipset or Is It a Security?
  • When the Lawyer Is Breaking Bad
  • Will Investors Have an Appetite for Semi-Annual Reporting?
  • Special Forces Trading on Insider Knowledge
  • Prediction Markets and Compliance Programs

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.