Cybersecurity and the SEC
“Cybersecurity threats know no boundaries. That's why assessing the readiness of market participants and providing investors with information on how to better protect their online investment accounts from cyber threats has been and will continue to be an important focus of the SEC. Through our engagement with other government agencies as well as with the industry and educating the investing public, we can all work together to reduce the risk of cyber attacks.”
— SEC Chair Mary Jo White
Regulations
- Regulation SCI
- Regulation S-P
- Regulation SDR
- Exchange Act Rule 13n-6
- Adopting release (see pages 232-236 for explanatory text)
- Regulation S-ID
- Market Access Rule
- Compliance Rules
- Investment Company Act Rule 38-1
- Investment Advisers Act Rule 206(4)-7
- Adopting release for ICA Rule 38-1 and IAA Rule 206(4)-7 (see Section II(A)(1) of the Adopting Release, which provides additional information about issues that the policies and procedures of funds or advisers should consider, certain of which are related to cybersecurity)
Providing Investors with Information
Assessing Market Participant Readiness
- OCIE September 2015 Cybersecurity Examination Initiative
- OCIE Summary of 2014 Cybersecurity Examination Sweep
Engaging Government Agencies and Industry
News
- SEC: Morgan Stanley Failed to Safeguard Customer Data
June 8, 2016 - SEC Names Christopher Hetner as Senior Advisor to the Chair for Cybersecurity Policy
June 2, 2016 - SEC Obtains $30 Million From Traders Who Profited on Hacked News Releases
September 24, 2015 - SEC Charges Investment Adviser With Failing to Adopt Proper Cybersecurity Policies and Procedures Prior To Breach
September 22, 2015 - SEC Charges 32 Defendants in Scheme to Trade on Hacked News Releases
February 11, 2015
