Mitigating CyberSecurity Risks & Threats
The SEC’s Division of Investment Management released a CyberSecurity Guidance Update for April 2015 for Investment Funds and RIAs to help address and mitigate CyberSecurity risks and threats.
They are clear in stating “…that is it not possible for a fund or adviser to anticipate and prevent every cyber attack. Appropriate planning to address cybersecurity and a rapid response capability may, nevertheless, assist funds and advisers in mitigating the impact of any such attacks and any related effects on fund investors and advisory clients, as well as complying with the federal securities laws.”
An Integral Part of that Planning is to:
- Periodically assess:
- How and where information is stored
- Potential cybersecurity vulnerabilities
- Current security and processes
- Repercussions of a security breach
- Create a strategy to prevent, detect and respond to CyberSecurity threats.
- Train employees and educate clients about reducing exposure to CyberSecurity threats concerning investment accounts.
The CyberSecurity Guidance goes on to say that “An effective assessment would assist in identifying potential cybersecurity threats and vulnerabilities so as to better prioritize and mitigate risk.”
Find out How to Identify Potential CyberSecurity Threats & Vulnerabilities.
Read blog How Can RIA Firms Afford CyberSecurity?
David Gemma is a Managing Director and CMO at UNAPEN, Inc. (What’s a UNAPEN?)
Connect with David on Google+