Cybersecurity: Time’s Up!

Social engineering and ransomware continue to top the list of cybersecurity threats, according to the 2016 Verizon Data Breach Investigations Report released a few weeks ago. Alarmingly, the report shows the amount of time to compromise and exfiltrate data is measured in seconds and minutes for 28.3% of cyberattacks.
Time is of the essence when a potential incident occurs. When you have mere seconds to make a decision on how to contain and mitigate an attack, it is critical to have a robust incident response plan in place and to test it periodically to ensure that all staff know their roles and responsibilities.

Ascendant has created incident response plans for advisers of various shapes and sizes, and a key element to each one has been establishing clear lines for reporting and prompt escalation. I am thrilled that we will be featuring an interactive incident response planning session at our upcoming national compliance conference in San Diego, California in September 2016.  Even firms who have adopted a solid incident response plan can benefit from incident response planning exercises – because the change in a single fact may alter the course of action you should take. But don’t take my word for it. As Verizon’s annual data breach report states, you have time. Three minutes and 45 seconds, to be exact.*

(*Median time from when a social engineering test is conducted to when the first recipient clicks to open the would-be malicious attachment).

Latest Content

Schedule 13D/13F Clarity on ETF Issues

Do I need to file a 13D or 13G if my client accounts hold in excess of 5% of an ETF? Generally, no. The SEC has granted no-action relief to ETFs with respect to compliance with Section 13(d) of the Securities Exchange Act. Section 13(d) was designed to require disclosure when holders begin to accumulate … Continued

New Remedy Coming for SEC’s Custody Rule?

The SEC’s Custody Rule continues to be a common source of confusion and a landmine for noncompliance. Custodial paperwork has caused huge headaches for investment advisers, who are not a party to the agreement and may not even have a copy of the custodial new account paperwork. The issue with existing guidance is that it … Continued

SEC Issues MiFID II No-Action Relief

Some industry anxiety was assuaged on October 26 with three no-action letters that offer relief for some US regulated broker-dealers and investment advisers regarding European MiFID II regulations. The letters followed consultation with the European authorities, and are designed to address concerns that investors could lose access to valuable research. MiFID II is a series of regulations … Continued

Regulatory Changes Impacting RICs and Service Providers

A year ago, the SEC adopted Investment Company Reporting Modernization Rules and Forms, as well as rules pertaining to liquidity risk management programs and swing pricing. New forms N-Port and N-Cen along with amendments to Regulation S-X significantly change the current reporting regime for most registered investment companies (RICs) because they require more comprehensive disclosure and … Continued

Publicly Available Information Heightens Need for Cybersecurity Vigilance

For any business, “ports” that allow for communication generally need to be open (for example, ports 80 and 443 for websites, and port 500 for VPN access). While most of these ports allow you to engage in critical functions, there are often ports that remain open despite being unneeded or unused. These available ports present … Continued

Mailing List

Subscribe to the Ascendant Compliance email list for the latest compliance resources, conferences, ComplianceCasts™, and more.

Loading form...

Contact Us

Ascendant works together with clients to identify and assess critical needs through customized plans. If you need assistance with compliance functions, regulatory services, cybersecurity or technology tools, we’d love to speak with you.