Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

North American Securities Administrators Association (NASAA) Releases Model Cybersecurity Rule

By Alexander Madrid, Emily P. Gordy & Cheryl Haas on May 24, 2019
Email this postTweet this postLike this postShare this post on LinkedIn

On May 21, the North American Securities Administrators Association (NASAA)—an organization comprised of 67 securities regulators within the United States (all fifty states as well as districts and territories), Canada, and Mexico—released a model cybersecurity rule package governing state-registered investment advisors’ cybersecurity and privacy practices.  The model rule package, which would need to be adopted by an individual state so as to become law in that jurisdiction, provides a structure for how state-registered investment advisers must design their information security policies and procedures.

The NASAA Model Cybersecurity and Privacy Rule

The heart of the model rule package is the Investment Adviser Information Security and Privacy Rule (Privacy Rule), which requires state-registered investment advisers to adopt, update, and enforce written physical and cybersecurity policies and procedures.  The Privacy Rule provides that these policies and procedures must identify how the firm will “develop the organizational understanding to manage information security risks” and then detail how the firm will develop and implement appropriate safeguards and processes to:

  • protect the delivery of critical infrastructure services;
  • detect information security events;
  • respond to such events; and
  • recover from such events.

Moreover, these policies and procedures must be tailored to the investment adviser’s business model, including the size of the firm, types of services provided, and number of locations.  The Privacy Rule also requires investment advisers to deliver to their clients—upon the initial engagement with the client, and then annually—a privacy policy reasonably designed to convey how the adviser collects and shares non-public personal information.  The model rule package promulgated by the NASAA also provides for an amendment to the existing NASAA model recordkeeping rule to require that investment advisers maintain records of their compliance with the model Privacy Rule, as well as an amendment that would render failing to follow the requirements of the Privacy Rule a violation of the NASAA’s model rule regarding unethical business practices.

The model Privacy Rule bears clear similarities to Regulation S-P, the primary SEC rule governing broker-dealers and federally-registered investment advisers, including its requirement that firms annually send clients their privacy policies.  As previously detailed, the SEC has recently highlighted firms’ deficiencies in complying with Regulation S-P, suggesting that information security remains a key focus for the regulator. The NASAA’s promulgation of the model rule demonstrates that state-level regulators remain similarly focused.  Should the model rule package be adopted across jurisdictions, it would provide uniformity and consistency in state regulation of investment advisers’ practices.

McGuireWoods’ experienced broker-dealer/investment adviser team will continue to monitor and report on important issues affecting the broker-dealer industry.  For more information, contact the authors of this article or any member of the team.

Photo of Alexander Madrid Alexander Madrid
Read more about Alexander MadridEmail
Photo of Emily P. Gordy Emily P. Gordy

Emily advises her clients as they navigate the complexities inherent in the securities regulatory environment. Drawing on her wealth of experience as a regulator, she handles a wide range of compliance and enforcement issues affecting broker-dealers, investment advisers, investment companies, and municipal securities…

Emily advises her clients as they navigate the complexities inherent in the securities regulatory environment. Drawing on her wealth of experience as a regulator, she handles a wide range of compliance and enforcement issues affecting broker-dealers, investment advisers, investment companies, and municipal securities dealers.

Read more about Emily P. GordyEmail
Show more Show less
Photo of Cheryl Haas Cheryl Haas

Cheryl is go-to litigation counsel for Fortune 100 companies, investment companies and advisers, broker-dealers and private individuals in high-stakes disputes in federal and state courts and a variety of arbitration forum as well as before the U.S. Securities and Exchange Commission, the Financial…

Cheryl is go-to litigation counsel for Fortune 100 companies, investment companies and advisers, broker-dealers and private individuals in high-stakes disputes in federal and state courts and a variety of arbitration forum as well as before the U.S. Securities and Exchange Commission, the Financial Industry Regulatory Authority and state securities regulators across the United States.

Read more about Cheryl HaasEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Password Protected
  • Organization:
    McGuireWoods LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo