OCIE Releases Observations on Cybersecurity and Resiliency Practices

OCIE Releases Observations on Cybersecurity and Resiliency Practices

Share on facebook
Share on twitter
Share on linkedin
Share on email
Share on print

On January 27, the SEC’s Office of Compliance Inspections and Examinations (OCIE) issued its observations from the most recent cybersecurity sweep examinations. These exams focused on operational resilience practices in the following areas:

  • Governance and risk management
  • Access rights and controls
  • Data loss prevention
  • Mobile security
  • Incident response and resiliency
  • Vendor management
  • Training and awareness

The observations highlight specific examples of controls that organizations have taken to potentially safeguard against threats and respond in the event of an incident.

Peter Driscoll, Director of OCIE, summarized the SEC’s cybersecurity priority and the latest release by stating: “Through risk-targeted examinations in all five examination program areas, OCIE has observed a number of practices used to manage and combat cyber risk and to build operational resiliency.  We felt it was critical to share these observations in order to allow organizations the opportunity to reflect on their own cybersecurity practices.”

This series of exams launched in 2014 with an initial assessment of what market participants were doing with respect to cybersecurity within their firms. Since then, OCIE has issued its observations, enabling other financial firms to review and update their cybersecurity programs along the way.

As with the exam program generally, OCIE’s cybersecurity exams are risk-based and intended to promote compliance with U.S. securities laws, prevent fraud, monitor risk and inform SEC policy.  Although there are currently no rules requiring firms to adopt cybersecurity programs, Greyline recommends that firms revisit the series of SEC releases and contact us with their questions.

Stay tuned for our takeaways on the latest release.

 

Related Posts

Darren Mooney

Partner and Co-Head of Business Development

Darren Mooney is a Partner and the Co-Head of Business Development at Greyline. Before joining Greyline, Darren served as deputy chief compliance officer of Partner Fund Management where he held primary responsibility for the compliance program of the second-largest hedge fund in the Bay Area. Prior to that, Darren spent five years providing compliance consulting services at Cordium and then ACA Compliance Group, where he led the company’s San Francisco office and west coast operations. In addition to providing ongoing consulting services to a variety of investment managers, including hedge fund, private equity, venture capital, real estate, quantitative and other wealth managers, Darren also regularly guided clients through the SEC registration process, implemented tailored compliance programs, supported clients’ live SEC exams, and served as an SEC-mandated independent compliance consultant following an SEC enforcement action. Darren’s other experience includes serving as deputy chief compliance officer and associate counsel at F-Squared Investments where he directly supported the compliance program during the investigation and subsequent enforcement regarding historical advertising practices. Darren has a B.S. in Economics from the University of Delaware and a J.D. from Suffolk University Law School. He is a member of the Massachusetts bar.

Annie Kong

Partner and Head of Venture Capital
Annie Kong is a Partner and Head of the Venture Capital Division at Greyline. She provides ongoing compliance consulting to investment advisers and manages client relationships. Prior to joining Greyline, Annie was part of compliance and operations at a long-only manager-of-managers that advised pension fund clients. While there, she conducted compliance and operational due diligence on SEC-registered investment advisers on the platform. She also oversaw and counseled on various legal matters across the firm. Annie has a B.A. in Economics from the University of California, San Diego, and a J.D. from the University of San Diego School of Law. She is an active member of the State Bar of California.
Greyline is pleased to announce that we are the recipient of the 2021 HFM U.S. Service Award in the Best Technology Firm – Newcomer category.