Cyber Still Atop Exam Priorities

FINRA held its bi-annual Cybersecurity Conference in January and recently published five take-away real-world experiences from the conference:

  • A firm’s social media posts about a charity golf tournament, tipped the scammers when to send an urgent email changing wire instructions, while most of the firm’s management was out on the course;
  • A thumb-drive planted in a parking lot labeled “bonuses,” “payroll,” or “commissions” proved bait too tasty for a firm’s personnel to resist;
  • Even the best vendor-based data systems have hidden vulnerabilities lurking among users, interface and reporting systems on the firm/client side;
  • An hour-long table-top incident-response drill that actually locked the C-suite participants out of their network drove home the point, increased buy-in and led to process improvements far above a merely academic exercise;
  • Multi-factor authentication doesn’t always work, as a firm found when a phishing attack hacked a trusted device to gain access to customer accounts.

The blog post from the conference is here and it provides links to the conference materials and FINRA’s cybersecurity page, too.

Cybersecurity continues as a top priority for both SEC and FINRA exam programs.

SEC OCIE Priorities.

For the SEC, cybersecurity appears twice among the SEC’s priorities for 2020, first as “information security” and again under the FinTech and Digital Assets categories.  OCIE broadly emphasizes culture, tone at the top and empowering compliance across seven broad categories:

  1. Retail investors and seniors, especially regarding disclosures and conflicts of interest, and the implementation Regulation Best Interest (“Reg. BI”).
  2. Information Security.
  3. FinTech, including how registrants deal with digital assets, robo-advice and cyber-security.
  4. Risk-based focus areas:

    (a) For RIAs, New or never-examined RIAs, especially (i) governance / risk management; (ii) access controls; (iii) data loss prevention; (iv) vendor management; (v) training; and (vi) incident response / BCP.

    (b) For BDs, Reg. BI/CRS

    (c) For Municipal Advisors, compliance with the still-relatively-new MA regulatory regime.

  5. Anti-Money-Laundering compliance.
  6. Market infrastructure for clearing agencies, exchanges, and transfer agents, including Reg. Systems Compliance and Integrity (“SCI” - another manifestation of information security).
  7. Regulating the regulators through oversight of FINRA and MSRB.

During FY 2019, of 3,089 exams conducted by OCIE, over 2,000 (65%) yielded deficiency letters and over 150 (5%) caused enforcement referrals.  OCIE’s exam priorities are here.

FINRA’s Exam Priorities.

FINRA’s 2020 Risk Monitoring and Examination Priorities Letter mirrored those same concerns and highlighted four broad categories:

  1. Sales Practice & Supervision
    a. BI and Form CRS (compliance deadline June 30, 2020). See FINRA’s Reg. BI/CRS Checklist, here.
    b. Private Placement Retail Communications … 1st Global, Woodbridge, low-interest-rate environment
    c. Digital Communication Channels
    d. IPOs
    e. Trading Authorizations
  2. Market Integrity
    a. Direct Access
    b. Best Execution, also the subject of FINRA’s recent targeted exam letter, discussed here.
  3. Financial Management
    a. Digital Assets
    b. Liquidity Management
    c. LIBOR to SOFR Transition (with its end-2021 compliance deadline)
  4. Operations
    a. Cybersecurity
    b. Technology Governance

FINRA’s exam priorities letter is here.

Thomas K. Potter, III ( is a partner in the Securities Litigation Practice Group at Burr & Forman, LLP. Tom is licensed in Tennessee, Texas, and Louisiana. He has over 34 years of experience representing financial institutions in litigation, regulatory and compliance matters. See attorney profile.

© 2020 by Thomas K. Potter, III (all rights reserved).

Posted in: Cyber Security, FINRA
Jump to Page
Arrow icon Top

Contact Us

We use cookies to improve your website experience, provide additional security, and remember you when you return to the website. This website does not respond to "Do Not Track" signals. By clicking "Accept," you agree to our use of cookies. To learn more about how we use cookies, please see our Privacy Policy.

Necessary Cookies

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Analytical Cookies

Analytical cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.