SEC Issues New Cyber Risk Alert to Financial Firms

Financial firms have a bigger target on their backs at the moment, according to a new risk alert issued July 10, 2020 by the Securities and Exchange Commission’s Office of Compliance Inspections and Examinations (OCIE).  This new risk alert on ransomware cautions investment advisers, broker-dealers, and investment companies that OCIE has recently observed a marked increase in cyberattacks targeting SEC registrants and the service providers to such registrants. The ransomware usually infiltrates firm networks through phishing, and OCIE highlights that through its coordination with federal, state, and local authorities investigating incidents, the level of sophistication of these recent cyberattacks has increased. The current risk alert follows on the heels of another ransomware risk alert issued by OCIE in 2017 when the WannaCry ransomware was causing widespread disruption to financial firms.

In particular, OCIE warns registrants about new variants of the Dridex ransomware currently being used by hackers, which was previously noted by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) at the end of June. This malware is dangerous because it has the ability to detect when users visit financial websites and install keyloggers and capture screenshots (which may include account numbers), in addition to the usual ransomware functionality of locking files to hold for ransom and deleting files.

One large registrant disclosed last week that it suffered a cybersecurity attack, a sign that these attacks aren’t just theoretical.

The good news for financial firms is that OCIE notes several practices to strengthen operational resiliency, including ways to enhance incident response plans and business continuity procedures, security awareness training programs such as conducting phishing testing for staff, and the importance of regular vulnerability scanning and network perimeter testing.

CSS is pleased to be at the forefront of helping clients manage their cybersecurity risks through services including phishing testing, security awareness training, vulnerability scanning, penetration testing, dark web monitoring for compromised credentials and drafting of incident response plans and BCPs. Please contact us at cybersecurity@cssregtech.com to inquire about how we can help make your firm stronger in protecting your data and that of your clients.


Subscribe to CSS Blog

CSS frequently publishes blog posts which are written by our team from their observations in the field, at conferences and through experiences with compliance professionals. These posts are designed to further knowledge and share industry best practices. Topics run the gamut, including Form ADV, cybersecurity, MiFID II, position limit monitoring, technology challenges and more. Complete and submit the brief form below to receive notifications when we publish new content.

Latest Content

From One CCO to Another: Don’t Lie to the SEC

Every once in a while, I think it’s important to get back to the basics. Since the adoption of the compliance rules in 2004, the Securities and Exchange Commission staff has repeatedly stated that the intent of the rules were not to hunt CCOs. Great pains have been made to enlist CCOs support in ensuring … Continued

BME Partners with CSS to Strengthen its Regulatory Service Suite

BME to offer financial services firms in Spain and Portugal a multi-regulation reporting platform Partnership brings a unique combination of local market presence and global coverage BME has partnered with Compliance Solutions Strategies (CSS), a leading RegTech platform provider, to offer a global regulatory reporting solution in Spain and Portugal. The combination of BME’s local … Continued

Compliance Solutions Strategies Acquires AMFINE

Combination Creates First Fully End-To-End Compliance Reporting Platform NEW YORK, September 10, 2020 – Compliance Solutions Strategies (“CSS”), a leading RegTech platform providing technology-driven solutions which enable financial services firms to meet mandatory regulatory compliance requirements, today announced the acquisition of AMFINE (“AMFINE”), a provider of SaaS-based regulatory reporting services to European asset managers, asset … Continued