Cybersecurity in the Time of COVID-19

For many firms, a remote workforce is now a new reality. Even with many states’ shelter-in-place restrictions lifting, firms are continuing with their work-from-home strategies for the majority of their staff. This transition and the related challenges have forced firms to re-evaluate their current cybersecurity and remote policies and procedures. The following considerations are important to ensure that your remote staff has the tools in place to adhere to regulatory rules, firm procedures, and best practices.

Read More…


Highlights from FINRA Small Firm Conference Call: Part 1

Earlier this month, FINRA hosted a Small Firm Conference Call to discuss updates and implications of COVID-19 (Coronavirus). If you were not able to listen to the call live, a replay recording is available on demand. This recording provides and discusses many highlights noted in FINRA’s FAQs Related to Coronavirus Pandemic.

Read More…


Teleworking Considerations During COVID-19 Pandemic

Many financial service institutions have been hesitant to create teleworking processes and systems that would give them more flexibility to service clients and build the business. However, within the regulatory framework, landmines appear at every turn.

Read More…

Enforcement Actions

SEC Enforcement Actions: Key Takeaways for 2020

Enforcement actions can be scary, especially if you or your Firm are named in the enforcement. For the rest of us, enforcement actions provide valuable information on patterns of misconduct, rule violations, and overall cautionary tales.

Read More…

safeguarding client data

Safeguarding Client Information

With the transition into the electronic storage of client data, Investment Advisers and Broker-Dealers are faced with more complex compliance issues regarding safeguarding client information and records. The United States Securities and Exchange Commission (“SEC”) OCIE Risk Alert from May 2019 addresses some of the issues and concerns identified with cloud-based storage and possible issues to consider regarding the protection of electronic client and business data.

Read More…

NASAA Proposes Information Security Rule for RIAs

The North American Securities Administrators Association, Inc. (“NASAA”) is requesting public comment regarding a proposed model rule for information security and privacy for registered investment advisers (RIAs) under the Uniform Securities Acts Of 1956 And 2002. NASSA has been actively working on addressing various investment adviser-related cybersecurity concerns and desires for several years and has identified a significant need for more information and tools regarding cybersecurity.

Read More…

Cybersecurity Programs Remain a Priority in 2018

Cybersecurity programs remain a significant priority for financial services industry regulators, including the SEC, FINRA, and state securities regulatory agencies. As mentioned in FINRA’s 2018 Annual Regulatory and Examination Priorities Letter, member firms need to have cybersecurity programs in place and such programs must capable of protecting sensitive information, including personally identifiable information of clients, from both internal and external threats. Over the past couple of years, awareness of cybersecurity risk has increased dramatically. However, as awareness increases, so does the sophistication of cybersecurity threats. And even a robust cybersecurity program can be compromised by something as simple as an employee opening an email attachment that contains malware. So, what can a firm do to combat phishing and spearphishing attacks, ransomware attacks, fraudulent third-party wires, etc.?

Read More…

Cybersecurity Breaches: Post SEC & Equifax Hacks, Firms Should Revisit Their Cybersecurity Program

Recently, two major cybersecurity breaches have been in the news which have been very unsettling for many Americans.  First, Equifax, one of the nation’s largest credit bureaus, was hacked exposing 143 million people’s financial data.  Second, the Securities and Exchange Commission’s (“SEC”) EDGAR filing system was hacked and it is believed that the hackers made off with information that was used to make money illegally in the stock market. Read More…