Ropes & Gray is all over CyberSecurity! Note the last

New Post Public Reply Private Reply Replies (0) Message Board
Hate Liars
474
Ropes & Gray is all over CyberSecurity! Note the last paragraph.

March 23, 2018
Cybersecurity Oversight
by Ropes & Gray LLP

THIS IS THE FIRST UPDATE from a working group of
investment management and cybersecurity attorneys.
We look forward to sharing more insights on cybersecurity
trends and developments of concern to the
investment management industry.

CYBERSECURITY OVERSIGHT

FINANCIAL REGULATORS continue to expand their reach in the cybersecurity
space, and funds, fund sponsors, and advisers should
take note. Most recently, on February 12, the CFTC fi led a simultaneous
Order and Settlement against AMP Global Clearing
LLC (AMP), a registered futures commission merchant, related
to a breach of its networks in April 2017 by a third party who
obtained approximately 97,000 AMP fi les, including customers’
personal information. Notably, the CFTC did not charge AMP
under its regulation requiring that registrants have in place policies
and procedures to safeguard customer records and information;
rather, the CFTC proceeded under a separate regulation
requiring that registrants diligently supervise any delegated entity
tasked with performing any aspect of the registrant’s business
activities. The Order and Settlement highlight the importance
for funds, fund sponsors, and advisers of adequately supervising
their service providers’ cybersecurity measures.

BACKGROUND ON THE AMP ORDER AND SETTLEMENT

AMP had adopted a written information systems security
program (ISSP) that delegated to an IT provider the implementation
of certain provisions, including (1) identifying and
performing risk assessments of network access routes, and (2)
performing quarterly network risk assessments to identify and
report vulnerabilities to AMP. In June 2016, the IT provider
installed a back-up data storage device, but failed to identify a
default feature that allowed third parties to access AMP’s backup
fi les from the Internet without permissions. In April 2017,
a third party detected this vulnerability on AMP’s network
and successfully copied approximately 97,000 fi les from the
installed back-up data storage device, unbeknownst to AMP.
The CFTC therefore concluded that the IT provider violated
the ISSP, fi rst by failing to identify or run a risk assessment of
the problematic feature in its initial installation, and second
by failing to report any network abnormalities or concerns
in each of three quarterly network risk assessments between
the time of installation and when the third party accessed the
AMP network.
The CFTC proceeded, however, not against the service provider
(which was outside of its jurisdiction, in any event), but against
AMP for failure to supervise the vendor. As evidence of its failure
to diligently supervise its IT provider, the CFTC pointed
to the 10-month period during which AMP was unaware that
thousands of customer records were unprotected, and the fact
that AMP only learned of the subsequent breach when notifi ed
by the third party. Notably, the CFTC did not identify any specifi
c action (or lack thereof) by AMP in determining that AMP
had failed to adequately supervise its service provider, instead
pointing to circumstantial factors such as the length of time the
vulnerability remained unremediated as the bases for its charge.

CFTC AND SEC CYBERSECURITY REGULATIONS

Regulations and interpretive notices published by the CFTC and
the National Futures Association (NFA), the self-regulatory
organization for the U.S. derivatives industry, put in place a
framework for registrants’ obligations for cybersecurity. CFTC
registered entities are required, for example, to “adopt policies
and procedures that address administrative, technical and physical
safeguards for the protection of customer records and information”
under Regulation 160.30. The CFTC has issued a staff
advisory clarifying that the policies and procedures should be in
writing and should identify reasonably foreseeable security risks
and the controls for assessing and mitigating such risks. The
NFA’s Interpretive Notice 9070 similarly requires NFA Members
to “adopt and enforce a written ISSP reasonably designed
to provide safeguards appropriate to the Member’s size, complexity
of operations, type of customers and counterparties, the
sensitivity of the data accessible within its systems, and its electronic
interconnectivity with outer entities, to protect against
security threats or hazards to their technology systems.”
The SEC has issued similar rules, compliance with which will
also satisfy obligations under CFTC Regulation 160.30. Regulation
S-P requires registered broker-dealers, investment companies,
and investment advisers to “adopt written policies and
procedures that address administrative, technical, and physical
safeguards for the protection of customer records and information.”
The regulation goes further to specify that policies and
procedures must be “reasonably designed” to protect customer
information, protect against anticipated threats to the security
of customer information, and prevent any unauthorized “access to or use of” any customer information that could result in
“substantial harm or inconvenience to any customer.”
Interestingly, however, in its recent action against AMP, the
CFTC did not rely on Regulation 160.30 and related notices.
Instead, the CFTC brought charges under Regulation 166.3,
which broadly imposes supervisory obligations on CFTC-registered
fund sponsors and commodity trading advisers. In
doing so, the CFTC expanded its enforcement reach beyond
failures to maintain policies and procedures to the supervisory
obligations of registrants in the cybersecurity space. AMP had
adopted an ISSP pursuant to NFA Interpretive Notice 9070—
but its cybersecurity obligations did not end there.

DUTY TO SUPERVISE

Both the CFTC and SEC have in place regulations imposing
supervisory obligations on registered fund sponsors and commodity
trading advisers, and registered investment companies,
advisers, and broker-dealers, respectively. CFTC registrants,
for example, are required to “diligently supervise the handling
by its partners, officers, employees and agents” of all
of the registrant’s business activities, including the securing of
networks handling such business. Identifying a violation of
the operative regulation, Regulation 166.3, is a fact-intensive
determination that examines whether (1) the registrant’s supervisory
system is generally inadequate, or (2) the registrant
failed to perform is supervisory duties diligently.1
Registrants
have an affirmative duty to actively supervise their delegates
by instituting procedures for both detecting and preventing
wrongdoing by such persons, including appropriate supervisory
structures and compliance programs.2
Evidence of inadequate
supervision can come from the nature of the violations
themselves or from repeated violations.3
Under the fund compliance rule (Rule 38a-1), the SEC similarly
requires every registered investment company and business
development company to “[a]dopt and implement written policies
and procedures reasonably designed to prevent violation
of the Federal Securities Laws by the fund, including policies
and procedures that provide for the oversight of compliance
by each investment adviser, principal underwriter, administrator,
and transfer agent of the fund.” Rule 206(4)-7 likewise requires
advisers to institute policies and procedures to prevent violations, which could include oversight of their vendors’ cybersecurity.
Indeed, oversight of vendors has been cited by the
SEC’s Division of Investment Management as a key measure for
implementing effective compliance programs under Rules 38a1
and 206(4)-7. In guidance published by the SEC’s Office of
Compliance Inspection and Examination (OCIE) on its Cybersecurity
Examination Initiative, which reviewed the cybersecurity
practices of broker-dealers, investment advisers, and investment
companies, OCIE has also stressed the importance of implementing
practices and controls related to vendor management,
including ongoing monitoring and oversight of vendors. OCIE
has gone as far as to indicate that an element of robust policies
and procedures is to require third-party vendors to periodically
provide logs of their activities on a firm’s network.
In the AMP Order, the CFTC connects registrants’ information
security obligations with their diligent supervision obligations—asserting
that it “flow naturally” from a registrant’s
obligation to adopt appropriate policies and procedures to
safeguard customer information under Regulation 160.30 that
the same registrant must, under Regulation 166.3, diligently
supervise how those policies and procedures are implemented
by downstream service providers, including the IT providers
tasked with securing a registrant’s network infrastructure and
customer data. With the AMP Order, the CFTC is sending a
clear signal that registrants cannot “abdicate” their data security
responsibilities under Regulation 166.3 by simply passing
them on to a service provider without further liability.

The AMP action emphasizes the importance of robust cybersecurity
oversight of vendors and the ease with which a regulated
entity can find itself in the crosshairs of an enforcement action.

The broader regulatory landscape and the SEC’s toolbox can
lead to similar results. Comprehensive, documented technical
and physical safeguards for customer records and information
alone are not sufficient. Funds, fund sponsors, and advisers
should also actively oversee the cybersecurity activities of their
vendors and document those efforts. The level of diligence required,
which could include security questionnaires or more detailed
examinations, could depend on the level of access granted
to the vendor as well as an overall assessment of the vendor’s
risk profile. For vendors providing critical IT services, such as
with AMP, a more rigorous level of oversight is likely required
.



Paulita Pike
Partner, Chicago
Investment Management
paulita.pike@ropesgray.com 
+1 312 845 1212
CONTACTS

Elizabeth Reza
Partner, Boston
Investment Management
elizabeth.reza@ropesgray.com 
+1 617 951 7919

Heather Sussman
Partner, Boston
Privacy & Cybersecurity
heather.sussman@ropesgray.com 
+1 617 951 7125

Kevin Angle
Counsel, Boston
Privacy & Cybersecurity
kevin.angle@ropesgray.com 
+1 617 951 7428

Zerify Inc (ZRFY) Stock Research Links

ZRFY Board Company Profile Buy Rating Time & Sales News Filings Financials
Scroll down for more posts ▼

Top 10 Most Recent News Articles

Mitrade EU Enhances Investor Safety with New Insurance

Updated Category News Views 3

Mitrade's New Insurance: A Safety Net? Mitrade EU is amping up its game with some fresh insurance perks that catch the eye. They're slapping on some extra insolvency protection for clients trading under their CySEC license. Now that sounds like a financial shield anyone would want. Basically, they're adding another layer to the basic regulatory protections, and without...

Continue Reading
Lundbeck's Bexicaserin Insights Rock Epilepsy Congress

Updated Category News Views 4

Breaking Down Bexicaserin's Dual Action Seems like Lundbeck's playing the long game with bexicaserin, and boy, are they shaking things up at the European Epilepsy Congress. This isn't your usual sit-back-and-watch situation. They're putting bexicaserin's dual mode of action under a magnifying glass, aiming to hit both sides of the brain's seesaw by increasing inhibitory...

Continue Reading
Telit Cinterion Secures U.S. Manufacturing with PA Facility

Updated Category News Views 1

Telit Cinterion Takes a Bold Step in U.S. Manufacturing Here's a move you don't see every day: Telit Cinterion, one of the leading players in the IoT scene, is planting its flag firmly in the good ol' U.S. of A. They're ramping up to start churning out 4G and 5G IoT modules right on American soil by October 2026. This isn't just a small-scale ambition, folks. We're...

Continue Reading
RealityMine Appoints CPO Amidst Strong Growth Momentum

Updated Category News Views 4

Pushing the Boundaries of Behavioral Data When a company like RealityMine posts a whopping 75% year-over-year revenue bump, you know they're not here to mess around. Enter Soumya Bijjal, a seasoned pro stepping in as their inaugural Chief Product Officer. This isn't just about adding to the C-suite boys' club; it's about locking in on a goldmine of behavioral data that's...

Continue Reading
PMI Foods Fuels Hunger Action Month with New Partnership

Updated Category News Views 3

Helping Families Put Food on the Table Out there in Utah's schoolyards, Parker Migliorini International (PMI Foods) is taking a tangible step against hunger, whipping out a $15,000 check to back the Utah Food Bank’s Mobile School Pantry initiative. This partnership kicks off in September, aligning with Hunger Action Month, a period dedicated to spotlighting food...

Continue Reading
Shell Seals ARC Acquisition, $16.5B Bet on Future

Updated Category News Views 3

Shell’s Strategic Play: Snagging ARC When it comes to Shell, they don't dawdle with peanuts. Snagging ARC Resources Ltd., a Canadian energy firm rooted squarely in British Columbia and Alberta, speaks volumes about their appetite for growth. They’re shelling out approximately US$16.5 billion to pull this deal off the ground. This isn't just some casual sector play; it...

Continue Reading
Balázs Nagy's Bold Move: Transforming AI Workforce

Updated Category News Views 1

New Horizons in AI: Balázs Nagy Leads There's always that one name that shakes things up, and today it's Balázs Nagy. The guy's not just playing in the AI sandbox; he's leveling the whole thing up with Project NoéMI. He's the big cheese at TheNewPush LLC, beyond just a job title. Nagy’s diving headfirst into AI workforce development in a world screaming for change....

Continue Reading
BRP's C-Suite Shakeup: What It Means for Investors

Updated Category News Views 0

Passing the Baton in BRP's Financial Helm Alright, folks, grab your coffee and listen up. There's a shakeup coming from the cold corners of Valcourt, Quebec—BRP Inc., the powersports behemoth on the TSX: DOO, has announced a changing of the guard in their finance department. Come October 1st, there's a planned power shift as Sébastien Martel steps down as CFO, passing...

Continue Reading
Moore and RMI Forge Alliance for Data-Driven Success

Updated Category News Views 1

RMI and Moore Team Up for Strategic Evolution Let me tell ya, RMI Direct Marketing deciding to join forces with Moore’s AudienceFirst Media is a decision that’ll ripple through the data-driven waters for quite some time. They ain’t merging, mind you, but they’re definitely tying their ships together with a shared compass set on list management and brokerage...

Continue Reading
Dr. Anastasatos to Speak on Endoscopic Brow Lift in Crete

Updated Category News Views 3

Conference Spotlight: Endoscopic Brow Lift Plastic surgeons from across the globe are gathering in Crete, Greece, for a conference that promises to shake up the aesthetic world. Among the big names is Dr. John M. Anastasatos, who'll be lifting more than just eyebrows with his presentation on the endoscopic brow lift. This isn't just another facelift spiel—no sir—this...

Continue Reading

Top 5 Most Recently Viewed Articles

Eli Lilly's Weight Loss Drug Set for Launch in Hong Kong Market

Updated Category News Views 191

Eli Lilly's Weight Loss Breakthrough in Hong Kong Eli Lilly (NYSE: LLY) is making significant strides as it gears up to release its innovative weight-loss drug in Hong Kong. This comes on the heels of government approval, paving the way for the availability of its tirzepatide injections, known by the brand name Mounjaro. With reports indicating that the launch could...

Continue Reading
Tradr's Bold Leap: Leveraged ETFs Target Tech Gems

Updated Category News Views 13

Tradr's Big Move in Leveraged ETFs You can't help but notice when someone drops five leveraged ETFs on the market, especially when they're focusing on under-the-radar tech stocks. Tradr ETFs, known for catering to savvy investors who aren't scared of a little risk, made waves by unveiling a suite of 2X long ETFs aimed at delivering double the daily performance of specific...

Continue Reading
Empowering Customer Service with AI Knowledge at eGain Solve 2024

Updated Category News Views 70

AI Knowledge Transforming Customer Experiences at eGain Solve 2024 eGain (NASDAQ: EGAN), a leader in the AI knowledge platform for enhancing customer service, is proud to announce the eGain Solve 2024 conference. This eagerly anticipated event will take place at the Hyatt Regency O'Hare in Chicago, bringing together thought leaders and industry practitioners to explore...

Continue Reading
Global Leaders to Engage in 10th Annual World FZO Congress

Updated Category News Views 74

Global Leaders to Gather at the 10th Annual World FZO Congress The upcoming 10th edition of the World Free Zones Organization (World FZO) Congress promises to be an engaging event, drawing industry leaders and notable speakers from around the world. This year, the congress enjoys the esteemed patronage of His Highness Sheikh Mohammed bin Rashid Al Maktoum and will take...

Continue Reading
Bradley Building Products Revolutionizes Construction in Florida

Updated Category News Views 133

Bradley Building Products Revolutionizes Construction in Florida Bradley Building Products, a premier distributor of building supplies in Florida, is thrilled to unveil its newly optimized website aimed at enhancing the purchasing experience for contractors. This initiative promises to make product navigation easier and more efficient, catering specifically to the needs...

Continue Reading