Showing posts with label cyber strategy. Show all posts
Showing posts with label cyber strategy. Show all posts

Wednesday, November 23, 2016

Steps BDs and RIAs can take to make their cyber threat response plan more effective.


Its year-end and time once again to review the Cyber-security plan and Incident Response strategy. Certain steps will help make the cyber threat response plan more effective whether you’re drafting the plan for the first time or conducting a review to improve it. 

Importance of an effective incident response strategy


The Cybersecurity Incident Response Plan becomes part of the Cybersecurity policy and outlines steps the firm will take when a risk or threat is discovered. All fund managers, investment firms, and securities brokerages are expected to have this policy in place, as it outlines what the firm is doing to minimize the risk of threats, and how it intends to administer response in the event of a breach. Firms are also expected to fully track and document their response steps, and fully disclose damage done, costs, and recovery procedures.

In order to develop a strong Cybersecurity IRP, an assessment of existing capabilities and threats is needed. SEC’s Office of Compliance Inspections and Examinations (OCIE) tells us what they expect in a sound plan.

OCIE Examiners will focus on and scrutinize areas of; governance and risk assessment, access rights and controls, data loss prevention, vendor and third party management, and incident response. Specifically, examiners will review whether established policies, assigned roles, system assessments, and plans to address events are sound. Examiners are keenly concerned about risk and handling of Personally Identifiable Information (PII).

Develop an Incident Response Team (IRT)

For most firms, containment and investigation of an incident requires a team effort with multiple departments involved. Depending on the size and structure of the firm; employees and service providers are assigned specific tasks to address various types of foreseeable incidents. The IRT leaders take responsibility as first responders and ensure initial tests outlined in the Response Plan are conducted. Therefore, it’s important that team members meet regularly to evaluate testing procedures and threats.

The Plan

Elements of the plan should include a list of critical contacts and resources. Essential contact information and resources should be readily accessible to persons responsible for activating critical resources in response to an incident. Contacts and information included may encompass forensic experts, legal counsel, insurance policy, data breach experts, notification services, press and media contacts.

Data breach experts recommend using an incident risk matrix to categorize risk levels between low, medium, and high. It’s a good policy to define “triggers” in the plan to help determine if an incident should be escalated to the next level. Escalation tends to be a key area where managers and first responders carry a level of uncertainty. For instance, a lost file with a single client or employee record may be medium to low risk. However, such an event could be classified as high risk requiring immediate action if it is a starting point for a greater threat. Triggers and matrices help IRP responders determine whether a threat should be escalated. 

Upon discovery or notification of a threat or attack, log the following information:

  •          Name and Contact of person making the notification
  •          Date and Time of notification
  •          Date and Time Incident occurred (if known)

When investigating the incident, key elements to log include:
  •          Source of the attack
  •          Systems accessed
  •          Information extracted or compromised
  •          Security of sensitive client or firm information
  •      Notification to Impacted Parties

The standards for notifying victims in the event of a breach can vary. State and federal laws differ, as do regulation governing financial industry sectors. When developing the IRP consider the regulatory standards and add additional layers of notification as deemed necessary. Firms should be aware the window for notification generally starts at the time an incident is first discovered.

Ease workload. Create notification templates covering various situations and make them readily available as part of the IRP. In event of an incident, the templates are used to communicate with clients, employees, service providers, and media relations. Take precaution when considering data security upon sending out communication; ensure the delivery method doesn’t further compromise PII (personally identifiable Information). Also, determine if clients and employees may need additional resources to mend damage.

Documentation and Regulation

The SEC will ask for documentation about incidents including losses incurred, cost of mitigation, along with circumstances and facts. The effectiveness of the IRP includes how well the documentation stands up under examination. 
Investigators often request various computer data logs and files pertaining to devices impacted and servers compromised. They may also look at employee communication, corrective actions taken, notifications, and the overall response of the IRT (Incident Response Team).

Include in the response; details about containment such as a factual description of the incident, preliminary risk assessment, and monitoring conducted after the incident was contained. 

Cybersecurity incidents are an ever evolving threat where attackers continually find inventive ways to do harm. Prevention is a strong form of protection, but not likely to be a solution in every situation. Preparation in advance gives firms the support plan they need to minimize risk and react swiftly.


To learn more about #cybersecurity #governance, Register for our free webinar December 6, 2016.
RND Resources assists Broker-dealer firms, Fund Managers, and RIAs with cybersecurity #assessment and planning solutions. 

Visit our website for more information, upcoming training events, gap analysis worksheets, and emerging trends in cybersecurity as it pertains to Financial Service firms.  www.finracompliance.com

Monday, May 9, 2016

CyberSecurity Checklist and Gap Analysis Worksheet

Download Cybersecurity Checklist
Financial Industry Firms have specialized needs when it comes to developing cyber-security procedures and policies  

Brokerage and Investment Advisor firms hopefully recognize a one-size-fits-all approach to CyberSecurity does not work. Today's firms will need to look beyond their Information Technology personnel and consider their operations in order to establish a comprehensive Cybersecurity procedures and policies manual. Adopting an “ISSP” Information Systems Security Program appropriate to your circumstances and “IRP” Incident Response Plan that your personnel can successfully implement is key to prevention, detection, and recovery.

National Futures Association | CyberSecurity - Interpretive Notice  ¶9070

The firm must develop and maintain a written ISSP for securing customer data and access to their electronic systems, which should be maintained with the rest of the firm’s written procedures. Although the firm is not required to have a separate single document describing every aspect of its ISSP, a comprehensive written policy may be the best way to ensure that firm personnel know what the firm’s policy is, depending upon the firm's size and complexity of business and technological operations.

RND Resources recognizes the significant challenges and risks that investment securities dealers and advisors face in protecting sensitive client and company data as well as proprietary trade system information. Developing a plan consistent with your own firms operations is an important first step. The checklist we created will help you get started on the comprehensive ISSP and IRP. If you have any questions or prefer to have one of our professionals help get you started on a cyber-security program, please feel free to reach out to us at (818) 657-0288.

CYBER-SECURITY CHECKLIST WITH GAP ANALYSIS AND CYBER INSURANCE COMPARISON WORKSHEET


Click the link here to download RND Resources Inc Cybersecurity Checklist. The checklist will help you evaluate what your firm needs to conduct a thorough cybersecurity evaluation and develop the regulatory required “ISSP” Information Systems Security Program and “IRP” Incident Response Plan. Our checklist enables you to;

  • Identify potential threats and risk gaps
  • Rank the threat value of risk gaps
  • Match gaps to sections of the CyberSecurity Compliance Procedure manual
  • Assign tasks to team members
  • Record completion estimates and due dates
  • Maintain notes all throughout the process


BONUS: Cyber Insurance Comparison Worksheet

We’ve also included our Cyber Insurance comparison worksheet that will help you compare policy coverage limits and policy riders across carriers, as well as rank premium prices; all to help determine which policy best fits your firms level of risk and risk tolerance


Need Assistance?


Need help with Technical changes to your system or Penetration testing? We have the tools and expertise to; Conduct a quick-hit assessment of your Information System; Provide a high-level assessment report and; Develop the ISSP and IRP for regulatory compliance.  Call us for more information (818) 657-0288, or Complete the form on our website 


Thursday, January 14, 2016

Taking #CyberSecurity to the Executive Level

CyberSecurity plan action steps

Financial industry executives have a unique responsibility to protect investors and proprietary firm information from compromise. 

For FINRA (Financial Industry Regulatory Authority), cybersecurity protection measures include a broad swipe approach that covers compromise through use of any electronic digital media (e.g. computers, mobile devices, Internet based systems, ipads, software solution providers). And, no matter how much of the cyber security task is outsourced to IT professionals, the ultimate responsibility lands on the shoulders of each firms executive leadership.  For this reason cyber-security practices have taken a front and center seat in board room discussions that reach past IT to operations, sales, vendors, and anyone else with access to electronic company data.

RND Resources has created an action plan for compliance officers and executives leading  #cybersecurity initiatives for their firm. A comprehensive plan includes components such as; Cybersecurity Governance and #RiskManagement, Cybersecurity #RiskAssessment, Technical Controls, Incident Response Planning, Vendor Management, Staff Training, Cyber Intelligence &  Information Sharing, Cyber Insurance.  These topics are discussed more completely on our website at www.finracompliance.com . 

Tips for taking action:  Guideline for Cyber-Security Board Room Meeting

  • Form a cyber-security committee to design, implement, and oversee day-to-day cybersecurity compliance efforts. Calendar regular reports and reviews to assess the activities and effectiveness of the team.
  • Educate yourself on Information Security: Research and understand various types of cyber-security threats. Speak with industry colleagues about what firms are doing to protect themselves. Make assessing cyber threats and solutions a regular part of the business cycle.
  • Know the plan. Read and keep a copy of information security policies handy. Make sure you thoroughly understand what to do in the event of an attack. Prepare as if an attack will happen one day, because chances are it will.
  • Review the plan regularly to make sure it remains relevant and up to date with current threats and trends.
  • Test the plan. Ask IT and other professionals or staff to try and break through the systems to see where the weaknesses are.  Run surprise or mock tests on your staff to see how they measure up on policy and procedures.
  • Work with professionals to identify security issues and industry trends. Audit procedures and conduct forensic investigations following a breach or at regular intervals.
  • Supplier Due Diligence. Vendors and suppliers have their own management weaknesses that present a threat. A motivated hacker may find their way in to your company records through an unsecure supplier system or other means. Test supplier and vendor portals for weaknesses and make sure the staff alerts appropriate parties of anything unusual.
  • Prioritize the security to do list  Some risks are naturally greater than others.  Get an understanding of which efforts require the most resources and match them up with level of threat. Handle items that pose the greatest risks first. Set aside some time for simple fixes and plan for long term solutions.
  • Create a cyber-secure culture   Make certain all staff has a clear understanding that cyber-security is needs are taken seriously. Ask them to consider cyber risks when hiring staff, adding new customer accounts, and establishing business partnerships.
RND Resources provides regulatory compliance services and consulting for broker-dealers, investment advisory firms, and fund managers. For assistance developing a cyber-security plan tuned to regulatory requirements, feel free to call us at 818.657.0288