Cybersecurity & 2017 SEC Exam Priorities

In September 2015, the SEC announced it was starting Phase 2 Cybersecurity Exam Initiative exams in which the SEC started doing more in-depth testing of policies, procedures and controls at firms. For example: testing a firm’s access provisioning policy by standing over the shoulder of various employees to confirm whether they could or couldn’t access certain files and folders on the network.

In January 2016, the SEC’s Exam Priorities announced a continuation of the Phase 2 exams.

Now in January 2017, it appears that Phase 2 is over, and this more in-depth testing has found its way into SEC examinations in general.

Granted, some exams might not focus on cybersecurity at all, but the ones that do are likely to now include a more in-depth examination of it, and the SEC will be looking to corroborate that you are doing what your policies say you are doing, and that you have policies on things they expect you to have policies on when it comes to cyber.

At the upcoming Ascendant Compliance Management conference, “Revolutionizing Compliance: The Matrix of Regulation, Operations & Technology,” we will be covering things on the SEC’s cybersecurity request list – what documentation they expect, what types of controls they expect, what policies they expect; how to test various policies ahead of time; ways to improve your firm’s training and security awareness program – since some firms are being called out for inadequate cyber training and since the SEC is using the benefit of hindsight to fine firms that have a cyber incident that comes to light during an exam.

Translation: more training reduces the likelihood of a cyber incident in the first place.

If you need to gain a deeper understanding of the SEC’s views of cybersecurity and how it might affect your firm, join us in Naples on April 3-5. For more information, read our agenda by clicking here.

Related Content

Latest Content

Regulation Best Interest, Cybersecurity Top Concerns at IAA 2019 Compliance Conference

The Investment Adviser Association (IAA) represents the interests of investment advisers in Washington D.C., and the IAA Investment Adviser Compliance Conference 2019 was a forum for the discussion of future potential rulemaking. Cybersecurity and Fiduciary Rule considerations were headline topics, with custody and marketing right behind. The following is a summary of key issues discussed … Continued

The Challenges of Building a Global Compliance Program

Compliance programs face challenges in balancing global requirements with local exceptions while incorporating the fast pace of regulatory change, addressing critical business needs and obtaining the necessary resources necessary to manage the program. Trends and thinking on the subject were center stage at the recent CSS London event “Looking at the Year Ahead – Global … Continued

Coming to America – California Adopts GDPR-Like Privacy Regulation

After a number of firms struggled last year to get their marketing and information systems into compliance with the EU’s General Data Protection Regulation (GDPR), advisers to U.S. clients will soon be facing similar requirements on the home front.  On the heels of the Cambridge Analytica scandal, California enacted the California Consumer Privacy Act of … Continued

SEC and FINRA 2019 Examination Priorities

The SEC and FINRA have recently released their examination priorities for 2019. These releases provide insight into regulatory priorities and serve as guidance for a firm in evaluating its compliance program. We will discuss topics covered in these releases, including: Protecting retail investors Fees and expenses Disclosure Conflicts of interest Suitability Protecting senior investors Trading … Continued

SEC Reopened After 35-Day Government Shutdown

SEC Chairman Jay Clayton announced on Saturday, January 26 that with an agreement reached to end the government shutdown, the “Commission has resumed normal staffing levels and is returning to normal operations.” In total, about 94% of the commission’s approximately 4,400 employees had been furloughed during the 35-day shutdown, according to its operations plan. In a … Continued

Mailing List

Subscribe to the Ascendant Compliance email list for the latest compliance resources, conferences, ComplianceCasts™, and more.

Loading form...

Contact Us

Ascendant works together with clients to identify and assess critical needs through customized plans. If you need assistance with compliance functions, regulatory services, cybersecurity or technology tools, we’d love to speak with you.