What Happens When Your CRM is Breached?

Even your client relationship management (CRM) software may not be safe from hackers. That’s the lesson some advisers are learning after an announcement by CRM vendor Redtail that it discovered in March 2019 that its cloud-based software had left some sensitive client data publicly accessible. The data left vulnerable included first names, last names, addresses, dates of birth, and Social Security numbers. Although Redtail has stated that it has subsequently removed such access, it remains to be seen whether any unauthorized access occurred during the time the data was left open to the public.

The SEC’s recent Risk Alert on Regulation S-P, issued in April 2019, highlighted that some advisers’ policies and procedures fail to address storage of personally identifiable information (PII) in a secure manner by third-party vendors and fail to identify all systems where the adviser is maintaining such PII.

If ever there was a crown jewel of investor data, an adviser’s CRM is a likely target – a treasure trove of the exact kind of information hackers find most valuable, all in a single location.

Redtail is allegedly still investigating, which reflects the inherent difficulty and the challenges vendors can face when attempting to discern the potential scope and impact of an incident. Logs become very critical to the investigation of what may or may not have been accessed and when. Conversely, the failure to maintain adequate logs can severely hamper efforts to piece together any indicators of compromise (IOC) surrounding a potential data incident.

Whether you use Redtail or another CRM, the chances are high that at least some of your client data is being stored in the cloud. Even Salesforce, a powerhouse in the CRM space, experienced an issue during a software update in June 2018 that temporarily made it possible for a programming API to allow one client to access another client’s data. It’s important to regularly review the information security safeguards your third-party vendors have in place as part of your ongoing vendor due diligence.  And, recognizing that most vendors will likely experience a security issue at some point given that there is no such thing as 100% security, use those due diligence reviews as an opportunity to inquire whether the issues have been remediated and whether there is any evidence that your firm’s data specifically was part of any detected unauthorized access.


For more information about how CSS cybersecurity services can help you evaluate your risk, please visit our Shield page or contact us. 


Subscribe to CSS Blog

CSS frequently publishes blog posts which are written by our team from their observations in the field, at conferences and through experiences with compliance professionals. These posts are designed to further knowledge and share industry best practices. Topics run the gamut, including Form ADV, cybersecurity, MiFID II, position limit monitoring, technology challenges and more. Complete and submit the brief form below to receive notifications when we publish new content.

Loading form...

Latest Content

Form CRS and Its Impact on State-Registered Advisers

While many investment advisers are starting to plan for Form CRS/Form ADV Part 3, one group of investment advisers can breathe a sigh of relief that this is a project that does not need to be on their ‘To Do’ list. As of now, no state regulator has adopted this disclosure document for state-registered advisers. … Continued

Effective Compliance Policies & Procedures and Annual Reviews: Meeting the Reasonably Designed Standards

Investment Advisers must perform an annual evaluation of the effectiveness of their compliance program. This starts with ensuring, maintaining and implementing reasonably designed policies and procedures. This ComplianceCast webinar covers the recent regulatory changes that may trigger a need to reevaluate your present policies. Who Conducts and How to Conduct the Annual Review Planning and … Continued

7 Reasons to Attend Our Scottsdale Fall 2019 Compliance Conference

If you’ve been considering joining us in Scottsdale for our Sept. 23-25 compliance event, here are seven reasons you should take the plunge now! The Best Mix of Informational & Educational Speakers – We just added OCIE’s Co-National Associate Director of Investment Adviser/Investment Company Examination Program Marshall Gandy to our stellar list of presenters. He joins ex-NFL star Merril … Continued