The SEC’s Cybersecurity Assessment: A Roadmap for Companies Nationwide

May 14, 2014

Reading Time : 1 min

The exam focuses on six key areas:

1. Identification of cybersecurity risks and corporate governance.

2. Protection of networks and information.

3. Risks associated with remote customer access and funds transfer requests.

4. Risks associated with vendors and other third parties.

5. Detection of unauthorized activity.

6. Experiences with certain cybersecurity threats and application of the Identity Theft Red Flag Rules.

The Risk Alert provides a seven-page appendix that details sample questions related to cybersecurity and data protection risk. Many of the questions in the Risk Alert appendix track language outlined in the Cybersecurity Framework released by the Department of Commerce’s National Institute of Standards and Technology in February of this year. The Risk Alert is the first clear application of the NIST guidelines at the SEC level. The Risk Alert also appears to encourage information sharing, specifically asking whether any cyber events were shared with law enforcement, FinCEN, FINRA, any state or federal regulatory agency, or any industry-specific organization. The questions related to experiences with certain cybersecurity threats should be reviewed by any SEC-reporting company, as it appears to outline the types of threats that the SEC may consider important in disclosing in a company’s risk factors.

The SEC’s release of the sample exam questions sends a clear signal to registered securities professionals: analyze your cybersecurity risk management process and make any modifications before the SEC comes knocking on your door. The exam results will inform any future rulemaking, which, after the SEC’s Cybersecurity Roundtable, seems likely. And although the Risk Alert specifically applies to registered broker dealers and investment advisers, any organization would benefit from reviewing the 28-question list and determining areas for improvement.

Share This Insight

Previous Entries

Deal Diary

April 12, 2023

Read More

Deal Diary

2022-12-15

On December 14, 2022, the Securities and Exchange Commission (SEC) adopted amendments regarding Rule 10b5-1 insider trading plans and related disclosures. The amendments aim to strengthen investor protections concerning insider trading and to help shareholders understand when and how insiders are trading in securities for which they may at times have material nonpublic information (MNPI). In light of these amendments, issuers should review and revise, if needed, their insider trading policies and equity grant policies.

Read more.

...

Read More

© 2024 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.