2022-01-01 SEC Press press_release 61 KB 1,986 chars

SEC Proposes Cybersecurity Risk Management Rules and Amendments for Registered Investment Advisers and Funds

Release
2022-20
summary

The Securities and Exchange Commission proposed new cybersecurity rules for registered investment advisers and funds to strengthen risk management and investor protection.

paragraph

The proposed rules would require entities to implement written cybersecurity policies, report significant cyber incidents confidentially to the SEC, and publicly disclose material cybersecurity risks and incidents. The proposal also introduces enhanced recordkeeping to support SEC oversight and enforcement. No specific dollar amounts or outcome are mentioned, as the rules aim to preemptively mitigate cyber threats that could harm investors and market integrity.

narrative

The Securities and Exchange Commission proposed new cybersecurity rules for registered investment advisers, funds, and business development companies to strengthen risk management and investor protection. The proposed rules would require entities to implement written cybersecurity policies, report significant cyber incidents confidentially to the SEC via a new form, and publicly disclose material cybersecurity risks and incidents in disclosures like brochures and registration statements. The proposal also introduces enhanced recordkeeping to support SEC oversight and enforcement. According to SEC Chair Gary Gensler, the proposed rules and amendments are designed to enhance cybersecurity preparedness and could improve investor confidence in the resiliency of advisers and funds against cybersecurity threats and attacks. The public comment period will remain open for 60 days after publication on SEC.gov or 30 days after Federal Register publication, whichever is longer. No specific dollar amounts or outcome are mentioned, as the rules aim to preemptively mitigate cyber threats that could harm investors and market integrity.

Enriched metadata

Scheme
cyber-fraud (80%)
Classified cyber-fraud(confidence 80%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
cyber risk relates to sec's three-part mission and goals of protecting investorssec chair gary genslerSecurities and Exchange Commission
Keywords
cybersecurityadvisers fundsadvisersrulesfundsregistered investmentseccybersecurity riskrisk managementrules amendmentsinvestment advisersproposed rulesrequire adviserscybersecurity incidentsinvestment

Exhibits & Attached Documents (2)

Extracted insights

Entities 3
  • agency cyber risk relates to sec's three-part mission and goals of protecting investors
  • agency sec chair gary gensler
  • agency Securities and Exchange Commission
Triples 7
  • SEC voted to propose rules related to cybersecurity risk management for registered investment advisers and funds
  • SEC Chair Gary Gensler said cyber risk relates to SEC's three-part mission and goals of protecting investors
  • Proposed rules would require advisers and funds to adopt written cybersecurity policies and procedures
  • Proposed rules would require advisers to report significant cybersecurity incidents to the Commission on confidential form
  • Proposal would require advisers and funds to publicly disclose cybersecurity risks and incidents in brochures and registration statements
  • Proposal would set forth new recordkeeping requirements for advisers and funds
  • Public comment period will remain open 60 days following SEC website publication or 30 days following Federal Register publication
Text layers
Extracted body text (1,986c)
The Securities and Exchange Commission today voted to propose rules related to cybersecurity risk management for registered investment advisers, and registered investment companies and business development companies (funds), as well as amendments to certain rules that govern investment adviser and fund disclosures. "Cyber risk relates to each part of the SEC’s three-part mission, and in particular to our goals of protecting investors and maintaining orderly markets," said SEC Chair Gary Gensler. "The proposed rules and amendments are designed to enhance cybersecurity preparedness and could improve investor confidence in the resiliency of advisers and funds against cybersecurity threats and attacks." The proposed rules would require advisers and funds to adopt and implement written cybersecurity policies and procedures designed to address cybersecurity risks that could harm advisory clients and fund investors. The proposed rules also would require advisers to report significant cybersecurity incidents affecting the adviser or its fund or private fund clients to the Commission on a new confidential form. To further help protect investors in connection with cybersecurity incidents, the proposal would require advisers and funds to publicly disclose cybersecurity risks and significant cybersecurity incidents that occurred in the last two fiscal years in their brochures and registration statements. Additionally, the proposal would set forth new recordkeeping requirements for advisers and funds that are designed to improve the availability of cybersecurity-related information and help facilitate the Commission’s inspection and enforcement capabilities. The proposal will be published on SEC.gov and in the Federal Register. The public comment period will remain open for 60 days following the publication of the proposing release on the SEC’s website or 30 days following the publication of the proposing release in the Federal Register, whichever period is longer.
OCR text (1,986c · html-text · 99% conf)
The Securities and Exchange Commission today voted to propose rules related to cybersecurity risk management for registered investment advisers, and registered investment companies and business development companies (funds), as well as amendments to certain rules that govern investment adviser and fund disclosures. "Cyber risk relates to each part of the SEC’s three-part mission, and in particular to our goals of protecting investors and maintaining orderly markets," said SEC Chair Gary Gensler. "The proposed rules and amendments are designed to enhance cybersecurity preparedness and could improve investor confidence in the resiliency of advisers and funds against cybersecurity threats and attacks." The proposed rules would require advisers and funds to adopt and implement written cybersecurity policies and procedures designed to address cybersecurity risks that could harm advisory clients and fund investors. The proposed rules also would require advisers to report significant cybersecurity incidents affecting the adviser or its fund or private fund clients to the Commission on a new confidential form. To further help protect investors in connection with cybersecurity incidents, the proposal would require advisers and funds to publicly disclose cybersecurity risks and significant cybersecurity incidents that occurred in the last two fiscal years in their brochures and registration statements. Additionally, the proposal would set forth new recordkeeping requirements for advisers and funds that are designed to improve the availability of cybersecurity-related information and help facilitate the Commission’s inspection and enforcement capabilities. The proposal will be published on SEC.gov and in the Federal Register. The public comment period will remain open for 60 days following the publication of the proposing release on the SEC’s website or 30 days following the publication of the proposing release in the Federal Register, whichever period is longer.