
Fundamentals for Newer Directors 2014 (pdf)
The latest edition of ICI’s flagship publication shares a wealth of research and data on trends in the investment company industry.
Stay informed of the policy priorities ICI champions on behalf of the asset management industry and individual investors.
Explore research from ICI’s experts on industry-related developments, trends, and policy issues.
Explore expert resources, analysis, and opinions on key topics affecting the asset management industry.
Read ICI’s latest publications, press releases, statements, and blog posts.
See ICI’s upcoming and past events.
The latest edition of ICI’s flagship publication shares a wealth of research and data on trends in the investment company industry.
Explore expert resources, analysis, and opinions on key topics affecting the asset management industry.
Read ICI’s latest publications, press releases, statements, and blog posts.
See ICI’s upcoming and past events.
ICI Innovate brings together multidisciplinary experts to explore how emerging technologies will impact fund operations and their implications for the broader industry.
ICI Innovate is participating in the Emerging Leaders initiative, offering a heavily discounted opportunity for the next generation of asset management professionals to participate in ICI’s programming.
The Emerging.
Stay informed of the policy priorities ICI champions on behalf of the asset management industry and individual investors.
Explore research from ICI’s experts on industry-related developments, trends, and policy issues.
Explore expert resources, analysis, and opinions on key topics affecting the asset management industry.
Read ICI’s latest publications, press releases, statements, and blog posts.
See ICI’s upcoming and past events.
[32598]
July 13, 2020 TO: ICI Members
Last Friday, July 10th, the SEC’s Office of Compliance Inspections and Examinations (OCIE) published its latest Risk Alert, which relates to ransomware.[1] According to this four-page document, “OCIE has observed an apparent increase in sophistication of ransomware attacks on SEC registrants,” including broker-dealers, investment advisers, and investment companies.[2] In such attacks, the perpetrators behind the attacks typically demand a ransom to either “maintain the integrity and/or confidentiality of customer data or for the return of control over registrant systems.” In light of these threats, the Risk Alert both encourages registrants to monitor cybersecurity alerts published by the Department of Homeland Security and Infrastructure Security Agency (CISA) and provides observations of OCIE that may assist registrants “in their consideration of how to enhance cybersecurity preparedness and operational resiliency to address ransomware attacks.”
As noted in the Risk Alert, on June 30, 2020, CISA published an alert on ransomware. This short (1-2 page) Alert updates an Alert that CISA originally released on February 18, 2020.[3] It includes a one-paragraph overview of “threat actor techniques” and corresponding mitigations and, in bullet form, it discusses how an attack occurred and lists actions firms are encouraged to consider as part of their risk-based assessment for mitigating such attacks.
The measures mentioned in the Risk Alert that OCIE has observed that may help a registrant mitigate a ransomware attack include:
The Risk Alert reminds registrants that the SEC has focused on cybersecurity issues for many years and that cybersecurity has been key examination priority for OCIE. As evidence of this, the Risk Alert notes that, in addition to the current Risk Alert, OCIE has published other Risk Alerts on this topic and the SEC maintain a “Cybersecurity Spotlight” webpage that provides cybersecurity-related information and guidance.[4]
Tamara K. Salmon
Associate General Counsel
[1] See Cybersecurity: Ransomware Alert, OCIE Risk Alert (July 10, 2020), which is available at: https://www.sec.gov/files/Risk%20Alert%20-%20Ransomware.pdf.
[2] Though not mentioned in this Risk Alert, while such attacks may be “sophisticated,” such attacks typically occur via a phishing email that an employee opens, which then provides the attacker access to the firm’s systems.
[3] CISA’s Alert AA20-049A is available at: https://us-cert.cisa.gov/ncas/alerts/aa20-049a.
[4] The Cybersecurity Spotlight is available at www.sec.gov/spotlight/cybersecurity. The Risk Alerts OCIE has previously issued related to cybersecurity can be found in the list of all Risk Alerts OCIE has issued. These are available at www.sec.gov/ocie under the “Risk Alert” tab.
Latest Comment Letters:
TEST - ICI Comment Letter Opposing Sales Tax on Additional Services in Maryland
ICI Comment Letter Opposing Sales Tax on Additional Services in Maryland
ICI Response to the European Commission on the Savings and Investments Union