Earlier this year, the SEC announced one of its focus areas for examinations in 2014 would be cybersecurity. The SEC Office of Compliance Inspections and Examinations published a Cybersecurity Initiative Risk Alert in April that provides a sample request for information and documents, which are designed to determine the preparedness of a firm for a cybersecurity threats. Examples of questions asked include:
– Please provide a copy of the Firm’s written business continuity of operations plan that addresses mitigation of the effects of a cybersecurity incident and/or recovery from such an incident if one exists;
– Does the Firm have a Chief Information Security Officer or equivalent position? If so, please identify the person and title. If not, where does principal responsibility for overseeing cybersecurity reside within the firm?;
– Please provide a copy of the Firm’s procedures for verifying the authenticity of email requests seeking to transfer customer funds. If no written procedures exist, please describe the process.