Showing posts with label cyber-security. Show all posts
Showing posts with label cyber-security. Show all posts

Monday, May 23, 2016

Tips to Reduce Audit and Examination Costs for BD's and RIA's

How Broker-Dealer and RIA firms can reduce the cost of  Audits and Examinations


Mid-sized broker dealers struggle to stay on top of audit preparation work. Even with today’s automated accounting technology and regulatory software; compiling data and records for audits is a time consuming task that large companies assign to a task force who monitor audit capabilities year round.  Some firms try to save costs by preparing audit records themselves, but wind up paying more in the end. They’re charged higher audit fees as a result of poorly organized records, incomplete information, and misunderstanding of the auditors’ role. Once the auditor has received the records, it can be anyone’s guess how they will be interpreted and what additional questions may be required.  Firms can benefit from a significant cost savings by outsourcing the audit preparation work to experienced pro’s.

Minimize Risk of Negative Audit Results and Keep Audit Costs Down


An important component in minimizing the risk of negative audit results is to first understand what the role of the auditor is. The auditor is engaged to “render an opinion on whether a company’s financial statements are presented fairly, in all material respects, in accordance with financial reporting”. Firms that don’t recognize this often make the mistake of providing poorly documented information, assuming the auditor will straighten everything out on the go. This costly assumption leaves firms paying hourly audit rates for the auditors staff to properly organize the records before they start on the audit itself.  Having the auditor spend time organizing your records can add up fast.
To form an audit opinion, the auditor “gathers records, observes, tests, compares, and confirms accuracy of data and processes”. Then “the auditor forms an opinion of whether the financial statements are free of material misstatements and if fraud or error exists”. In analyzing records the auditor does not reconcile the accounts and financial statements, but makes a judgment on how well the company has reconciled its financial statements and accounts.  The auditor does not prepare footnotes or financial statement disclosures, but will assess what the company accountant has included in footnotes. The auditor does not maintain records, establish values, locate records, or prepare the entity for the audit. These responsibilities rest solely on the firm being audited. Further, the auditor does not make a recommendation for corrective action plans, rather they identify if corrective action measures should be taken.

A clear picture of what the auditor does and doesn’t do can be found in the PCAOB.org Ethics and Independence Rules for Auditors. The mainstay of auditor independence is that auditors do not take responsibility for records and financial statements on which they form an audit opinion. Responsibility for the financial statements and records lies squarely on the shoulders of the company being audited.


For more tips register for the June 2016 #LosAngeles #compliance and #riskmanagement roundtable meeting. The roundtable discussion meeting is sponsored by RND Resources Inc, compliance, audit, and regulatory support services firm located in Woodland Hills California. RND Resources has been serving broker-dealers and registered investment advisors for over 30 years with audit preparation services and regulatory support. RND Resources also provides regulatory compliance consulting & support for #fintech firms.  The secondary topic we’ll be discussing at the meeting is best practice for reviewing #cybersecurity along with system testing and penetration testing technology.  Sign up on our website at www.finracompliance.com 

Read more about Audit Preparation Support Services available from RND Resources Inc.

Monday, May 9, 2016

CyberSecurity Checklist and Gap Analysis Worksheet

Download Cybersecurity Checklist
Financial Industry Firms have specialized needs when it comes to developing cyber-security procedures and policies  

Brokerage and Investment Advisor firms hopefully recognize a one-size-fits-all approach to CyberSecurity does not work. Today's firms will need to look beyond their Information Technology personnel and consider their operations in order to establish a comprehensive Cybersecurity procedures and policies manual. Adopting an “ISSP” Information Systems Security Program appropriate to your circumstances and “IRP” Incident Response Plan that your personnel can successfully implement is key to prevention, detection, and recovery.

National Futures Association | CyberSecurity - Interpretive Notice  ¶9070

The firm must develop and maintain a written ISSP for securing customer data and access to their electronic systems, which should be maintained with the rest of the firm’s written procedures. Although the firm is not required to have a separate single document describing every aspect of its ISSP, a comprehensive written policy may be the best way to ensure that firm personnel know what the firm’s policy is, depending upon the firm's size and complexity of business and technological operations.

RND Resources recognizes the significant challenges and risks that investment securities dealers and advisors face in protecting sensitive client and company data as well as proprietary trade system information. Developing a plan consistent with your own firms operations is an important first step. The checklist we created will help you get started on the comprehensive ISSP and IRP. If you have any questions or prefer to have one of our professionals help get you started on a cyber-security program, please feel free to reach out to us at (818) 657-0288.

CYBER-SECURITY CHECKLIST WITH GAP ANALYSIS AND CYBER INSURANCE COMPARISON WORKSHEET


Click the link here to download RND Resources Inc Cybersecurity Checklist. The checklist will help you evaluate what your firm needs to conduct a thorough cybersecurity evaluation and develop the regulatory required “ISSP” Information Systems Security Program and “IRP” Incident Response Plan. Our checklist enables you to;

  • Identify potential threats and risk gaps
  • Rank the threat value of risk gaps
  • Match gaps to sections of the CyberSecurity Compliance Procedure manual
  • Assign tasks to team members
  • Record completion estimates and due dates
  • Maintain notes all throughout the process


BONUS: Cyber Insurance Comparison Worksheet

We’ve also included our Cyber Insurance comparison worksheet that will help you compare policy coverage limits and policy riders across carriers, as well as rank premium prices; all to help determine which policy best fits your firms level of risk and risk tolerance


Need Assistance?


Need help with Technical changes to your system or Penetration testing? We have the tools and expertise to; Conduct a quick-hit assessment of your Information System; Provide a high-level assessment report and; Develop the ISSP and IRP for regulatory compliance.  Call us for more information (818) 657-0288, or Complete the form on our website 


Thursday, January 14, 2016

Taking #CyberSecurity to the Executive Level

CyberSecurity plan action steps

Financial industry executives have a unique responsibility to protect investors and proprietary firm information from compromise. 

For FINRA (Financial Industry Regulatory Authority), cybersecurity protection measures include a broad swipe approach that covers compromise through use of any electronic digital media (e.g. computers, mobile devices, Internet based systems, ipads, software solution providers). And, no matter how much of the cyber security task is outsourced to IT professionals, the ultimate responsibility lands on the shoulders of each firms executive leadership.  For this reason cyber-security practices have taken a front and center seat in board room discussions that reach past IT to operations, sales, vendors, and anyone else with access to electronic company data.

RND Resources has created an action plan for compliance officers and executives leading  #cybersecurity initiatives for their firm. A comprehensive plan includes components such as; Cybersecurity Governance and #RiskManagement, Cybersecurity #RiskAssessment, Technical Controls, Incident Response Planning, Vendor Management, Staff Training, Cyber Intelligence &  Information Sharing, Cyber Insurance.  These topics are discussed more completely on our website at www.finracompliance.com . 

Tips for taking action:  Guideline for Cyber-Security Board Room Meeting

  • Form a cyber-security committee to design, implement, and oversee day-to-day cybersecurity compliance efforts. Calendar regular reports and reviews to assess the activities and effectiveness of the team.
  • Educate yourself on Information Security: Research and understand various types of cyber-security threats. Speak with industry colleagues about what firms are doing to protect themselves. Make assessing cyber threats and solutions a regular part of the business cycle.
  • Know the plan. Read and keep a copy of information security policies handy. Make sure you thoroughly understand what to do in the event of an attack. Prepare as if an attack will happen one day, because chances are it will.
  • Review the plan regularly to make sure it remains relevant and up to date with current threats and trends.
  • Test the plan. Ask IT and other professionals or staff to try and break through the systems to see where the weaknesses are.  Run surprise or mock tests on your staff to see how they measure up on policy and procedures.
  • Work with professionals to identify security issues and industry trends. Audit procedures and conduct forensic investigations following a breach or at regular intervals.
  • Supplier Due Diligence. Vendors and suppliers have their own management weaknesses that present a threat. A motivated hacker may find their way in to your company records through an unsecure supplier system or other means. Test supplier and vendor portals for weaknesses and make sure the staff alerts appropriate parties of anything unusual.
  • Prioritize the security to do list  Some risks are naturally greater than others.  Get an understanding of which efforts require the most resources and match them up with level of threat. Handle items that pose the greatest risks first. Set aside some time for simple fixes and plan for long term solutions.
  • Create a cyber-secure culture   Make certain all staff has a clear understanding that cyber-security is needs are taken seriously. Ask them to consider cyber risks when hiring staff, adding new customer accounts, and establishing business partnerships.
RND Resources provides regulatory compliance services and consulting for broker-dealers, investment advisory firms, and fund managers. For assistance developing a cyber-security plan tuned to regulatory requirements, feel free to call us at 818.657.0288