Sponsored By

FINRA’s Cybersecurity Best PracticesFINRA’s Cybersecurity Best Practices

FINRA announces the latest best practices, including a wealth of cybersecurity suggestions for mobile devices.

Samuel Steinberger, Senior Technology Editor

December 25, 2018

3 Min Read
Wealth Management logo in a gray background | Wealth Management

Updating its 2015 report, the Financial Industry Regulatory Authority released a cybersecurity report outlining prudent security measures for advisors interested in shoring up their cybersecurity protocols. The report covers controls in branch offices, methods of mitigating phishing attacks, how to identify and counteract insider threats, how to build a strong penetration-testing program and, perhaps most timely, how to establish and maintain controls on mobile devices.

Observing the challenges some firms have in maintaining cybersecurity controls in branch locations, FINRA noted that branch autonomy can run in the face of consistent firm-wide security. After evaluating the need for cybersecurity enhancements, the organization suggested that firms take steps like implementing robust examination programs and formalizing oversight via Written Supervisory Procedures. Establishing asset inventories to outline the scope needing protection are also particularly useful.

The social engineering behind phishing attacks can make them particularly challenging to defend against. In some cases, merely recognizing the attack can be a challenge, so FINRA suggested including phishing scenarios in the firm-level risk assessment process. Effective policies also included: clarifying that users should not click on any links or open any attachments in suspected phishing emails; and developing a process to securely notify IT administrators and compliance staff of suspected phishing attempts. Wire transfers can pose particularly disastrous consequences, so the authority suggested confirming all requests for wire transfers with the customer via telephone or in person.

Insider threats present a unique situation to cybersecurity measures, noted FINRA, because insiders tend to bypass firm controls, which can cause significant material harm, using both sensitive customer and firm data. Overarching, risk-based insider threat programs tend to implement identity and access management policies and technical controls, including heightened controls for individuals with privileged access. Some firms have even included measures to identify potentially abnormal user behavior in the firm’s network, which the organization noted has been effective at mitigating insider threats. Data loss prevention protocols, like multi-factor authentication, are also used in the more robust cybersecurity environments.

Penetration testing, or simulating an attack on a firm’s internally or externally facing computer network, is a powerful way of bolstering a firm’s cyber defenses. Firms should adopt a risk-based approach to penetration testing and thoroughly vet their testing vendors, suggested FINRA. Because test results are only as good as the manner in which they’re measured, using a variety of testing providers and managing test results are effective ways for maximizing testing.

As computing becomes more dispersed and mobile devices are more commonplace, cyber risks associated with mobile devices are rising, observed FINRA. There are a number of ways to safeguard devices, however. Firms can require all personal devices to maintain a separate, secure, encrypted mobile device management application for firm activities, such as sending emails and scheduling events, the authority suggested. It’s also hard to respond to unknown threats, so including reviews of mobile device security controls in branch office audits and inspections, including for remote employees and branch office staff, can be an effective security procedure, FINRA noted.

“There is no one-size-fits-all approach to cybersecurity,” observed Steven Polansky, senior director of member supervision in the organization’s Washington, D.C. office. The latest FINRA report can help firms “determine the right set of practices for their individual business,” he added.

About the Author

Samuel Steinberger

Senior Technology Editor, WealthManagement.com

Samuel Steinberger is Senior Technology Editor for Informa Connect’s WealthManagement.com. In his role, Mr. Steinberger provides the publication’s wealth and financial technology coverage. 

Mr. Steinberger’s editorial insight and familiarity with technology accelerates Informa’s growth within the financial advisor and wealth management communities, providing in-depth news for advisors and financial professionals. 

Before joining Informa Connect, Mr. Steinberger produced documentaries with former CNN anchor Soledad O’Brien at Soledad O’Brien Productions (formerly Starfish Media Group). He specialized in research, shooting and editing, as well as finding distinct voices to explain topics like mental health, poverty and racial divide. 

Prior to joining Soledad O’Brien Productions, Mr. Steinberger managed multi-departmental technology projects for global legal technology leader Transperfect Legal Solutions. After obtaining his graduate degree in journalism from Columbia University, he completed his transition from technology management to media. 

Mr. Steinberger is an award-winning journalist, author and researcher who has written, edited and reported for a number of publications, including The New York Times, Financial PlanningAmerican Banker and PBS. He is founder of beverages publication Give Me Weird Drinks

Mr. Steinberger’s technology analysis and insight has been featured in several books on virtual and augmented reality. Mr. Steinberger has received awards and recognition for his reporting and research, including the American Business Media's prestigious Jesse H. Neal Award for editorial excellence.

Follow on Twitter: @slsteinberger