It reads like a movie script: First, the financial services industry experiences a bout of firm-specific attacks in the form of distributed denial of service (DDoS), domain name system (DNS) poisoning, or breach of personally identifiable information (PII).   One day later, trade order processing at major exchanges and alternative trading systems (ATS) is disrupted.  On

On October 23, 2015, the National Futures Association (NFA) adopted its Interpretive Notice Regarding Information Systems Security Programs (the Notice).  As noted in our prior Password Protected update, the Notice requires NFA member firms − including swap dealers, major swap participants, futures commission merchants, commodity trading advisors, commodity pool operators and introducing brokers (collectively

On October 20, 2015, the IRS, state taxing authorities, and leaders of the tax industry announced continued progress to expand and strengthen protection against identity theft in refund fraud for the 2016 tax season. “We are taking new steps upfront to protect taxpayers at the time they file and beyond,” said IRS Commissioner John Koskinen in announcing this development. “Thanks to the cooperative efforts taking place between the industry, the states and the IRS, we will have new tools in place this January to protect taxpayers during the 2016 filing season.”

(Tax-related identity theft occurs when someone uses a taxpayer’s stolen Social Security number to file a tax return claiming a fraudulent refund. Generally, an identity thief will use a taxpayer’s SSN to file a false return early in the year. The taxpayer may be unaware he or she is a victim until the taxpayer tries to file a tax return and learns one already has been filed using his or her SSN.)

The strengthened and expanded protections include the following:
Continue Reading IRS, States, Industry Continue Progress to Protect Taxpayers from Identity Theft

Syrian_hackerThere once existed a time when a crew of skydiving surfers could throw on surprisingly well crafted ex-president masks, stroll into a cash-heavy bank and rob the institution blind. There was a time when the weapon of choice for a bank robbery was a sawn off shotgun and an ingenious disguise. There was a time when a handwritten note riddled with grammatical errors was handed over to a shaking bank teller or power tools and explosives were used to bust open vault doors as a get-away driver idled at the curb waiting for the right moment to disappear in a fog of tire smoke. But that time has faded. That time is over. The ex-presidents are finished, and new, invisible and far more effective crews are moving in and taking over the very old and familiar business model of robbery.

Organized gangs of international hackers have replaced the old tools and techniques of the trade with skills and technology that yield results and efficiencies unimaginable to even the most prolific robbers and thieves of the past era.  And by some experts’ accounts, these organizations are just getting started.  This is not news though.  It is well-known that hackers are so adept at navigating code and circumventing security systems that, with the assistance of only a laptop, an internet connection and likely some Red Bull, Adderall and a few late nights, they are able to access the most sensitive data on the most sensitive servers. Amongst many other companies, Adobe, Zappos and AshleyMadison.com have all been hacked. Even the United States Office of Personnel Management suffered the largest breach of government data in history this year. And now, increasingly, the financial securities industry needs to be worried.

This week, the Securities and Exchange Commission (SEC) announced in a press release that Ukrainian-based Jaspen Capital Partners Limited and CEO Andriy Supranonok have agreed to pay $30 million to settle allegations that they made massive financial gains from trading on non-public corporate news releases that were hacked and stolen from newswire services. It appears now that the glory days of receiving stock tips while enjoying a 25-year-old scotch at a roof-top party in Manhattan have diminished in favor of those traders obtaining their tips from the murky labyrinth of the hacking world.
Continue Reading Through the Wire: SEC Turns its Sights on Insider Trading, Hacking and Data Thievery

On Sept. 15, 2015, the Securities Exchange Commission (SEC) Office of Compliance Inspections and Examinations (OCIE) published its second cybersecurity risk alert (the “2015 Risk Alert”). The 2015 Risk Alert is a follow up to the OCIE’s April 2014 cybersecurity initiative risk alert (the “2014 Risk Alert”) announcing a series of examinations to identify cybersecurity risks and assess cybersecurity preparedness in the securities industry. The 2015 Risk Alert puts broker-dealers (BDs) and investment advisors (IAs) on notice that OCIE will seek additional information and expand its area of focus in this second round of cybersecurity examinations.
Continue Reading SEC’s OCIE Issues a Second Cybersecurity Risk Alert

On August 28, 2015, the National Futures Association (NFA) submitted a proposed interpretative notice (Notice) to the Commodity Futures Trading Commission (CFTC) to require information systems security programs (ISSPs). If the CFTC adopts the NFA’s proposals, NFA member firms − including swap dealers, major swap participants, futures commission merchants, commodity trading advisors, commodity pool operators and introducing brokers (collectively, Members) − would have to establish, maintain and follow written ISSPs.
Continue Reading NFA Proposes Cybersecurity Guidance for Derivatives Traders

The U.S. Securities and Exchange Commission’s (“SEC”) Division of Investment Management (“Division”) recently released a Guidance Update (“Guidance”) highlighting the importance of cybersecurity for registered investment companies (“funds”) and registered investment advisers (“advisers”).  This Guidance is similar to the Department of Justice’s recently issued Best Practices regarding preparation for and response to cybersecurity breaches.  (See our post on the DOJ’s Best Practices here).  In the Guidance, the Division identified a number of measures for funds and advisers to consider in addressing cybersecurity risk and rapid response capability.
Continue Reading SEC Division of Investment Management Issues Cybersecurity Guidance for Investment Funds and Advisers

The Federal Trade Commission (FTC) recently announced formation of its Office of Technology Research and Investigation (OTRI), an office meant to “ensure that consumers enjoy the benefits of technological progress without being placed at risk of deceptive and unfair practices.” The office is meant to expand the scope of work previously conducted by the FTC’S