2015-01-01 SEC Press press_release 62 KB 2,159 chars

SEC Alerts Investors, Industry on Cybersecurity

Release
2015-20
summary

The SEC released educational materials on cybersecurity best practices for financial firms and investors, with no fraud allegations, charges, or financial penalties, focusing instead on preventive guidance and risk mitigation.

paragraph

The SEC published a Risk Alert from OCIE summarizing observations from examinations of over 100 broker-dealers and investment advisers on cybersecurity preparedness, including policies, remote access, and third-party vendor risks. Simultaneously, the OIEA issued an Investor Bulletin offering practical tips such as using strong passwords, enabling two-step verification, and avoiding public networks to protect online investment accounts. No fraud, enforcement actions, dollar amounts, or legal charges were involved—this was purely a preventive, educational initiative to enhance industry and investor resilience against cyber threats.

narrative

The Securities and Exchange Commission did not pursue any fraud enforcement actions but instead released two educational publications to strengthen cybersecurity across the financial sector. One, a Risk Alert from OCIE, compiled findings from examinations of more than 100 broker-dealers and investment advisers, highlighting common gaps in identifying risks, establishing policies, securing networks, and managing remote access and third-party vendors. The second, an Investor Bulletin from OIEA, provided actionable advice for individuals, including using strong passwords, enabling two-step verification, and avoiding public Wi-Fi for financial transactions. SEC Chair Mary Jo White and OCIE Director Andrew Bowden emphasized that cyber threats transcend boundaries and require coordinated efforts among regulators, industry, and the public. OIEA Director Lori Schock underscored the importance of investor vigilance as online account usage grows. The initiative was explicitly non-punitive, aiming to prevent future breaches rather than penalize past misconduct. No financial penalties, charges, or accused parties were identified, as the focus remained on awareness, preparedness, and collaborative risk reduction.

Enriched metadata

Scheme
non-corporate (100%)
Classified non-corporate(confidence 100%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
ocie director andrew bowdensec chair mary jo whitesec office of compliance inspections and examinationssec office of investor education and advocacySecurities and Exchange Commission
Keywords
investorscybersecurityinvestment accountssecinvestors industryonline investmentindustryinvestmentaccountsprotectonlineexaminationsalerts investorsindustry cybersecurityprotect online

Exhibits & Attached Documents (1)

Extracted insights

Entities 5
  • person ocie director andrew bowden
  • agency sec chair mary jo white
  • agency sec office of compliance inspections and examinations
  • agency sec office of investor education and advocacy
  • agency Securities and Exchange Commission
Triples 8
  • Securities And Exchange Commission released Publications On Cybersecurity At Brokerage And Advisory Firms
  • SEC Chair Mary Jo White stated Cybersecurity Threats Know No Boundaries
  • SEC engaged with Other Government Agencies, Industry, And Investing Public
  • SEC Office Of Compliance Inspections And Examinations released Risk Alert Based On Examinations Of More Than 100 Broker-Dealers And Investment Advisers
  • OCIE Director Andrew Bowden stated Examinations Assessed Cross-Section Of Industry To Inform Commission On Cybersecurity Preparedness
  • SEC Office Of Investor Education And Advocacy issued Investor Bulletin With Core Tips To Safeguard Online Investment Accounts
  • OIEA Director Lori J. Schock stated Bulletin Provides Everyday Investors With Tips To Protect From Cyber-Criminals And Online Fraud
  • Broker-Dealers And Investment Advisers examined for Cybersecurity Risk Identification, Policies, Procedures, Network Protection, And Unauthorized Activity Detection
Text layers
Extracted body text (2,159c)
The Securities and Exchange Commission today released publications that address cybersecurity at brokerage and advisory firms and provide suggestions to investors on ways to protect their online investment accounts. “Cybersecurity threats know no boundaries. That’s why assessing the readiness of market participants and providing investors with information on how to better protect their online investment accounts from cyber threats has been and will continue to be an important focus of the SEC,” said SEC Chair Mary Jo White. “Through our engagement with other government agencies as well as with the industry and educating the investing public, we can all work together to reduce the risk of cyber attacks.” One publication, a Risk Alert from the SEC’s Office of Compliance Inspections and Examinations (OCIE), contains observations based on examinations of more than 100 broker-dealers and investment advisers. The examinations focused on how these firms: Identify cybersecurity risks Establish cybersecurity policies, procedures, and oversight processes Protect their networks and information Identify and address risks associated with remote access to client information, funds transfer requests, and third-party vendors Detect unauthorized activity “Our examinations assessed a cross-section of the industry as a way to inform the Commission on the current state of cybersecurity preparedness,” said OCIE Director Andrew Bowden. “We hope that investors and industry participants will also benefit from what we have learned.” The second publication, an Investor Bulletin issued by the SEC’s Office of Investor Education and Advocacy (OIEA), provides core tips to help investors safeguard their online investment accounts, including: Pick a “strong” password Use two-step verification Exercise caution when using public networks and wireless connections “As investors increasingly use web-based investment accounts, it is critical that they take steps to safeguard those accounts,” said OIEA Director Lori J. Schock. “This bulletin provides everyday investors with a set of useful tips to help protect themselves from cyber-criminals and online fraud.”
OCR text (2,159c · plain-text · 99% conf)
The Securities and Exchange Commission today released publications that address cybersecurity at brokerage and advisory firms and provide suggestions to investors on ways to protect their online investment accounts. “Cybersecurity threats know no boundaries. That’s why assessing the readiness of market participants and providing investors with information on how to better protect their online investment accounts from cyber threats has been and will continue to be an important focus of the SEC,” said SEC Chair Mary Jo White. “Through our engagement with other government agencies as well as with the industry and educating the investing public, we can all work together to reduce the risk of cyber attacks.” One publication, a Risk Alert from the SEC’s Office of Compliance Inspections and Examinations (OCIE), contains observations based on examinations of more than 100 broker-dealers and investment advisers. The examinations focused on how these firms: Identify cybersecurity risks Establish cybersecurity policies, procedures, and oversight processes Protect their networks and information Identify and address risks associated with remote access to client information, funds transfer requests, and third-party vendors Detect unauthorized activity “Our examinations assessed a cross-section of the industry as a way to inform the Commission on the current state of cybersecurity preparedness,” said OCIE Director Andrew Bowden. “We hope that investors and industry participants will also benefit from what we have learned.” The second publication, an Investor Bulletin issued by the SEC’s Office of Investor Education and Advocacy (OIEA), provides core tips to help investors safeguard their online investment accounts, including: Pick a “strong” password Use two-step verification Exercise caution when using public networks and wireless connections “As investors increasingly use web-based investment accounts, it is critical that they take steps to safeguard those accounts,” said OIEA Director Lori J. Schock. “This bulletin provides everyday investors with a set of useful tips to help protect themselves from cyber-criminals and online fraud.”