Cybersecurity: Time’s Up!

Social engineering and ransomware continue to top the list of cybersecurity threats, according to the 2016 Verizon Data Breach Investigations Report released a few weeks ago. Alarmingly, the report shows the amount of time to compromise and exfiltrate data is measured in seconds and minutes for 28.3% of cyberattacks.
Time is of the essence when a potential incident occurs. When you have mere seconds to make a decision on how to contain and mitigate an attack, it is critical to have a robust incident response plan in place and to test it periodically to ensure that all staff know their roles and responsibilities.

Ascendant has created incident response plans for advisers of various shapes and sizes, and a key element to each one has been establishing clear lines for reporting and prompt escalation. I am thrilled that we will be featuring an interactive incident response planning session at our upcoming national compliance conference in San Diego, California in September 2016.  Even firms who have adopted a solid incident response plan can benefit from incident response planning exercises – because the change in a single fact may alter the course of action you should take. But don’t take my word for it. As Verizon’s annual data breach report states, you have time. Three minutes and 45 seconds, to be exact.*

(*Median time from when a social engineering test is conducted to when the first recipient clicks to open the would-be malicious attachment).


Subscribe to CSS Blog

CSS frequently publishes blog posts which are written by our team from their observations in the field, at conferences and through experiences with compliance professionals. These posts are designed to further knowledge and share industry best practices. Topics run the gamut, including Form ADV, cybersecurity, MiFID II, position limit monitoring, technology challenges and more. Complete and submit the brief form below to receive notifications when we publish new content.

Loading form...

Latest Content

Tips to Prevent an SEC OCIE Investment Adviser Exam from Going Bad

Strategies to employ when an SEC OCIE adviser exam goes bad drew a great crowd at the recent CSS Ascendant Fall Compliance Conference. Proactively pointing an exam in the right direction was a consistent theme, summarized by the familiar refrain: “There is no substitute for preparation.” A few keys to note if you find your … Continued

Giving Voice to Values: A New Approach to Ethics

The “Giving Voice to Values” program grew out of Professor Mary Gentile’s frustration of what was going on in both the financial industry and in higher education. She was frustrated and angry about the poor way that ethics was being taught in universities and applied in real-world scenarios. What developed out of her frustration is … Continued

Tips for Developing a Tailored Private Fund Compliance Calendar

As regulatory concerns proliferate and become more complex, developing and monitoring your “to-do” list becomes of paramount importance.  John Gentile, the Director of Private Fund Manager Services for Compliance Solutions Strategies and Michael Emanuel, a Partner at Stroock & Stroock & Lavan LLP provided attendees of the recent CSS 2019 Fall Conference some insight into … Continued