Two weeks ago, the SEC’s Office of Compliance Inspections and Examinations (OCIE) issued its newest guidance on the subject of cybersecurity in the form of a new National Exam Program (NEP) Risk Alert, issued Sept. 15. In addition to the matters discussed below, the Risk Alert contains links to several earlier Commission and OCIE materials, including to the March 2014 SEC Cybersecurity roundtable, past NEP cybersecurity-related releases, and the 2015 SEC examination priorities.

With the purpose of “[providing] additional information on the areas of focus for OCIE’s second round of cybersecurity examinations” and in addition to informing industry participants that testing and assessing the implementation of cybersecurity procedures and controls will characterize the next phase of exams, the Risk Alert identifies six key areas of focus for OCIE: (1) governance and risk assessment; (2) access rights and controls; (3) data loss prevention; (4) vendor management; (5) training; and (6) incident response. The Risk Alert also provides a sample document request, which regulated entities may use in assessing their cybersecurity programs.

A firm’s cybersecurity program, by its nature, requires ongoing review and evaluation, and OCIE and its exam staff expects senior management and boards of directors to be involved. The release of the OCIE Risk Alert provides firms with a good opportunity to reevaluate their current cybersecurity program – the six identified areas of focus highlight crucial elements of any cybersecurity program, while the sample document request provides a roadmap to the steps, processes, and documents that a regulated firm should consider in the implementation and maintenance of its cybersecurity program.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Richard M. Cutshall Richard M. Cutshall

Richard M. Cutshall is Co-Chair of the firm’s Financial, Regulatory and Compliance Practice, Co-Chair of the firm’s Private Funds Group, and Co-Chair of the firm’s Investment Management Group. Rich has experience representing clients in a variety of investment management, general securities, and corporate

Richard M. Cutshall is Co-Chair of the firm’s Financial, Regulatory and Compliance Practice, Co-Chair of the firm’s Private Funds Group, and Co-Chair of the firm’s Investment Management Group. Rich has experience representing clients in a variety of investment management, general securities, and corporate matters, including the representation of mutual funds, ETFs, and other funds registered under the Investment Company Act of 1940; fund and ETF independent directors; unregistered investment funds; federally registered, state registered, and federally and state exempt investment advisers; broker-dealers; and an array of public and private companies.

Rich represents investment adviser clients at all stages of their life cycle, from concept and formation through registration, daily operation through wind-down and exiting the business, including representing investment adviser clients on both the buy-side and sell-side in M&A transactions. He also represents clients in all aspects of investment company practice, including organizing and forming new funds and ETFs, registering mutual funds and ETFs with the SEC, and the acquisition and merger of public funds.

In the course of representing investment advisers and public and private funds, Rich advises Greenberg Traurig’s clients on all aspects of securities regulatory compliance, particularly including new and existing SEC rules; SEC examination, regulatory, and investigative initiatives and sweeps; the SEC’s proposal, adoption, and implementation of new regulations, such as the recently rewritten investment adviser marketing rule; and finding compliance solutions related to the regulatory scheme applicable to investment advisers and investment funds, including implementing both novel and long-standing SEC regulatory guidance and interpretations. He also advises clients on the day-to-day aspects of corporate governance, board and adviser fiduciary responsibility, and SEC compliance, as well as assisting clients in all aspects of SEC and other regulatory examinations.

Rich has given presentations on and assists a variety of investment management clients with their compliance with anti-money laundering laws, and has performed annual independent third party audits of several clients’ anti-money laundering policies, programs and controls.

Rich also has experience representing clients in many industries in the sale or acquisition of businesses, formation of corporate entities, sophisticated contract negotiations, and in obtaining, renewing and renegotiating the terms of financing business operations. He routinely works with clients’ chief executive officers, chief financial officers, directors, and in-house general and assistant general counsels, including occasionally working from clients’ corporate headquarters upon request. Rich works with corporate and finance clients of all sizes, from startup family-run businesses and entrepreneurial endeavors to Fortune 500 clients. He also has experience representing clients across many industries, including health care, data management, retail product display and advertising design and manufacturing, industrial manufacturing, and real estate management and brokerage industries.