Cybersecurity & 2017 SEC Exam Priorities

In September 2015, the SEC announced it was starting Phase 2 Cybersecurity Exam Initiative exams in which the SEC started doing more in-depth testing of policies, procedures and controls at firms. For example: testing a firm’s access provisioning policy by standing over the shoulder of various employees to confirm whether they could or couldn’t access certain files and folders on the network.

In January 2016, the SEC’s Exam Priorities announced a continuation of the Phase 2 exams.

Now in January 2017, it appears that Phase 2 is over, and this more in-depth testing has found its way into SEC examinations in general.

Granted, some exams might not focus on cybersecurity at all, but the ones that do are likely to now include a more in-depth examination of it, and the SEC will be looking to corroborate that you are doing what your policies say you are doing, and that you have policies on things they expect you to have policies on when it comes to cyber.

At the upcoming Ascendant Compliance Management conference, “Revolutionizing Compliance: The Matrix of Regulation, Operations & Technology,” we will be covering things on the SEC’s cybersecurity request list – what documentation they expect, what types of controls they expect, what policies they expect; how to test various policies ahead of time; ways to improve your firm’s training and security awareness program – since some firms are being called out for inadequate cyber training and since the SEC is using the benefit of hindsight to fine firms that have a cyber incident that comes to light during an exam.

Translation: more training reduces the likelihood of a cyber incident in the first place.

If you need to gain a deeper understanding of the SEC’s views of cybersecurity and how it might affect your firm, join us in Naples on April 3-5. For more information, read our agenda by clicking here.

Latest Content

DOL Fiduciary Rule Transition Period Extension to 2019 Requested

The Secretary of Labor, Alexander Acosta, made a court filing on August 9 requesting the Transition Period and Delay of Applicability for the Department of Labor Fiduciary Rule be extended from January 1, 2018 to July 1, 2019. This court filing included extending the deadlines for the following Prohibited Contract Exemptions: Best Interest Contract Exemption … Continued

SEC Cyber Sweep Highlights Areas In Need of Improvement

The results of the SEC’s second cybersecurity sweep examinations are in, and they paint a picture of an industry that has come to grips with the need to address cybersecurity risk, but where the canvas is incomplete in many respects.

Colorado Joins New York in Mandating Cybersecurity Controls for Financial Institutions

On the heels of the recently adopted New York State Department of Financial Services Cybersecurity Regulation (23 NYCRR 500), Colorado has followed suit with its own set of protections. The Colorado Division of Securities has issued cybersecurity regulations applicable to broker dealers and investment advisers registered with the state, which are codified in Sections 51-4.8 … Continued

Form ADV: What You Need to Know Now to Prepare for October

October 2017 new Form ADV amendments continue the big data trend. Form ADV continues to expand ever more rapidly as data mining and handling techniques by regulators allow for the utilization of Form ADV for risk measurement. Ease the burden of answering over 100 separate questions (plus scores more for each private fund) through this … Continued

Electronic Messaging Exams: Looking Beyond Emails

The SEC is conducting “electronic messaging” examinations -- mainly in the New York region -- which include all forms of written communications related to an Adviser's business.

Mailing List

Subscribe to the Ascendant Compliance email list for the latest compliance resources, conferences, ComplianceCasts™, and more.

Loading form...

Contact Us

Ascendant works together with clients to identify and assess critical needs through customized plans. If you need assistance with compliance functions, regulatory services, cybersecurity or technology tools, we’d love to speak with you.