Here Are Some Cybersecurity Best Practices That Regulators Will Be Looking For
Facing increasing risks across numerous industries, a federal regulator for the first time has issued a list of best practices for cybersecurity as well as for resiliency after a breach.
January 28, 2020 at 04:22 PM
4 minute read
Facing increasing risks across numerous industries, a federal regulator for the first time has issued a list of best practices for cybersecurity as well as for resiliency after a breach.
The 13-page report includes tips aimed at general counsel and chief compliance officers on mobile device security, vendor management and more.
The Office of Compliance Inspections and Examinations, part of the U.S. Securities and Exchange Commission, on Monday issued the list, gleaned from its exams. The office regularly issues such observations, but usually they pertain to securities, investment advisers, money laundering and other financial issues.
"It's the first time these types of important cybersecurity resiliency observations have come from OCIE," said Alexander Southwell, co-chair of the privacy, cybersecurity and consumer protection group in the New York office of Gibson, Dunn & Crutcher.
"They have provided other guidance over the years about social media use, ransomware, privacy notices and more specific issues," Southwell added. "The SEC has recognized that it needs to be much more vigilant about cybersecurity risks and also that its entities could use more guidance, which is what leads to the sharing of observations like these."
The OCIE said, "In an environment in which cyber threat actors are becoming more aggressive and sophisticated—and in some cases are backed by substantial resources including from nation state actors—firms participating in the securities markets, market infrastructure providers and vendors should all appropriately monitor, assess and manage their cybersecurity risk profiles, including their operational resiliency."
OCIE director Peter Driscoll explained in a statement, "Through risk-targeted examinations … OCIE has observed a number of practices used to manage and combat cyber risk and to build operational resiliency. We felt it was critical to share these observations in order to allow organizations the opportunity to reflect on their own cybersecurity practices."
The observations highlight basic approaches taken by organizations in the areas of governance and risk management, access rights and controls for the system, data loss prevention, mobile security, incident response and resiliency, vendor management, and training and awareness.
In the statement, SEC chairman Jay Clayton said, "Data systems are critical to the functioning of our markets, and cybersecurity and resiliency are at the core of OCIE's inspection efforts."
The OCIE report made business continuity and resiliency a key component of any incident response plan, that is, "if an incident were to occur, how quickly can the organization recover and again safely serve clients?"
The report discussed key elements of resiliency, including maintaining inventory of core business operations and systems, assessing risks and prioritizing business operations, and considering other safeguards such as backing up data elsewhere or buying cybersecurity insurance.
Gibson Dunn's Southwell said the report is significant because these are the matters regulators will be watching.
"We will continue to see greater emphasis on cybersecurity issues in SEC exams," he predicted, "and that will likely lead to an increase in enforcement investigations and actions, as well." The OCIE declined comment beyond its press release statement.
Southwell noted that OCIE included cybersecurity in its Jan. 7 list of exam priorities for 2020, along with "the related, quite interesting, area of alternative data." Alternative data includes information collected from various non-traditional sources, such as web scraping, data vendors, news stories and even hacking.
The OCIE statement of priorities said the office "recognizes that advancements in financial technologies, methods of capital formation and market structures, as well as registered firms' use of new sources of data (often referred to as "alternative data"), warrant ongoing attention and review."
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View All'Erroneous Assumption'?: Apple Challenges DOJ Antitrust Remedy in Google Search Monopoly Case
3 minute read'Be Comfortable Being Uncomfortable': Pearls of Wisdom From 2024 GC Q&As
Law Firms Mentioned
Trending Stories
- 1'Pull Back the Curtain': Ex-NFL Players Seek Discovery in Lawsuit Over League's Disability Plan
- 2Tensions Run High at Final Hearing Before Manhattan Congestion Pricing Takes Effect
- 3Improper Removal to Fed. Court Leads to $100K Bill for Blue Cross Blue Shield
- 4Michael Halpern, Beloved Key West Attorney, Dies at 72
- 5Burr & Forman, Smith Gambrell & Russell Promote More to Partner This Year
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250