S4:E5 | Cybersecurity Rule Proposal Redux - Lessons From The Front Lines | Compliance In Context

Episode 5 June 20, 2023 01:24:26
S4:E5 | Cybersecurity Rule Proposal Redux - Lessons From The Front Lines | Compliance In Context
The Securities Compliance Podcast: Compliance In Context
S4:E5 | Cybersecurity Rule Proposal Redux - Lessons From The Front Lines | Compliance In Context

Jun 20 2023 | 01:24:26

/

Show Notes

Welcome back to the Compliance in Context Podcast! On today’s show, we do a double-feature Lessons From The Front Lines episode on the SEC Cybersecurity Rule Proposal (Rule 206(4)-9) with an esteemed panel of experts from ACA Aponix and Fairview Cyber, including Carlo di Florio, Christine Tetherly-Lewis, Mike Pappacena, and Amber Allen. Given the increased focus from the SEC and the fact that many elements of the rule proposal represent challenges already facing SEC-registered firms, this is an episode you won’t want to miss!! 

 

Show

Interview with Carlo di Florio (Co-Host), Christine Tetherly-Lewis (ACA Aponix), and Mike Pappacena (ACA Aponix) and Amber Allen (Fairview Cyber)

 

Quotes

10:14 – “You really see the growth and focus by the SEC and FINRA and other regulators starting in 2010 and forward timeframe. You mention a number of risk alerts there and I would observe that the exam division has published more risk alerts, special reports, exam priorities specifically focused on cyber than any other subject. And the same thing at FINRA with some really excellent reports.” – Carlo di Florio

12:20 – “So under the proposed rule 206(4)-9, the SEC has set forth this proposal that would require advisors to adopt specific and fairly prescriptive requirements to address cybersecurity at a firm level. It would require comprehensive programs to address things like cybersecurity risk assessments which would be conducted annually and potentially more frequently depending on changes in firm risks and also even just industry risks.” – Amber Allen

31:44 – “You don’t know what you don’t know is sort of a cliché when it comes to cyber, but making sure that you have appropriate tools in place that can help you detect an incident or a potential incident. I think that what firm’s need to do with respect to understanding if there is a significant incident is really—when they look at their incident response plans and how they receive alerts, notifications, and monitoring—is really set some guidelines and some boundaries around what that all means.” – Mike Pappacena

33:28 – “I think it’s really critical for firms to have thorough monitoring programs in place so they can keep an eye on potential breaches. And under the proposed rule, the SEC did note that firms should be reporting once they have a reasonable basis for concluding that an incident is occurring or has occurred. And it’s interesting that it also noted specifically that, that does not mean that they know that the incident has occurred.” – Amber Allen

35:24 – “Testing of all of these practices is really, really important. The best way to be prepared is to roleplay. Step through some of these scenarios. Make sure you know how you would react, how you’d maneuver, and ultimately, how you’d survive one of these issues if an incident does, kind of, reveal itself.”  – Christine Tetherly-Lewis

Other Episodes

Episode 9

January 05, 2021 00:52:04
Episode Cover

S1:E9 | Cybersecurity and Teleworking | Compliance In Context

Welcome back to the Securities Compliance podcast. In today’s episode, we discuss the recently adopted amendments to the Investment Adviser Marketing Rule and a...

Listen

Episode 4

May 15, 2024 01:03:30
Episode Cover

S5:E4 | Analyzing FINRA Remote Supervision | Compliance in Context

Welcome back to the Compliance In Context podcast! On today’s show, we review one of the most important topics impacting broker-dealers this year, namely...

Listen

Episode 12

February 16, 2021 00:58:03
Episode Cover

S1:E12 | Lessons From The Front Lines - Examinations and Enforcement | Compliance In Context

Welcome back to The Securities Compliance Podcast! On today’s show, we continue our Lessons From the Front Lines series. Much like our regular shows,...

Listen