Broker-dealers need to respond to recent focus on cybersecurity threats
David Petron, Michael D. Wolk, Edward R. McNicholas · Journal of Investment Compliance · 2014
Purpose – To alert broker-dealers to several regulatory developments relating to cybersecurity threats. Design/methodology/approach – Reviews four regulatory developments in the cybersecurity area and provides several steps broker-dealers should undertake to review and improve their cybersecurity and information technology protocols and practices. Findings – While FINRA’s new cybersecurity sweep appears to be an exploratory and learning exercise to obtain regulatory knowledge and intelligence, firms should be cognizant of the fact that both FINRA and the SEC have imposed significant sanctions against Firms when it has found inadequate cyber security policies and procedures. Practical implications – Broker-dealers should review the White House’s recent Framework for Improving Critical Infrastructure Cybersecurity and evaluate their own cybersecurity preparedness under the key areas of the Framework. Originality/value – Practical guidance from experienced privacy and securities regulatory lawyers that consolidates several recent developments in one piece.