Showing posts with label wsp. Show all posts
Showing posts with label wsp. Show all posts

Wednesday, November 23, 2016

Steps BDs and RIAs can take to make their cyber threat response plan more effective.


Its year-end and time once again to review the Cyber-security plan and Incident Response strategy. Certain steps will help make the cyber threat response plan more effective whether you’re drafting the plan for the first time or conducting a review to improve it. 

Importance of an effective incident response strategy


The Cybersecurity Incident Response Plan becomes part of the Cybersecurity policy and outlines steps the firm will take when a risk or threat is discovered. All fund managers, investment firms, and securities brokerages are expected to have this policy in place, as it outlines what the firm is doing to minimize the risk of threats, and how it intends to administer response in the event of a breach. Firms are also expected to fully track and document their response steps, and fully disclose damage done, costs, and recovery procedures.

In order to develop a strong Cybersecurity IRP, an assessment of existing capabilities and threats is needed. SEC’s Office of Compliance Inspections and Examinations (OCIE) tells us what they expect in a sound plan.

OCIE Examiners will focus on and scrutinize areas of; governance and risk assessment, access rights and controls, data loss prevention, vendor and third party management, and incident response. Specifically, examiners will review whether established policies, assigned roles, system assessments, and plans to address events are sound. Examiners are keenly concerned about risk and handling of Personally Identifiable Information (PII).

Develop an Incident Response Team (IRT)

For most firms, containment and investigation of an incident requires a team effort with multiple departments involved. Depending on the size and structure of the firm; employees and service providers are assigned specific tasks to address various types of foreseeable incidents. The IRT leaders take responsibility as first responders and ensure initial tests outlined in the Response Plan are conducted. Therefore, it’s important that team members meet regularly to evaluate testing procedures and threats.

The Plan

Elements of the plan should include a list of critical contacts and resources. Essential contact information and resources should be readily accessible to persons responsible for activating critical resources in response to an incident. Contacts and information included may encompass forensic experts, legal counsel, insurance policy, data breach experts, notification services, press and media contacts.

Data breach experts recommend using an incident risk matrix to categorize risk levels between low, medium, and high. It’s a good policy to define “triggers” in the plan to help determine if an incident should be escalated to the next level. Escalation tends to be a key area where managers and first responders carry a level of uncertainty. For instance, a lost file with a single client or employee record may be medium to low risk. However, such an event could be classified as high risk requiring immediate action if it is a starting point for a greater threat. Triggers and matrices help IRP responders determine whether a threat should be escalated. 

Upon discovery or notification of a threat or attack, log the following information:

  •          Name and Contact of person making the notification
  •          Date and Time of notification
  •          Date and Time Incident occurred (if known)

When investigating the incident, key elements to log include:
  •          Source of the attack
  •          Systems accessed
  •          Information extracted or compromised
  •          Security of sensitive client or firm information
  •      Notification to Impacted Parties

The standards for notifying victims in the event of a breach can vary. State and federal laws differ, as do regulation governing financial industry sectors. When developing the IRP consider the regulatory standards and add additional layers of notification as deemed necessary. Firms should be aware the window for notification generally starts at the time an incident is first discovered.

Ease workload. Create notification templates covering various situations and make them readily available as part of the IRP. In event of an incident, the templates are used to communicate with clients, employees, service providers, and media relations. Take precaution when considering data security upon sending out communication; ensure the delivery method doesn’t further compromise PII (personally identifiable Information). Also, determine if clients and employees may need additional resources to mend damage.

Documentation and Regulation

The SEC will ask for documentation about incidents including losses incurred, cost of mitigation, along with circumstances and facts. The effectiveness of the IRP includes how well the documentation stands up under examination. 
Investigators often request various computer data logs and files pertaining to devices impacted and servers compromised. They may also look at employee communication, corrective actions taken, notifications, and the overall response of the IRT (Incident Response Team).

Include in the response; details about containment such as a factual description of the incident, preliminary risk assessment, and monitoring conducted after the incident was contained. 

Cybersecurity incidents are an ever evolving threat where attackers continually find inventive ways to do harm. Prevention is a strong form of protection, but not likely to be a solution in every situation. Preparation in advance gives firms the support plan they need to minimize risk and react swiftly.


To learn more about #cybersecurity #governance, Register for our free webinar December 6, 2016.
RND Resources assists Broker-dealer firms, Fund Managers, and RIAs with cybersecurity #assessment and planning solutions. 

Visit our website for more information, upcoming training events, gap analysis worksheets, and emerging trends in cybersecurity as it pertains to Financial Service firms.  www.finracompliance.com

Thursday, August 18, 2016

Planning for Success: Startup RIA Tips (Part 1)


RND Resources specializes in assisting startup RIA firms complete the process of submitting an application to the SEC or state registry. Over the years we have seen a number of complications due to lack of understanding of the RIA formaiton process and poor planning.  RIA formation is not a one-size-fits-all business venture. There are a number of considerations investment advisors should address as part of the planning process to save time, conflicts, and expense later on.
 
SEC RIA registrations 2014 (588), 2015 (449)


Start with a Plan

An important step in starting a new RIA is to make a solid analysis of goals. When considering goals a thorough research of the business model, tax planning, custodian relationships, state rules, and more will impact the cost to establish the RIA and decisions down the line. For many investment advisors wanting to start their own RIA the effort involved in dissecting various aspects of formation is beyond their expertise.

Start at the beginning

To balance out the complexity in setting up a new firm, some RIA principals will start with a simple low cost template based solution and assume they will modify it later once they build up capacity. From what we’ve seen, this can create a number of even more complex problems that are not easy to upgrade or change once the firm is already doing business. As an experienced consultant to new RIA firms starting out, we caution against making decisions without fully understanding their impact.

Strategy: Business Model, Product Model, Fee Model

One important aspect of establishing a new RIA firm is complexity of the business model, both now and in the future. There are a number of products and client preferences to work with. Over years demographics change and consumer preferences evolve. For instance, if the plan is to serve younger generations, a Fintech strategy will need to be adopted as part of the business model. However, Fintech firms are in an evolving state where compliance regulation and product offering are constantly being developed. For a new RIA, researching a well thought out Fintech solution now can make the difference later when some Fintech providers will likely fail, or get tangled up in regulatory actions, bad press, or worse.

As another example, many firms want to start with a niche they’re comfortable serving. Matching the value proposition to long term goals is helpful. If a firm is adopting a competitive price strategy, they may decide to partner with a third party money manager rather than hire analysts. This decision is followed with the question of available resources through the partner, technology concerns, and restrictive agreements. There’s many other market segmenting factors as well that have restrictive consequences which are not easily changed.

The best consulting advice helps a newly forming firm winnow down the possibilities with stakeholders while discussing pros and cons of various options. Starting from a foundation that considers future strategy, a new firm can apply resources toward meeting goals now and later.
RND Resources Inc assists new RIA firms with start up and formation strategy


Make decisions with confidence

Investment advisors that take the plunge should do everything possible to ensure that their new business is set up to maximize resources. “We’ve worked with a lot of RIA structures after they were set up and it’s clear that many don’t consider advanced planning strategies”. Some mistakes are costly to fix in terms of adopting changes to procedures and policies, negative exams, and staff training.  Reaching out to an experienced consultant allows new business stakeholders make important decisions with confidence.

For more information check out our Resource Guides 

RND Resources Inc | Compliance  * Consulting * Audit * Startup & Formation 
Broker-Dealers, RIAs, Private Equity, Family Offices

Monday, May 9, 2016

CyberSecurity Checklist and Gap Analysis Worksheet

Download Cybersecurity Checklist
Financial Industry Firms have specialized needs when it comes to developing cyber-security procedures and policies  

Brokerage and Investment Advisor firms hopefully recognize a one-size-fits-all approach to CyberSecurity does not work. Today's firms will need to look beyond their Information Technology personnel and consider their operations in order to establish a comprehensive Cybersecurity procedures and policies manual. Adopting an “ISSP” Information Systems Security Program appropriate to your circumstances and “IRP” Incident Response Plan that your personnel can successfully implement is key to prevention, detection, and recovery.

National Futures Association | CyberSecurity - Interpretive Notice  ¶9070

The firm must develop and maintain a written ISSP for securing customer data and access to their electronic systems, which should be maintained with the rest of the firm’s written procedures. Although the firm is not required to have a separate single document describing every aspect of its ISSP, a comprehensive written policy may be the best way to ensure that firm personnel know what the firm’s policy is, depending upon the firm's size and complexity of business and technological operations.

RND Resources recognizes the significant challenges and risks that investment securities dealers and advisors face in protecting sensitive client and company data as well as proprietary trade system information. Developing a plan consistent with your own firms operations is an important first step. The checklist we created will help you get started on the comprehensive ISSP and IRP. If you have any questions or prefer to have one of our professionals help get you started on a cyber-security program, please feel free to reach out to us at (818) 657-0288.

CYBER-SECURITY CHECKLIST WITH GAP ANALYSIS AND CYBER INSURANCE COMPARISON WORKSHEET


Click the link here to download RND Resources Inc Cybersecurity Checklist. The checklist will help you evaluate what your firm needs to conduct a thorough cybersecurity evaluation and develop the regulatory required “ISSP” Information Systems Security Program and “IRP” Incident Response Plan. Our checklist enables you to;

  • Identify potential threats and risk gaps
  • Rank the threat value of risk gaps
  • Match gaps to sections of the CyberSecurity Compliance Procedure manual
  • Assign tasks to team members
  • Record completion estimates and due dates
  • Maintain notes all throughout the process


BONUS: Cyber Insurance Comparison Worksheet

We’ve also included our Cyber Insurance comparison worksheet that will help you compare policy coverage limits and policy riders across carriers, as well as rank premium prices; all to help determine which policy best fits your firms level of risk and risk tolerance


Need Assistance?


Need help with Technical changes to your system or Penetration testing? We have the tools and expertise to; Conduct a quick-hit assessment of your Information System; Provide a high-level assessment report and; Develop the ISSP and IRP for regulatory compliance.  Call us for more information (818) 657-0288, or Complete the form on our website