2023-03-15 SEC Press pdf 1373 KB 64,541 chars

Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer

Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer, No. 1:17-cv-06305 (Mar. 15, 2023)

summary

The SEC proposed amendments to Regulation S-P requiring broker-dealers, investment advisers, investment companies, and transfer agents to implement written incident response programs, notify customers within 30 days of breaches involving sensitive personal information, and enforce stricter safeguards and service provider obligations to combat cyber threats and align with GLBA.

paragraph

The SEC proposed sweeping updates to Regulation S-P to mandate written incident response programs for broker-dealers, registered investment advisers, investment companies, and transfer agents, requiring notification to affected individuals within 30 days of unauthorized access to sensitive customer information such as Social Security numbers or biometric data. The rule expands safeguards and disposal requirements to cover all nonpublic personal information regardless of source, imposes 48-hour breach reporting obligations on service providers, and mandates detailed notice content including protective steps and FTC resources. While estimating $465.7 million in aggregate compliance costs, the SEC rejected exemptions and aligned annual privacy notice rules with a statutory GLBA exception to reduce administrative burdens.

narrative

The Securities and Exchange Commission proposed comprehensive amendments to Regulation S-P under the Gramm-Leach-Bliley Act to strengthen cybersecurity protections for broker-dealers, investment companies, registered investment advisers, and—newly—transfer agents. These amendments require all covered entities to adopt written incident response programs that mandate notification to affected customers within 30 days of discovering unauthorized access to sensitive customer information, including Social Security numbers, biometric data, or other identifiers capable of causing substantial harm, unless a reasonable investigation concludes no such harm is likely. The proposal broadens the scope of safeguarding and disposal requirements to encompass all nonpublic personal information, regardless of format or source, and extends contractual security obligations to third-party service providers, who must report breaches to their clients within 48 hours. Notice to affected individuals must include specific details about the incident and guidance on protective steps, such as credit monitoring and FTC resources. The SEC also introduced new recordkeeping mandates to document compliance and streamlined annual privacy notice delivery by aligning it with a statutory exception under GLBA. Designed to address rising cyber threats, inconsistent state laws, and systemic risks from remote work and third-party vendors, the rule rejects exemptions and estimates aggregate compliance costs of $465.7 million and 1.1 million hours across the industry.

Enriched metadata

Scheme
cyber-fraud (95%)
Case No.
1:17-cv-06305
Victims
730,000
Classified cyber-fraud(confidence 95%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Statutes
15 U.S.C. 680115 U.S.C. 1681-168115 U.S.C. 78a15 U.S.C. 80a-115 U.S.C. 80b-115 U.S.C. 80a-315 U.S.C. 6801(b)15 U.S.C. 6801-682715 U.S.C. 6803(a)15 U.S.C. 1681w15 U.S.C. 78o(b)15 U.S.C. 6804(a)15 U.S.C. 1681w(a)15 U.S.C. 1681s15 U.S.C. 80b-2(a)15 U.S.C. 6801(a)15 U.S.C. 1681a(d)15 U.S.C. 1681(d)15 U.S.C. 1681w(2)12 U.S.C. 1843(k)15 U.S.C. 78c(a)17 CFR 248.3(r)17 CFR 248.30(a)17 CFR 248.30(b)17 CFR 248.3(g)17 CFR 248.1-24817 CFR 248.417 CFR 248.517 CFR 240.17d-117 CFR 240.15c3-317 CFR 242.100017 CFR 248.1317 CFR 248.201(d)17 CFR 248.201(e)17 CFR 240.17Ad-717 CFR 240.17ad-717 CFR 248.9(a)17 CFR 248.3(c)17 CFR 248.3016 CFR 682.1(b)17 CFR 162.2(g)16 CFR 314.2(d)16 CFR 313.3(n)15 CFR 314.1(b)section 3 of the Investment Company Actsection 3(c)(1) or 3(c)(7) of the Investment Company Actsection 3(c)(1) or 3(c)(7) of the Investment Company Actsection 3(c)(1) or 3(c)(7) of the Investment Company Actsection 15(b)(11) of the Securities Exchange Actsection 15(b)(11) of the Securities Exchange ActRule 38a-1(a)
Parties
Aaron ElliasBrice PrinceDevin Ryanedward schellhornemily westerberg russellJames WinteringJessica Leonardojohn faheymarc mehrespandSecurities and Exchange Commissionsusan poklembaTaylor Evensonthoreau bartmann
Keywords
informationcustomer informationcustomerseeincidentincident responsecoveredcovered institutionunauthorized accessresponseresponse programaccessunauthorizedproposedinstitution

Extracted insights

Entities 13
  • person susan poklemba ×2
  • person Aaron Ellias
  • person Brice Prince
  • person Devin Ryan
  • person edward schellhorn
  • person emily westerberg russell
  • person James Wintering
  • person Jessica Leonardo
  • person john fahey
  • person marc mehrespand
  • agency Securities and Exchange Commission
  • person Taylor Evenson
  • person thoreau bartmann
Triples 5
  • Securities and Exchange Commission is proposing rule amendments that would require broker-dealers, investment companies, and registered investment advisers to adopt written policies and procedures for incident response programs
  • Commission will post all comments on the Commission’s website
  • Comments should be received on or before June 5, 2023
  • Susan Poklemba is listed as contact for further information
  • Proposed amendments extend the application of the safeguards provisions to transfer agents
Text layers
Extracted body text (64,541c)
advisers”)

(“Commission” or “SEC”)

brokers and dealers (or “ ”)

registered with the Commission (“registered investment

 Use the Commission’s internet comment form

post all comments on the Commission’s website (http://ww Comments are also available for website viewing and printing in the Commission’s Public

conditions may limit access to the Commission’s

lable on the Commission’s website. To ensure direct

Chief Counsel’s Office

the Code of Federal Regulations (“CFR”).

1

1

’s provisions include

(b) (“disposal rule”), which

to obtain, share, and maintain individuals’

] (“Reg. S Release”). Regulation S

Similarly, employees’ securities companies –

.” The term “covered institutions referred to as “you” in Regulation S

apply, are sometimes referred to as “covered ” is sometimes used in this release to refer to

FBI’s Internet Crime Complaint Center received 847,376 complaints in 2021

the Financial Industry Regulatory Authority (“ “) 2021 Report on FINRA’s

Examinations) (“EXAMS”),

(Apr. 16, 2019) (“Reg. S

Alert”),

(Observations Risk Alert”)

organization (“SRO”) rules requiring written supervisory procedures and written business

an institution’s preparedness and the

States also differ regarding a firm’s duty to investigate a data breach when

BA’s requirements for standards for safeguarding customer records and information

California residents of a data breach generally required when a resident’s personal information was or is reasonably believed to have been acquired by an unauthorized person; “pe ” is defined to mean an individual’s first or last name in combination with one of a list

likely to cause substantial harm to the resident to whom the information relates; “sensitive fying information” is defined as the resident’s first or last name in combination

As a result, a firm’s notific

defining “sensitive customer information” more broadly than the current definitions used by at

requirements of the entity’s “primary federal regulator.”

customers’ information

that financial institution’s

among other things, “

6801(b)(3) (emphasis added). We agree with the Federal Trade Commission (“FTC”) that pertaining to another institution’s customers is consistent with the purp

definition of “customer information” that would include both nonpublic personal information that

17 CFR 248.3(g)(2)(iii) (“An individual

dealer’s consumers in order to clear transactions.”).

nfidentiality of customers’ personal information.

unless otherwise noted, we refer to them collectively as “transfer agents” for

term “customer records and information” defined as “

ursuant to the Fair and Accurate Credit Transactions Act of 2003 (“FACT Act”),

“Consumer report information”

information”)

fining “customer records or information”)

(“Disposal Rule Adopting Release”). Section “requiring” but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ anddealer’s

(Mar. 13, 2008)] (“2008 Proposal”). The amendments to Regulation S dealer’s designated examining au ble financial responsibility rules (including the Commission’s customer applicable to “ which would have been defined report information” that is

suggested modifying the proposed amendments’ information security

Letter” Letter”

regulators’ ’s safeguards rule. The

financial institutions under the FTC’s GLBA jurisdiction to establish a written incident response

Information, 86 FR 70272 (Dec. 9, 2021) (“FTC Safeguards Release”). As amended, the FTC’s rule requires that a response plan address security events materially affecting the confidentiality, integrity, or availability of customer information in the financial institution’s an institution’s independent obligation to perform notification as required by state law. Union Administration (“NCUA”)

(Mar. 29, 2005) (“Banking Agencies’ Incident Response Guidance”). The Banking Agencies’ Incident Response Guidance provides,

protection of customers’ nonpublic personal information. These proposed amendments would

applying the protections of both rules to “customer information,” a newly defined term. We also

for the definition of “sensitive customer information.”

13524 (Mar. 9, 2022)] (“Investment Management Cybersecurity Proposal”); Cybersecurity Proposal” ) ( “Corporation Finance ( “Exchange ”) and , 2023), (“Regulation SCI Proposal”)

of a customer’s nonpublic personal

with approximately 330,000 different households, by accessing two of the firm’s portals. The (“PII”) such as customers’ full

92806 (Aug. 30, 2021) (“Cambridge Order”),

third parties resulting in the exposure of at least 2,177 customers’ PII stored i email accounts and potential exposure of another 3,800 customers’ PII); Commission Order

omers’ PII stored in the compromised email

92807 (Aug. 30, 2021) (“KMS Order”),

for example, phishing or credential stuffing. “Phishing” is “spoofed” email to trick a victim into taking action, such as downloading malicious software or website for the system or service, while “credential stuffing” is a means of gaining unauthorized

taking over a customer’s acc to obtain unauthorized entry to a customer’s online brokerag without the customer’s ’s

The “dark web” is a part of the internet that requires specialized software t specifically designed to facilitate anonymity by obscuring users’ identities, including by hiding users’ internet protocol addresses. The anonymity provided by the dark web has allowed users to

institution’s

and unauthorized trading scheme with at least one other person. The SEC’s complaint alleged

the unauthorized trading of stock in the victims’ accounts.

rule refer to “ “use.” ”, the word “ ” modifies both “access” and information.” for a discussion of “customer

avoid inadequate responses based on a covered institution’s

amendments would require that a covered institution’s

for the definition of “sensitive customer information ”

, which includes a discussion of “sensitive customer information.”

a covered institution’s

)(3)(i). The term “customer information systems” would mean the support the covered institution’s operations.

rules would be applicable to “Market Entities” s (collectively, “Covered Entities”) as well as broker “fund information system” and “fund information.”

the Market Entities’ institutions’ policies the proposed rule’s requirement that

.

a covered institution’s

the proposed rule’s requirements

the covered institutions’

For example, a bad actor could use a service provider’s access to a covered institution’s systems to infiltrate the covered institution’s network through a

(“Adviser Outsourcing Proposal”); FINRA Notice to

NIST defines a “cybersecurity compromise in the supply chain” as “an occurrence within the

and thereby gain unauthorized access to the covered institution’s customer

we propose to define the term “service provider” to

institution’s

anywhere during the life cycle of the system, product or service.”

(Best Practices in Cyber Supply Chain Risk Management”)

was able to gain a foothold in Target’s network through a third

a bad actor breached the Target Corporation’s

A “Kill Chain” Analysis of the 2013

institution’s

could create a risk of substantial harm to the covered institution’s c

The proposed amendments would require that a covered institution’s incident response

the proposed definition of “service provider”?

we exclude a covered institution’s

“service provider” in this ruledefinitions of “service provider” that should be included in the definition of “service providers?”

institution’s customer information. Is

P’s opt

ID’s requirements

11, “service provider” investment adviser. In the proposal, a “covered function” would mean cause a material negative impact on the adviser’s clients or on the adviser’s requires financial institutions subject to the Commission’s jurisdiction with covered

Banking Agencies’ Incident Response Guidance

Banking Agencies’ Incident Response Guidance

Is “as” an

such as “as soon as practicable”?

A risk of harm provision under a particular state’s rules

Notification Laws, (“NCSL Security Breach Notification Law Resource”),

sufficiently clear? Is a standard of “reasonably likely” appropriate? Should the

“reasonably possible” which would suggest a more expansive standard than “likely”?

. Is this standard “not reasonably

” for rebutting the presumption to notify the appropriate standard?

Should the standard be “not reasonably possible”?

some states’ laws

” likely risk of substantial harm or inconvenience.” definition of “sensitive customer information.”

ould create a “reasonably notice requirements would be information pertaining to a covered institution’s customers and customer’s Social Security number may not

linked to the individual, would be sensitive because they have been used in “Social Security only” or “synthetic” identity theft. In this type of identity theft, a Social Security create a new (or “synthetic”) identity, which then may allow the malicious actor to, among other information that can be used alone to authenticate an individual’s identity. A biometric record of

mother’s maiden name A mother’s maid

In this respect, our proposed definition is broader than the definition of “sensitive customer information” provided in the Banking Agencies’ Incident Response Guidance. That definition includes a customer’s name, address, or telephone number, only in conjunction with other pieces

Tapping “Synthetic Identity Fraud” to Commit

cipher text could be decrypted, it would also reduce the likelihood that the cipher text’s

definition of “sensitive customer

acquisition of certain “unencrypted, computerized data information,” and defining “encrypted” as data transformed “through the use of a one hundred twenty

confidential process or key” unless the data was “acquired in combination with any key, security data.”).

We request comment on the proposed rule’s definition of sensitive customer information

Should we broaden the proposed definition of “sensitive customer information” to

Agencies’ Incide

when linked would permit access to an individual’s accounts? Should the

ecurity number, driver’s license or other government identification number,

create a “reasonably likely” risk

For example, would a “reasonably foreseeable” standard

information the compromise of which “could” create a reasonably likely risk

customer information that “would” create such risk?

Should we provide additional or alternative examples of what constitutes “sensitive customer information” in the rule text?

Is encryption a relevant factor to a covered institution’s determination of the

,

covered institution’s determination that cipher text’s

Should we except from the definition of “sensitive customer information” encrypted

Definition of “Substantial Harm or Inconvenience”

We propose to define “substantial harm or inconvenience” to mean “personal injury, or

,” and provide

P requires a covered institution’s

malicious actor’s

,

Congress’s goal

We request comment on the proposed rule’s definition of substantial harm or

proposed definition of “substantial harm or inconvenience”?

other than “substantial” and “more than trivial” in describing the types of harms that

Is “more

“the policy of the Congress that each financial institution

the security and confidentiality of these customers’ nonpublic personal information.”

“more than trivial” the appropriate standard?

“immaterial” or “ significant”?

a numerical or other objective standard for “ substantial” harm or

Should a harm that is a “ personal injury,” such as phys

“trivial,” similar to our proposed treatment of

Should the standard for a harm that is a “ personal injury” be something other than “ trivial?”

notwithstanding a covered institution’s determination to

which specific individuals’ data

identify which specific individuals’ sensitive customer information has been accessed or used

. Accordingly, proposed rule 248.30(b)(3)(iii) and (b)(4)(i) refers to “affected individuals without authorization” rather than “customer.” This is because the term “customer” is defined in section 248.3(j) as “a consumer that has a customer relationship with the [covered] institution,”

institutions provide notices “as soon as practicable”

identity theft or other harm. The amount of time that would constitute “as soon as practicable” may vary based on several factors,

“as soon as practicable”The proposal’s as practicable.”

provide notices to affected customers “as soon

institution’s timely and uniform customer notification that customers’ sensitive customer information has

We request comment on the proposed rule’s notification timing requirements

Should the rule require institutions to provide notice “as soon as possible ”

Should the rule provide parameters to define “as soon as practicable,” “as soon as possible ” “as soon as reasonably practicable”

“becoming aware that unauthorized access to or use of customer information has

”?

for example, after the covered institution “reasonably should have

been aware” of the incident or, alternatively, after completing its assessment of the

the timing requirement should begin upon “becoming

” should we provide covered institutions

individuals may obtain “consumer reports” from consumer reporting we refer to “credit reports” in

Banking Agencies’ Incident Response Guidance notices include a recommendation that customers obtain “credit reports,” and in part, because we ” Consumer Financial Protection Bureau (“CFPB”),

and opt out notices) and 17 CFR 248.3(c)(1) (defining “clear and conspicuous”)

17 CFR 248.3(c)(2) (providing examples explaining what is meant by the terms “reasonably understandable” and “designed to call attention” ).

whether to provide certain information “as appropriate” on a case

“consumer reports” “credit reports” more familiar with the term “credit report”

of 45% of jobs involving teleworking “at least some of the time.”

“customer information,” a newly defined term

institution’s customers

defined “customer

” The Commission has “broad rulemaking authority” to effectuate “the policy of the Congress that information.” f these customers’ nonpublic personal

’s protect “customer records and information,” “consumer report information,” a

15 U.S.C. 6801(a) (“It is the policy of the Congress that each financial institution has an security and confidentiality of those customers’ nonpublic personal information.”) (emphasis

disposal of “consumer information, or any compilation of consumer information, derived from consumer reports for a business purpose.”

“consumer report information” about an individual “that is a consumer

report.” 17

“Consumer report”

the term “customer records and information” in the safeguards rule with term “customer information”

“customer information” to encompass any record containing “nonpublic personal information” about “a customer of a financial institution,” whether in paper,

GLBA, which focuses on protecting “nonpublic personal information” of those who are “customers” of financial institutions.

conform more closely to the definition of “customer information” in the safeguards rule adopted

to change the term “consumer report information” currently in Regulation S P to “consumer information” (without changing the definition) to conform to the term used by

Information Security Standards (“OCC Information Security Guidance”), at I.C. 2 to Part 208 (“FRB Information Security Guidance”), at I.C.2.b.

We propose a separate definition of “customer information” applicable to transfer agents.

16 CFR 314.2(d) (FTC safeguards rule defining “customer information” to mean “any record

“continuing obligation” to protect the security and confidentiality of customers’ nonpublic

FACT Act focuses on protecting “consumer information ”

eliminating an institution’s need to

rule more closely to the Banking Agencies’ Safeguards Guidance.

he Commission’s statutory mandate

or on behalf of you or your affiliates”). The proposed rules would not require covered institutions to be responsible for their affiliates’ policies and procedures for safeguarding customer

proposed rule 248.30(c)(1). “Customer information” is n

“customer information,” because the safeguards rule is adopted pursuant to the GLBA and therefore is limited to information about “customers.”

associations’ must develop, implement, and maintain appropriate measures to properly dispose of customer information and consumer information.”);

comment on the proposed definition of “ s’ Is the proposed definition of “customer information,” which includes nonpublic personal information about an institution’s own customers that

from a third party financial institution about that institution’s customers

P defines “customer” as “a consumer who has a customer relationship with you.” The

rule, therefore, only protects the “records and information” of individuals who are

d institution’s own

the custodian of a former client’s assets wou

individual’s c

The safeguards rule is applicable to “consumer information” only to the extent it overlaps with “customer information.”

P defines “financial institution” generally to mean any institution the business of

approach is consistent with the FTC’s

the scope? For example, should the rules’ protections for “customer information”

, an employee’s or former customer’s bank account

customers’ information that the covered institution

Should employees’ nonpublic personal information be

314.1(b) (providing that the FTC’s safeguards rule “applies to all customer information h information to you”)

--- page 64 ---

--- page 65 ---

--- page 66 ---

--- page 67 ---

--- page 68 ---

--- page 69 ---

--- page 70 ---

--- page 71 ---

--- page 72 ---

--- page 73 ---

--- page 74 ---

--- page 75 ---

--- page 76 ---

--- page 77 ---

--- page 78 ---

--- page 79 ---

--- page 80 ---

--- page 81 ---

--- page 82 ---

--- page 83 ---

--- page 84 ---

--- page 85 ---issuers the official record of ownership of such issuer’s securities; (ii) cancel old certificates, and other detailed and individualized information related to the transfer agents’ recordkeeping

Exchange Act Release No. 76743 (Dec. 22, 2015) [80 FR 81948, 81949 (Dec. 31, 2015)] (“2015 ”).

account for this, the proposed definition of “customer information” with respect to a transfer

“ nonpublic personal information...

Currently, the disposal rule only applies to those transfer agents “registered with the Commission.”

proposed definition of a “covered institution” as “a transfer agent registered with the ate regulatory agency.”

ection 216 of the FACT Act was to “prevent unauthorized disclosure of information contained

ud or related crimes, including identity theft.” that covered entities’ consumers would

indicated that the disposal rule as proposed would impose “minimal costs” on firms in the form

under the disposal rule through the taking of “reasonable measures” to protect against

“minimize the burden of compliance for smaller entities.”

FR 56304 (Sept. 20, 2004)] (“2004 Proposing Release”), at 56308.

“residual jurisdiction” under the same congressional mandate, to enact both

registered, the Commission “is empowered with broad rulemaking authority over all a transfer agent’s activities as a transfer agent.”

(d)(1) (providing that “n as ... transfer agent such rules and regulations” as the Commission may prescribe); Exchange Act (providing that “Nothing in the preceding imit ... the Commission’s der.”).

Commission’s experience administering the transfer agent examination program, we are aware

A transfer agent’s failure to account for such risks and take appropriate steps to

found on the systems they maintain will help prevent securityholders’ customer information from

We use the term “paying agent services” here to refer to administrative, recordkeeping, and

definition of “customer information” appropriate with

of “customer information”

Notice

Dealer Release”).

dealers from the rule’s scope noting its belief that Congress did not intend for the Commission’s FACT Act rules to apply to entities subject to primary oversight by

and the disposal rule. First, the proposed rule would define a “covered institution” to include “any broker or dealer,” without excluding notice

P’s disposal rule (currently rule 248.30(b)).

at n.23 (stating “

”);

.”).

page 97 ---

P’s substituted compliance provisions would still apply to notice

also employ this proposed definition of a “covered institution ” it would retain the disposal rule’s

the CFTC’s financial privacy rules, the Commission believes the benefits and

page 98 ---

alter the scope of either rule’s application to notice

institution’s

tain investment companies, such as some employees’ securities

page 99 ---

covered institution’s periodic

(“proper disposal policies and procedures are enc

”)

page 100 ---

informing them about the institution’s privacy policies.

informing them about the institution’s privacy policies.

Fixing America’s Surface Transportation (“FAST ”)

new section 503(f) to GLBA (“statutory exception”).

“consumer” as “

P, an institution’s customer is a “consumer” that has a

” 17 CFR 248.3(g).

page 104 ---

the requirement to provide customers an opportunity to opt out of the institution’s information

the words “Except as provided by paragraph (e) of this section ....”

page 105 ---

’s policies

he institution’s most recent privacy notice sent to customers. We are not

the notice to describe the customer’s right to opt out of the

requiring an institution’s privacy notice to include any

institution’s affiliates and do not affect whether the statutory exception is satisfied 603(d)(2)(iii) (excluding from the term “consumer report” communication of other

the Fixing America’s Surface Transportation Act, 83 FR 63450 (Dec. 10, 2018), at n.17; CFPB,

page 106 ---

notice to an individual who becomes the institution’s customer no later than when it

“ annually”

page 107 ---

institution’s change in policies or practices. tion’s change in policies or practices does not

page 108 ---

-

page 109 ---

collectively, “departing personnel”)

he shared information could not include any customer’s account number, Social

page 110 ---

from this proposal’s notice and opt out requirements

opriate in light of the GLBA’s goals? If so, is

page 111 ---

“cybersecurity risk” as “an effect of uncertainty on or within information and technology.”

page 112 ---

alternative trading systems (“ “)

and surrounding text as to the meaning of “covered institution.”

An “SCI Entity” is currently defined to include

page 113 ---

“SCI entity”

based trading threshold in national market system (“NMS”) stocks, exchange

17 CFR 242.1000 (defining the terms “SCI alternative trading system,” “SCI self system,” and “Exempt clearing agency subject to ARP,” and including all of those defined terms in the definition of “SCI ties”)

page 114 ---

P’s requirements apply to all br dealers, except for “notice dealers” (as defined in 17 CFR 248.30), who in most cases will be deemed to be in

P’s obligations.

. of this release, the term “broker dealer”

the Commission (“registered transfer agents”) (but not transfer agents registered with another P’s disposal rule.

ntity’s policies and

page 115 ---

the policies and procedures required by Regulation SCI focus on the SCI entities’

page 116 ---

-

page 117 ---

the Commission (“registered transfer agents”) (but not transfer agents registered with another P’s disposal rule.

ntity’s policies and

page 118 ---

-P currently defines the term “disposal” to mean: (1) the Regulation SCI’s obligation to take corrective action ma

Covered Entity’s

and remediate any cybersecurity threats and vulnerabilities with respect to the Covered Entity’s

, a Covered Entity’s policies and procedures would

ntity’s information systems and the information residing

To the extent an entity’s policies and procedures under the Exchange Act Cybersecurity Proposal

’s risk

Covered Entity’s policies and

need to require periodic assessments of cybersecurity risks associated with the Covered Entity’s

Entity’s information systems and any of the Covered Entity’s information residing on those

riity risks associated with the Covered Entity’s use of these

, a Covered Entity’s policies and

Covered Entity’s information, or are otherwise permitted to access the Covered Entity’s

to protect the Covered Entity’s information systems and information residing on those systems.

P’s proposed policy

y’s policies and

behavior for individuals authorized to access the Covered Entity’s information systems and the

, a Covered Entity’s policies and include measures designed to protect the Covered Entity’s information

based on a periodic assessment of the Covered Entity’s information systems and the information

--- page 125 ---

formation to the Covered Entity’s business operations;

--- page 126 ---

-

--- page 127 ---

would, if it experiences a “significant cybersecurity incident,” be required to

entity’s business and operations and how the covered entity assesses, prioritizes, and addresses

--- page 128 ---

summary description of the incident via EDGAR and the entity’s business

Covered Entity’s exposure to materia

a way for market participants to evaluate the Covered Entity’s cybersecurity risks and

--- page 129 ---

dealer, with information they can use to evaluate the event’s impact on their trading and

--- page 130 ---

and business development companies (“covered IM entities”)

--- page 131 ---

confidentiality, integrity, or availability of an adviser or fund’s information or information

impact on the adviser’s clients or on the adviser’s ability to provide investment advisory services

--- page 132 ---

such persons’

--- page 133 ---

-

--- page 134 ---

-

--- page 135 ---

<table>
  <tr>
    <td></td>
    <td></td>
  </tr>
  <tr>
    <td></td>
    <td></td>
  </tr>
</table>

--- page 136 ---

"smaller " for this purpose?

--- page 137 ---

As discussed above, “customers” includes not only custo the possession of covered institutions. In addition, with respect to a transfer agent, “customers” refers to “

--- page 138 ---

covered records to “customer information” and extending the covered population

--- page 139 ---

notices improve customers’ ability to take

--- page 140 ---

defining “sensitive customer information” more broadly than the

Throughout this economic analysis, “compliance costs” refers to the direct costs that borne in order to avoid violating the Commission’s rules.

costs” excludes costs that are not require Commission’s rules ( As used here, “compliance

--- page 141 ---

customers’ customers, and that both these effects would improve customers’ ability to act to protect their customers’ sensitive information.

--- page 142 ---

’ ability to compete with t

In a perfectly competitive market, market forces would lead firms to “efficiently”

--- page 143 ---

information about the firm’s product or service

customers’ (current

covered institutions’

economic texts, this “efficient” safeguarding of customer information would correspond to

Here, “adequate safeguards” can be thought of as the level of safeguards in a world where the level of firms’ efforts (and the costs of these

Press release, U.S. Fed. Trade Comm’n,

--- page 144 ---

, “underspend”)

covered institution’

and in so doing influence firms’ efforts toward protecting customer information.

enhance firms’

“underspending” on cybersecurity.

(Mar. 2020) (“IIF/McKinsey Report”),

In the case of transfer agents such effects would be mediated through firms’ choice of transfer prefer to avoid employing the services of transfer agents that allow their investors’ information to

(“ ”)

--- page 145 ---

,

competitive “race to the bottom.”

by the proposed amendments (“covered institutions”

The “bottom” in such a race is a level of cybersecurity spending that is too low from an efficiency

--- page 146 ---

1

--- page 147 ---

“underspending” on cybersecurity

(stating 58% of surveyed banks’ Chief Risk Officers cite “inability to manage cybersecurity risk” as the top strategic risk); s Public cloud security ‘just barely adequate,’ experts say,

providers “should be doing more on security.”)

--- page 148 ---

regulations that affect covered institutions’ effort toward safeguarding customers’ information.

Annual Report”),

Annual Report (Jan. 2022) (“ITRC Data Breach (“IBM Cost of Data Breach Report”),

--- page 149 ---

regulations aimed at increasing firms’ efforts toward safeguarding customer information reduce

“personal information” of a state’s resident is either accessed or acquired in an unauthorized

number, driver’s license number

information. “States” in this discussion includes the 50 U.S. states and the District of Columbia,

--- page 150 ---

certain harms (“ harm exception”).

commonly include: “harm” generally (12), identity theft or other fraud (10), misuse of personal

harms referenced in states’

3501, (defining “personal information” to include credit card

551 (defining “personal information” to include an individual’smade “without unreasonable delay,” or “in the most expedient time possible and without unreasonable delay”).

“ not later than 30 days after the date of determination that the breach occurred”

1798.82(a) (disclosure to be made “in the most expedient time possible and without unreasonable delay” but allowing for needs of law enforcement and

716 (notice to be made “in the most expedient time possible

integrity of the computerized data system”); Fla. Stat. 501.171(4)(a) (notice to be made “as ly as practicable and without unreasonable delay ... but no later than 30 days after the determination of a breach” unless delayed at the request of law enforcement or waived pursuant to the state’s no

[68 FR 74714 (Dec. 24, 2003)], at n.22 (“Compliance Program Release”) ID applies to “financial institutions” or “creditors” that offer or maintain “covered accounts.” 2013)] (“

Some covered institutions may also be subject to other regulators’ rules implicating

cies’ Incident Response Guidance.

Agencies’ guidelines require covered financial institutions to develop a response program

sensitive customer information “has occurred or is reasonably possible ”

notices to occur “as soon as possible ” but permit delays if “an appropriate law

” Under the guidelines, “sensitive customer information” means “a customer’s name, address, or

customer’s ecuirty number, driver’s license number, account number, credit or debit card

customer’s account.” ddition “any combination of components of customer information

that would allow someone to log onto or access the customer’s account, such as user name and

Banking Agencies’ Incident Response Guidance

Commission’s recently amended Standards for Safeguarding Customer Information (“ Safeguards Rule”) that contains a number of modifications to the existing rule with respect to

fecting customers’ securities transactions, providing

holding customers’ funds and securities; (4) handling clearance and settlement of trades; (5)

Such information would include the customers’ names, tax numbers, telephone numbers, broker,

dealers are not “carrying broker dealers” and therefore do not report the numbers of customer

of clients’

Here, “custody” means “holding, directly or i authority to obtain possession of them.” An adviser also has “custody” if “a related person holds, n connection with advisory services [the adviser] provide[s] to clients.”

a “ ng”

# Advisers

# States

companies (‘‘  ’’) Unit Investment Trusts (‘‘  ’’) entities’ companies

Because they are not operating companies, investment companies do not have ‘‘customers’’ as such, and thus are unlikely to possess significant amounts of nonpublic ‘‘customer’’ information

employees’ securities companies

the investment companies that would be subject to the proposed rules are part of a ‘‘family’’ of

As used here, ‘‘family’’ refers to a set of funds reporting the same family investment company

changes of ownership (“transfers”), communicat

registered securities are held in “street name” where the ultimate ownership

Rather the individual’s broker maintains the records of the individual’s

transfers a transfer agent would need to provide a customer’s identification information in the

—to other transfer agents (“service companies”).

” institutions’ ’ core functions would generally offering more “traditional” “otherwise [] permitted access to customer information” reliance on third parties for

ed institutions to “develop, implement safeguards for the protection of customer information” “designed to detect, respond to, and recover from unauthorized access to or use of customer

institutions’ response programs

or example, NIST’s Computer Security

Similar analogues are found in other reports, recommendations, and other regulators’

improvements to covered institutions’ processe

process for handling them is unlikely to be routine for a covered institution’s covered institution’s

institutions’ with the proposed rule’s requirements For example, the Banking Agencies’ Guidance states that covered institutions that are king Agencies’ geographic catering and that these entities will all have a “national presence ”

customers’ perceptions of the firm). Thus, the costs of

“Cybersecurity Incident Response and Recovery” element of the policies and procedure required

covered institutions’ customers—

proposed amendments would require that a covered institution’s incident response

“service provider” is defined broadly, as “

institution.”

to facilitate covered institutions’ compliance with the proposed requirements.

institutions’ compliance with the proposed amendments.

critical function likely “ processes, or otherwise is permitted access to customer information”

d institutions’ compliance, but may be unwilling to enter into suitable

address “generic” vulnerabilities that apply to all customers ( mitigate vulnerabilities “specific” to a given customer ( Smaller, “upstart” service providers may be more willing to provide unrealistic contractual

The “strength” of a data breach laws generally applicable to compromises of their residents’ information.

each customer’s state of residence, with the

provisions to the overall “strength”

“strength” of individualextends to “all customer information in the possession of a covered institution, institutions and has been provided to the covered institution.”

s from the covered institution’s “core” customer account management systems

These “GLBA Safe Harbors”

1

in the most

notification deadlines should increase customers’ ability to take effective

state statute requires notice be given “without unreasonable delay, and no more than thirty system” RCW 19.255.010(8).

Days to Identify Breach

data from the Washington Attorney General’s Office for 2021, “containment” of data breaches it takes an average of 75 days to “contain” ccording to IBM’s study for 2021, of “containment ” raising the attack’s

, “sensitive customer information” is defined

—cases where the “sensitive customer information” be problematic if they reduce customers’ sensitivity to data breach notices. In addition,

“sensitive customer information” is defined as “any component of

” ’s basis in “any compon customer information”

mother’s maiden name,

a customer’s name together with one or

a driver’s license number, or a

a covered institution’s compromise of the customer’s

linked with the customer’s name) can trigger the not

customer’s email address in combination with a security question and answer would only trigger

moreover, the compromise of information such as a customer’s name, combined with her

increase customers’ ability to take actions to mit

Under the proposal, the access or use without authorization of an individual’s sensitive

Currently, 21 states’ notification laws do

ed recordkeeping requirements would help facilitate the Commission’s

We distinguish here between the theoretical “baseline” in which the self of the statute have not come into effect and the current “status quo” (in which they have).

of covered institutions’ response to incidents,

’ service providers, the overall

obtain “reasonable assurances”

Under this alternative we would use the proposal’s “service provider ” institution.”

“maintain” computerized data containing private information

d institutions’ compliance with the proposed

proposal’s requirement for written contracts, we expect that “reasonable assurances” would

to document the “reasonable assurances,”

red to “reasonable assurances,” a written contract is clearer,

critical function likely “

processes, or otherwise is permitted access to customer information”

the “possible misuse” of sensitive customer information (rather than the proposed

Additionally, the service provider’s standard terms and conditions might in some

customers’

proposed, notification is triggered by the “reasonable likelihood” that sensitive

an express safe harbor may not be as protective as the proposal’s

“a reasonably likely risk of substantial harm or incon

Here, “secure procedures” refers to the secure implementation of encryption algorithms and

credentials belonging to LastPass’ customers was exfil

attempts to decrypt the passwords by guessing a customer’s

customers’

attacker’s location, identity

enhance law enforcement’s

Banking Agencies’ Inci

investigators may “avoid tipping off the adversary that their presence in the network has been discovered”).

law enforcement’s knowledge of attackers’ recovery of criminals’ ill

contain “ ” Paperwork Reduction Act of 1995 (“PRA”).

(“OMB”) for review in accordance with the PRA.

0610, the title of which is, “Rule 248.30, Procedures ion; disposal of consumer report information.”

P’s notice and opt

— 3 —

Q; and data on employees’ securities companies

The Commission’s estimates of the relevant wage rates are based on

The Commission’s estimates of the relevant wage rates for external time costs, such

covered institution’s

accuracy of the Commission’s estimate of the burden of the proposed collection of information;

(RFA")

Analysis (“IRFA”) that describes the impact of the proposed rule on small entities, unless the

enhance the protection of customers’ nonpublic personal

by applying the protections of both rules to “customer information ”

P’s annual

Improve covered institutions’

that a covered institution’s response program include policies and procedures

organization (collectively, “small entity”) for purposes

P’s annual privacy notice delive

ce a fraud alert in the individual’s credit reports to put the individual’s sion’s website address where individuals may obtain government

P’s annual privacy notice delivery provisions

records covered by the rule, and an institution’s

Banking Agencies’ Incident Response Guidance

Agencies’ Incident Response Guidance

overlap or conflict with the Banking Agencies’ Incident Response Guidanc

ubpart C, (requiring financial institutions subject to the Commission’s jurisdiction

protections for these entities’ customers and compro

overlap or conflict with the Banking Agencies’ Incident Response Guidance(SBREFA’’), the Commission must advise OMB whether a proposed regulation considered “major” rule. Under SBREFA, a rule is “major” where, if adopted, it results in or is

We request comment on whether our proposal would be a “major rule” for purposes of

by, in paragraph (b), replacing the words “ ” with “ ”; and replacing the words “Federal Trade Commission’s” with “Consumer Financial Protection Bureau’s.”

unable to identify which specific individuals’ sensitive customer informati

individual’

(“ARA”)

institution’s operations.

combination with similar information that could be used to gain access to the customer’s account

,

In paragraph (a)(7), removing the period at the end of paragraph and adding “; and” in
OCR text (64,541c · gpumon-ocr-api · 90% conf)
advisers”)

(“Commission” or “SEC”)

brokers and dealers (or “ ”)

registered with the Commission (“registered investment

 Use the Commission’s internet comment form

post all comments on the Commission’s website (http://ww Comments are also available for website viewing and printing in the Commission’s Public

conditions may limit access to the Commission’s

lable on the Commission’s website. To ensure direct

Chief Counsel’s Office

the Code of Federal Regulations (“CFR”).

1

1

’s provisions include

(b) (“disposal rule”), which

to obtain, share, and maintain individuals’

] (“Reg. S Release”). Regulation S

Similarly, employees’ securities companies –

.” The term “covered institutions referred to as “you” in Regulation S

apply, are sometimes referred to as “covered ” is sometimes used in this release to refer to

FBI’s Internet Crime Complaint Center received 847,376 complaints in 2021

the Financial Industry Regulatory Authority (“ “) 2021 Report on FINRA’s

Examinations) (“EXAMS”),

(Apr. 16, 2019) (“Reg. S

Alert”),

(Observations Risk Alert”)

organization (“SRO”) rules requiring written supervisory procedures and written business

an institution’s preparedness and the

States also differ regarding a firm’s duty to investigate a data breach when

BA’s requirements for standards for safeguarding customer records and information

California residents of a data breach generally required when a resident’s personal information was or is reasonably believed to have been acquired by an unauthorized person; “pe ” is defined to mean an individual’s first or last name in combination with one of a list

likely to cause substantial harm to the resident to whom the information relates; “sensitive fying information” is defined as the resident’s first or last name in combination

As a result, a firm’s notific

defining “sensitive customer information” more broadly than the current definitions used by at

requirements of the entity’s “primary federal regulator.”

customers’ information

that financial institution’s

among other things, “

6801(b)(3) (emphasis added). We agree with the Federal Trade Commission (“FTC”) that pertaining to another institution’s customers is consistent with the purp

definition of “customer information” that would include both nonpublic personal information that

17 CFR 248.3(g)(2)(iii) (“An individual

dealer’s consumers in order to clear transactions.”).

nfidentiality of customers’ personal information.

unless otherwise noted, we refer to them collectively as “transfer agents” for

term “customer records and information” defined as “

ursuant to the Fair and Accurate Credit Transactions Act of 2003 (“FACT Act”),

“Consumer report information”

information”)

fining “customer records or information”)

(“Disposal Rule Adopting Release”). Section “requiring” but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ anddealer’s

(Mar. 13, 2008)] (“2008 Proposal”). The amendments to Regulation S dealer’s designated examining au ble financial responsibility rules (including the Commission’s customer applicable to “ which would have been defined report information” that is

suggested modifying the proposed amendments’ information security

Letter” Letter”

regulators’ ’s safeguards rule. The

financial institutions under the FTC’s GLBA jurisdiction to establish a written incident response

Information, 86 FR 70272 (Dec. 9, 2021) (“FTC Safeguards Release”). As amended, the FTC’s rule requires that a response plan address security events materially affecting the confidentiality, integrity, or availability of customer information in the financial institution’s an institution’s independent obligation to perform notification as required by state law. Union Administration (“NCUA”)

(Mar. 29, 2005) (“Banking Agencies’ Incident Response Guidance”). The Banking Agencies’ Incident Response Guidance provides,

protection of customers’ nonpublic personal information. These proposed amendments would

applying the protections of both rules to “customer information,” a newly defined term. We also

for the definition of “sensitive customer information.”

13524 (Mar. 9, 2022)] (“Investment Management Cybersecurity Proposal”); Cybersecurity Proposal” ) ( “Corporation Finance ( “Exchange ”) and , 2023), (“Regulation SCI Proposal”)

of a customer’s nonpublic personal

with approximately 330,000 different households, by accessing two of the firm’s portals. The (“PII”) such as customers’ full

92806 (Aug. 30, 2021) (“Cambridge Order”),

third parties resulting in the exposure of at least 2,177 customers’ PII stored i email accounts and potential exposure of another 3,800 customers’ PII); Commission Order

omers’ PII stored in the compromised email

92807 (Aug. 30, 2021) (“KMS Order”),

for example, phishing or credential stuffing. “Phishing” is “spoofed” email to trick a victim into taking action, such as downloading malicious software or website for the system or service, while “credential stuffing” is a means of gaining unauthorized

taking over a customer’s acc to obtain unauthorized entry to a customer’s online brokerag without the customer’s ’s

The “dark web” is a part of the internet that requires specialized software t specifically designed to facilitate anonymity by obscuring users’ identities, including by hiding users’ internet protocol addresses. The anonymity provided by the dark web has allowed users to

institution’s

and unauthorized trading scheme with at least one other person. The SEC’s complaint alleged

the unauthorized trading of stock in the victims’ accounts.

rule refer to “ “use.” ”, the word “ ” modifies both “access” and information.” for a discussion of “customer

avoid inadequate responses based on a covered institution’s

amendments would require that a covered institution’s

for the definition of “sensitive customer information ”

, which includes a discussion of “sensitive customer information.”

a covered institution’s

)(3)(i). The term “customer information systems” would mean the support the covered institution’s operations.

rules would be applicable to “Market Entities” s (collectively, “Covered Entities”) as well as broker “fund information system” and “fund information.”

the Market Entities’ institutions’ policies the proposed rule’s requirement that

.

a covered institution’s

the proposed rule’s requirements

the covered institutions’

For example, a bad actor could use a service provider’s access to a covered institution’s systems to infiltrate the covered institution’s network through a

(“Adviser Outsourcing Proposal”); FINRA Notice to

NIST defines a “cybersecurity compromise in the supply chain” as “an occurrence within the

and thereby gain unauthorized access to the covered institution’s customer

we propose to define the term “service provider” to

institution’s

anywhere during the life cycle of the system, product or service.”

(Best Practices in Cyber Supply Chain Risk Management”)

was able to gain a foothold in Target’s network through a third

a bad actor breached the Target Corporation’s

A “Kill Chain” Analysis of the 2013

institution’s

could create a risk of substantial harm to the covered institution’s c

The proposed amendments would require that a covered institution’s incident response

the proposed definition of “service provider”?

we exclude a covered institution’s

“service provider” in this ruledefinitions of “service provider” that should be included in the definition of “service providers?”

institution’s customer information. Is

P’s opt

ID’s requirements

11, “service provider” investment adviser. In the proposal, a “covered function” would mean cause a material negative impact on the adviser’s clients or on the adviser’s requires financial institutions subject to the Commission’s jurisdiction with covered

Banking Agencies’ Incident Response Guidance

Banking Agencies’ Incident Response Guidance

Is “as” an

such as “as soon as practicable”?

A risk of harm provision under a particular state’s rules

Notification Laws, (“NCSL Security Breach Notification Law Resource”),

sufficiently clear? Is a standard of “reasonably likely” appropriate? Should the

“reasonably possible” which would suggest a more expansive standard than “likely”?

. Is this standard “not reasonably

” for rebutting the presumption to notify the appropriate standard?

Should the standard be “not reasonably possible”?

some states’ laws

” likely risk of substantial harm or inconvenience.” definition of “sensitive customer information.”

ould create a “reasonably notice requirements would be information pertaining to a covered institution’s customers and customer’s Social Security number may not

linked to the individual, would be sensitive because they have been used in “Social Security only” or “synthetic” identity theft. In this type of identity theft, a Social Security create a new (or “synthetic”) identity, which then may allow the malicious actor to, among other information that can be used alone to authenticate an individual’s identity. A biometric record of

mother’s maiden name A mother’s maid

In this respect, our proposed definition is broader than the definition of “sensitive customer information” provided in the Banking Agencies’ Incident Response Guidance. That definition includes a customer’s name, address, or telephone number, only in conjunction with other pieces

Tapping “Synthetic Identity Fraud” to Commit

cipher text could be decrypted, it would also reduce the likelihood that the cipher text’s

definition of “sensitive customer

acquisition of certain “unencrypted, computerized data information,” and defining “encrypted” as data transformed “through the use of a one hundred twenty

confidential process or key” unless the data was “acquired in combination with any key, security data.”).

We request comment on the proposed rule’s definition of sensitive customer information

Should we broaden the proposed definition of “sensitive customer information” to

Agencies’ Incide

when linked would permit access to an individual’s accounts? Should the

ecurity number, driver’s license or other government identification number,

create a “reasonably likely” risk

For example, would a “reasonably foreseeable” standard

information the compromise of which “could” create a reasonably likely risk

customer information that “would” create such risk?

Should we provide additional or alternative examples of what constitutes “sensitive customer information” in the rule text?

Is encryption a relevant factor to a covered institution’s determination of the

,

covered institution’s determination that cipher text’s

Should we except from the definition of “sensitive customer information” encrypted

Definition of “Substantial Harm or Inconvenience”

We propose to define “substantial harm or inconvenience” to mean “personal injury, or

,” and provide

P requires a covered institution’s

malicious actor’s

,

Congress’s goal

We request comment on the proposed rule’s definition of substantial harm or

proposed definition of “substantial harm or inconvenience”?

other than “substantial” and “more than trivial” in describing the types of harms that

Is “more

“the policy of the Congress that each financial institution

the security and confidentiality of these customers’ nonpublic personal information.”

“more than trivial” the appropriate standard?

“immaterial” or “ significant”?

a numerical or other objective standard for “ substantial” harm or

Should a harm that is a “ personal injury,” such as phys

“trivial,” similar to our proposed treatment of

Should the standard for a harm that is a “ personal injury” be something other than “ trivial?”

notwithstanding a covered institution’s determination to

which specific individuals’ data

identify which specific individuals’ sensitive customer information has been accessed or used

. Accordingly, proposed rule 248.30(b)(3)(iii) and (b)(4)(i) refers to “affected individuals without authorization” rather than “customer.” This is because the term “customer” is defined in section 248.3(j) as “a consumer that has a customer relationship with the [covered] institution,”

institutions provide notices “as soon as practicable”

identity theft or other harm. The amount of time that would constitute “as soon as practicable” may vary based on several factors,

“as soon as practicable”The proposal’s as practicable.”

provide notices to affected customers “as soon

institution’s timely and uniform customer notification that customers’ sensitive customer information has

We request comment on the proposed rule’s notification timing requirements

Should the rule require institutions to provide notice “as soon as possible ”

Should the rule provide parameters to define “as soon as practicable,” “as soon as possible ” “as soon as reasonably practicable”

“becoming aware that unauthorized access to or use of customer information has

”?

for example, after the covered institution “reasonably should have

been aware” of the incident or, alternatively, after completing its assessment of the

the timing requirement should begin upon “becoming

” should we provide covered institutions

individuals may obtain “consumer reports” from consumer reporting we refer to “credit reports” in

Banking Agencies’ Incident Response Guidance notices include a recommendation that customers obtain “credit reports,” and in part, because we ” Consumer Financial Protection Bureau (“CFPB”),

and opt out notices) and 17 CFR 248.3(c)(1) (defining “clear and conspicuous”)

17 CFR 248.3(c)(2) (providing examples explaining what is meant by the terms “reasonably understandable” and “designed to call attention” ).

whether to provide certain information “as appropriate” on a case

“consumer reports” “credit reports” more familiar with the term “credit report”

of 45% of jobs involving teleworking “at least some of the time.”

“customer information,” a newly defined term

institution’s customers

defined “customer

” The Commission has “broad rulemaking authority” to effectuate “the policy of the Congress that information.” f these customers’ nonpublic personal

’s protect “customer records and information,” “consumer report information,” a

15 U.S.C. 6801(a) (“It is the policy of the Congress that each financial institution has an security and confidentiality of those customers’ nonpublic personal information.”) (emphasis

disposal of “consumer information, or any compilation of consumer information, derived from consumer reports for a business purpose.”

“consumer report information” about an individual “that is a consumer

report.” 17

“Consumer report”

the term “customer records and information” in the safeguards rule with term “customer information”

“customer information” to encompass any record containing “nonpublic personal information” about “a customer of a financial institution,” whether in paper,

GLBA, which focuses on protecting “nonpublic personal information” of those who are “customers” of financial institutions.

conform more closely to the definition of “customer information” in the safeguards rule adopted

to change the term “consumer report information” currently in Regulation S P to “consumer information” (without changing the definition) to conform to the term used by

Information Security Standards (“OCC Information Security Guidance”), at I.C. 2 to Part 208 (“FRB Information Security Guidance”), at I.C.2.b.

We propose a separate definition of “customer information” applicable to transfer agents.

16 CFR 314.2(d) (FTC safeguards rule defining “customer information” to mean “any record

“continuing obligation” to protect the security and confidentiality of customers’ nonpublic

FACT Act focuses on protecting “consumer information ”

eliminating an institution’s need to

rule more closely to the Banking Agencies’ Safeguards Guidance.

he Commission’s statutory mandate

or on behalf of you or your affiliates”). The proposed rules would not require covered institutions to be responsible for their affiliates’ policies and procedures for safeguarding customer

proposed rule 248.30(c)(1). “Customer information” is n

“customer information,” because the safeguards rule is adopted pursuant to the GLBA and therefore is limited to information about “customers.”

associations’ must develop, implement, and maintain appropriate measures to properly dispose of customer information and consumer information.”);

comment on the proposed definition of “ s’ Is the proposed definition of “customer information,” which includes nonpublic personal information about an institution’s own customers that

from a third party financial institution about that institution’s customers

P defines “customer” as “a consumer who has a customer relationship with you.” The

rule, therefore, only protects the “records and information” of individuals who are

d institution’s own

the custodian of a former client’s assets wou

individual’s c

The safeguards rule is applicable to “consumer information” only to the extent it overlaps with “customer information.”

P defines “financial institution” generally to mean any institution the business of

approach is consistent with the FTC’s

the scope? For example, should the rules’ protections for “customer information”

, an employee’s or former customer’s bank account

customers’ information that the covered institution

Should employees’ nonpublic personal information be

314.1(b) (providing that the FTC’s safeguards rule “applies to all customer information h information to you”)

--- page 64 ---

--- page 65 ---

--- page 66 ---

--- page 67 ---

--- page 68 ---

--- page 69 ---

--- page 70 ---

--- page 71 ---

--- page 72 ---

--- page 73 ---

--- page 74 ---

--- page 75 ---

--- page 76 ---

--- page 77 ---

--- page 78 ---

--- page 79 ---

--- page 80 ---

--- page 81 ---

--- page 82 ---

--- page 83 ---

--- page 84 ---

--- page 85 ---issuers the official record of ownership of such issuer’s securities; (ii) cancel old certificates, and other detailed and individualized information related to the transfer agents’ recordkeeping

Exchange Act Release No. 76743 (Dec. 22, 2015) [80 FR 81948, 81949 (Dec. 31, 2015)] (“2015 ”).

account for this, the proposed definition of “customer information” with respect to a transfer

“ nonpublic personal information...

Currently, the disposal rule only applies to those transfer agents “registered with the Commission.”

proposed definition of a “covered institution” as “a transfer agent registered with the ate regulatory agency.”

ection 216 of the FACT Act was to “prevent unauthorized disclosure of information contained

ud or related crimes, including identity theft.” that covered entities’ consumers would

indicated that the disposal rule as proposed would impose “minimal costs” on firms in the form

under the disposal rule through the taking of “reasonable measures” to protect against

“minimize the burden of compliance for smaller entities.”

FR 56304 (Sept. 20, 2004)] (“2004 Proposing Release”), at 56308.

“residual jurisdiction” under the same congressional mandate, to enact both

registered, the Commission “is empowered with broad rulemaking authority over all a transfer agent’s activities as a transfer agent.”

(d)(1) (providing that “n as ... transfer agent such rules and regulations” as the Commission may prescribe); Exchange Act (providing that “Nothing in the preceding imit ... the Commission’s der.”).

Commission’s experience administering the transfer agent examination program, we are aware

A transfer agent’s failure to account for such risks and take appropriate steps to

found on the systems they maintain will help prevent securityholders’ customer information from

We use the term “paying agent services” here to refer to administrative, recordkeeping, and

definition of “customer information” appropriate with

of “customer information”

Notice

Dealer Release”).

dealers from the rule’s scope noting its belief that Congress did not intend for the Commission’s FACT Act rules to apply to entities subject to primary oversight by

and the disposal rule. First, the proposed rule would define a “covered institution” to include “any broker or dealer,” without excluding notice

P’s disposal rule (currently rule 248.30(b)).

at n.23 (stating “

”);

.”).

page 97 ---

P’s substituted compliance provisions would still apply to notice

also employ this proposed definition of a “covered institution ” it would retain the disposal rule’s

the CFTC’s financial privacy rules, the Commission believes the benefits and

page 98 ---

alter the scope of either rule’s application to notice

institution’s

tain investment companies, such as some employees’ securities

page 99 ---

covered institution’s periodic

(“proper disposal policies and procedures are enc

”)

page 100 ---

informing them about the institution’s privacy policies.

informing them about the institution’s privacy policies.

Fixing America’s Surface Transportation (“FAST ”)

new section 503(f) to GLBA (“statutory exception”).

“consumer” as “

P, an institution’s customer is a “consumer” that has a

” 17 CFR 248.3(g).

page 104 ---

the requirement to provide customers an opportunity to opt out of the institution’s information

the words “Except as provided by paragraph (e) of this section ....”

page 105 ---

’s policies

he institution’s most recent privacy notice sent to customers. We are not

the notice to describe the customer’s right to opt out of the

requiring an institution’s privacy notice to include any

institution’s affiliates and do not affect whether the statutory exception is satisfied 603(d)(2)(iii) (excluding from the term “consumer report” communication of other

the Fixing America’s Surface Transportation Act, 83 FR 63450 (Dec. 10, 2018), at n.17; CFPB,

page 106 ---

notice to an individual who becomes the institution’s customer no later than when it

“ annually”

page 107 ---

institution’s change in policies or practices. tion’s change in policies or practices does not

page 108 ---

-

page 109 ---

collectively, “departing personnel”)

he shared information could not include any customer’s account number, Social

page 110 ---

from this proposal’s notice and opt out requirements

opriate in light of the GLBA’s goals? If so, is

page 111 ---

“cybersecurity risk” as “an effect of uncertainty on or within information and technology.”

page 112 ---

alternative trading systems (“ “)

and surrounding text as to the meaning of “covered institution.”

An “SCI Entity” is currently defined to include

page 113 ---

“SCI entity”

based trading threshold in national market system (“NMS”) stocks, exchange

17 CFR 242.1000 (defining the terms “SCI alternative trading system,” “SCI self system,” and “Exempt clearing agency subject to ARP,” and including all of those defined terms in the definition of “SCI ties”)

page 114 ---

P’s requirements apply to all br dealers, except for “notice dealers” (as defined in 17 CFR 248.30), who in most cases will be deemed to be in

P’s obligations.

. of this release, the term “broker dealer”

the Commission (“registered transfer agents”) (but not transfer agents registered with another P’s disposal rule.

ntity’s policies and

page 115 ---

the policies and procedures required by Regulation SCI focus on the SCI entities’

page 116 ---

-

page 117 ---

the Commission (“registered transfer agents”) (but not transfer agents registered with another P’s disposal rule.

ntity’s policies and

page 118 ---

-P currently defines the term “disposal” to mean: (1) the Regulation SCI’s obligation to take corrective action ma

Covered Entity’s

and remediate any cybersecurity threats and vulnerabilities with respect to the Covered Entity’s

, a Covered Entity’s policies and procedures would

ntity’s information systems and the information residing

To the extent an entity’s policies and procedures under the Exchange Act Cybersecurity Proposal

’s risk

Covered Entity’s policies and

need to require periodic assessments of cybersecurity risks associated with the Covered Entity’s

Entity’s information systems and any of the Covered Entity’s information residing on those

riity risks associated with the Covered Entity’s use of these

, a Covered Entity’s policies and

Covered Entity’s information, or are otherwise permitted to access the Covered Entity’s

to protect the Covered Entity’s information systems and information residing on those systems.

P’s proposed policy

y’s policies and

behavior for individuals authorized to access the Covered Entity’s information systems and the

, a Covered Entity’s policies and include measures designed to protect the Covered Entity’s information

based on a periodic assessment of the Covered Entity’s information systems and the information

--- page 125 ---

formation to the Covered Entity’s business operations;

--- page 126 ---

-

--- page 127 ---

would, if it experiences a “significant cybersecurity incident,” be required to

entity’s business and operations and how the covered entity assesses, prioritizes, and addresses

--- page 128 ---

summary description of the incident via EDGAR and the entity’s business

Covered Entity’s exposure to materia

a way for market participants to evaluate the Covered Entity’s cybersecurity risks and

--- page 129 ---

dealer, with information they can use to evaluate the event’s impact on their trading and

--- page 130 ---

and business development companies (“covered IM entities”)

--- page 131 ---

confidentiality, integrity, or availability of an adviser or fund’s information or information

impact on the adviser’s clients or on the adviser’s ability to provide investment advisory services

--- page 132 ---

such persons’

--- page 133 ---

-

--- page 134 ---

-

--- page 135 ---

<table>
  <tr>
    <td></td>
    <td></td>
  </tr>
  <tr>
    <td></td>
    <td></td>
  </tr>
</table>

--- page 136 ---

"smaller " for this purpose?

--- page 137 ---

As discussed above, “customers” includes not only custo the possession of covered institutions. In addition, with respect to a transfer agent, “customers” refers to “

--- page 138 ---

covered records to “customer information” and extending the covered population

--- page 139 ---

notices improve customers’ ability to take

--- page 140 ---

defining “sensitive customer information” more broadly than the

Throughout this economic analysis, “compliance costs” refers to the direct costs that borne in order to avoid violating the Commission’s rules.

costs” excludes costs that are not require Commission’s rules ( As used here, “compliance

--- page 141 ---

customers’ customers, and that both these effects would improve customers’ ability to act to protect their customers’ sensitive information.

--- page 142 ---

’ ability to compete with t

In a perfectly competitive market, market forces would lead firms to “efficiently”

--- page 143 ---

information about the firm’s product or service

customers’ (current

covered institutions’

economic texts, this “efficient” safeguarding of customer information would correspond to

Here, “adequate safeguards” can be thought of as the level of safeguards in a world where the level of firms’ efforts (and the costs of these

Press release, U.S. Fed. Trade Comm’n,

--- page 144 ---

, “underspend”)

covered institution’

and in so doing influence firms’ efforts toward protecting customer information.

enhance firms’

“underspending” on cybersecurity.

(Mar. 2020) (“IIF/McKinsey Report”),

In the case of transfer agents such effects would be mediated through firms’ choice of transfer prefer to avoid employing the services of transfer agents that allow their investors’ information to

(“ ”)

--- page 145 ---

,

competitive “race to the bottom.”

by the proposed amendments (“covered institutions”

The “bottom” in such a race is a level of cybersecurity spending that is too low from an efficiency

--- page 146 ---

1

--- page 147 ---

“underspending” on cybersecurity

(stating 58% of surveyed banks’ Chief Risk Officers cite “inability to manage cybersecurity risk” as the top strategic risk); s Public cloud security ‘just barely adequate,’ experts say,

providers “should be doing more on security.”)

--- page 148 ---

regulations that affect covered institutions’ effort toward safeguarding customers’ information.

Annual Report”),

Annual Report (Jan. 2022) (“ITRC Data Breach (“IBM Cost of Data Breach Report”),

--- page 149 ---

regulations aimed at increasing firms’ efforts toward safeguarding customer information reduce

“personal information” of a state’s resident is either accessed or acquired in an unauthorized

number, driver’s license number

information. “States” in this discussion includes the 50 U.S. states and the District of Columbia,

--- page 150 ---

certain harms (“ harm exception”).

commonly include: “harm” generally (12), identity theft or other fraud (10), misuse of personal

harms referenced in states’

3501, (defining “personal information” to include credit card

551 (defining “personal information” to include an individual’smade “without unreasonable delay,” or “in the most expedient time possible and without unreasonable delay”).

“ not later than 30 days after the date of determination that the breach occurred”

1798.82(a) (disclosure to be made “in the most expedient time possible and without unreasonable delay” but allowing for needs of law enforcement and

716 (notice to be made “in the most expedient time possible

integrity of the computerized data system”); Fla. Stat. 501.171(4)(a) (notice to be made “as ly as practicable and without unreasonable delay ... but no later than 30 days after the determination of a breach” unless delayed at the request of law enforcement or waived pursuant to the state’s no

[68 FR 74714 (Dec. 24, 2003)], at n.22 (“Compliance Program Release”) ID applies to “financial institutions” or “creditors” that offer or maintain “covered accounts.” 2013)] (“

Some covered institutions may also be subject to other regulators’ rules implicating

cies’ Incident Response Guidance.

Agencies’ guidelines require covered financial institutions to develop a response program

sensitive customer information “has occurred or is reasonably possible ”

notices to occur “as soon as possible ” but permit delays if “an appropriate law

” Under the guidelines, “sensitive customer information” means “a customer’s name, address, or

customer’s ecuirty number, driver’s license number, account number, credit or debit card

customer’s account.” ddition “any combination of components of customer information

that would allow someone to log onto or access the customer’s account, such as user name and

Banking Agencies’ Incident Response Guidance

Commission’s recently amended Standards for Safeguarding Customer Information (“ Safeguards Rule”) that contains a number of modifications to the existing rule with respect to

fecting customers’ securities transactions, providing

holding customers’ funds and securities; (4) handling clearance and settlement of trades; (5)

Such information would include the customers’ names, tax numbers, telephone numbers, broker,

dealers are not “carrying broker dealers” and therefore do not report the numbers of customer

of clients’

Here, “custody” means “holding, directly or i authority to obtain possession of them.” An adviser also has “custody” if “a related person holds, n connection with advisory services [the adviser] provide[s] to clients.”

a “ ng”

# Advisers

# States

companies (‘‘  ’’) Unit Investment Trusts (‘‘  ’’) entities’ companies

Because they are not operating companies, investment companies do not have ‘‘customers’’ as such, and thus are unlikely to possess significant amounts of nonpublic ‘‘customer’’ information

employees’ securities companies

the investment companies that would be subject to the proposed rules are part of a ‘‘family’’ of

As used here, ‘‘family’’ refers to a set of funds reporting the same family investment company

changes of ownership (“transfers”), communicat

registered securities are held in “street name” where the ultimate ownership

Rather the individual’s broker maintains the records of the individual’s

transfers a transfer agent would need to provide a customer’s identification information in the

—to other transfer agents (“service companies”).

” institutions’ ’ core functions would generally offering more “traditional” “otherwise [] permitted access to customer information” reliance on third parties for

ed institutions to “develop, implement safeguards for the protection of customer information” “designed to detect, respond to, and recover from unauthorized access to or use of customer

institutions’ response programs

or example, NIST’s Computer Security

Similar analogues are found in other reports, recommendations, and other regulators’

improvements to covered institutions’ processe

process for handling them is unlikely to be routine for a covered institution’s covered institution’s

institutions’ with the proposed rule’s requirements For example, the Banking Agencies’ Guidance states that covered institutions that are king Agencies’ geographic catering and that these entities will all have a “national presence ”

customers’ perceptions of the firm). Thus, the costs of

“Cybersecurity Incident Response and Recovery” element of the policies and procedure required

covered institutions’ customers—

proposed amendments would require that a covered institution’s incident response

“service provider” is defined broadly, as “

institution.”

to facilitate covered institutions’ compliance with the proposed requirements.

institutions’ compliance with the proposed amendments.

critical function likely “ processes, or otherwise is permitted access to customer information”

d institutions’ compliance, but may be unwilling to enter into suitable

address “generic” vulnerabilities that apply to all customers ( mitigate vulnerabilities “specific” to a given customer ( Smaller, “upstart” service providers may be more willing to provide unrealistic contractual

The “strength” of a data breach laws generally applicable to compromises of their residents’ information.

each customer’s state of residence, with the

provisions to the overall “strength”

“strength” of individualextends to “all customer information in the possession of a covered institution, institutions and has been provided to the covered institution.”

s from the covered institution’s “core” customer account management systems

These “GLBA Safe Harbors”

1

in the most

notification deadlines should increase customers’ ability to take effective

state statute requires notice be given “without unreasonable delay, and no more than thirty system” RCW 19.255.010(8).

Days to Identify Breach

data from the Washington Attorney General’s Office for 2021, “containment” of data breaches it takes an average of 75 days to “contain” ccording to IBM’s study for 2021, of “containment ” raising the attack’s

, “sensitive customer information” is defined

—cases where the “sensitive customer information” be problematic if they reduce customers’ sensitivity to data breach notices. In addition,

“sensitive customer information” is defined as “any component of

” ’s basis in “any compon customer information”

mother’s maiden name,

a customer’s name together with one or

a driver’s license number, or a

a covered institution’s compromise of the customer’s

linked with the customer’s name) can trigger the not

customer’s email address in combination with a security question and answer would only trigger

moreover, the compromise of information such as a customer’s name, combined with her

increase customers’ ability to take actions to mit

Under the proposal, the access or use without authorization of an individual’s sensitive

Currently, 21 states’ notification laws do

ed recordkeeping requirements would help facilitate the Commission’s

We distinguish here between the theoretical “baseline” in which the self of the statute have not come into effect and the current “status quo” (in which they have).

of covered institutions’ response to incidents,

’ service providers, the overall

obtain “reasonable assurances”

Under this alternative we would use the proposal’s “service provider ” institution.”

“maintain” computerized data containing private information

d institutions’ compliance with the proposed

proposal’s requirement for written contracts, we expect that “reasonable assurances” would

to document the “reasonable assurances,”

red to “reasonable assurances,” a written contract is clearer,

critical function likely “

processes, or otherwise is permitted access to customer information”

the “possible misuse” of sensitive customer information (rather than the proposed

Additionally, the service provider’s standard terms and conditions might in some

customers’

proposed, notification is triggered by the “reasonable likelihood” that sensitive

an express safe harbor may not be as protective as the proposal’s

“a reasonably likely risk of substantial harm or incon

Here, “secure procedures” refers to the secure implementation of encryption algorithms and

credentials belonging to LastPass’ customers was exfil

attempts to decrypt the passwords by guessing a customer’s

customers’

attacker’s location, identity

enhance law enforcement’s

Banking Agencies’ Inci

investigators may “avoid tipping off the adversary that their presence in the network has been discovered”).

law enforcement’s knowledge of attackers’ recovery of criminals’ ill

contain “ ” Paperwork Reduction Act of 1995 (“PRA”).

(“OMB”) for review in accordance with the PRA.

0610, the title of which is, “Rule 248.30, Procedures ion; disposal of consumer report information.”

P’s notice and opt

— 3 —

Q; and data on employees’ securities companies

The Commission’s estimates of the relevant wage rates are based on

The Commission’s estimates of the relevant wage rates for external time costs, such

covered institution’s

accuracy of the Commission’s estimate of the burden of the proposed collection of information;

(RFA")

Analysis (“IRFA”) that describes the impact of the proposed rule on small entities, unless the

enhance the protection of customers’ nonpublic personal

by applying the protections of both rules to “customer information ”

P’s annual

Improve covered institutions’

that a covered institution’s response program include policies and procedures

organization (collectively, “small entity”) for purposes

P’s annual privacy notice delive

ce a fraud alert in the individual’s credit reports to put the individual’s sion’s website address where individuals may obtain government

P’s annual privacy notice delivery provisions

records covered by the rule, and an institution’s

Banking Agencies’ Incident Response Guidance

Agencies’ Incident Response Guidance

overlap or conflict with the Banking Agencies’ Incident Response Guidanc

ubpart C, (requiring financial institutions subject to the Commission’s jurisdiction

protections for these entities’ customers and compro

overlap or conflict with the Banking Agencies’ Incident Response Guidance(SBREFA’’), the Commission must advise OMB whether a proposed regulation considered “major” rule. Under SBREFA, a rule is “major” where, if adopted, it results in or is

We request comment on whether our proposal would be a “major rule” for purposes of

by, in paragraph (b), replacing the words “ ” with “ ”; and replacing the words “Federal Trade Commission’s” with “Consumer Financial Protection Bureau’s.”

unable to identify which specific individuals’ sensitive customer informati

individual’

(“ARA”)

institution’s operations.

combination with similar information that could be used to gain access to the customer’s account

,

In paragraph (a)(7), removing the period at the end of paragraph and adding “; and” in