The SEC’s Division of Investment Management issued guidance highlighting the importance of cybersecurity and discussing measures that registered investment companies (“funds”) and registered investment advisers (“advisers”) should consider when addressing cybersecurity risk. The latest guidance reflects the Staff’s continued focus on cybersecurity as a key compliance issue (see our report on the SEC’s cybersecurity sweep exam here).
Other regulators, including FINRA and certain state regulators, have also highlighted the importance of this issue for their members and registrants (see our related posts here and here).
Even though the nature of cybersecurity threats is rapidly changing, funds and advisers cannot delay the implementation of effective compliance policies because every day that passes increases the possibility that the firm will be the subject of a regulatory examination into its cybersecurity procedures or, worse, be the subject of a cyber attack.
The guidance highlighted a number of measures that funds and advisers may wish to consider when developing effective cybersecurity and compliance policies. The Staff stressed, however, that its suggestions were not comprehensive and that registrants should consider the nature of their businesses and operations to ensure that policies adequately protect shareholders.
For a more detailed discussion of the guidance, please see our complete client alert.