Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer
Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer, No. 1:17-cv-06305 (Mar. 15, 2023)
The SEC proposed amendments to Regulation S-P requiring broker-dealers, investment advisers, investment companies, and transfer agents to implement written incident response programs, notify customers within 30 days of breaches involving sensitive personal information, and enforce stricter safeguards and service provider obligations to combat cyber threats and align with GLBA.
The SEC proposed sweeping updates to Regulation S-P to mandate written incident response programs for broker-dealers, registered investment advisers, investment companies, and transfer agents, requiring notification to affected individuals within 30 days of unauthorized access to sensitive customer information such as Social Security numbers or biometric data. The rule expands safeguards and disposal requirements to cover all nonpublic personal information regardless of source, imposes 48-hour breach reporting obligations on service providers, and mandates detailed notice content including protective steps and FTC resources. While estimating $465.7 million in aggregate compliance costs, the SEC rejected exemptions and aligned annual privacy notice rules with a statutory GLBA exception to reduce administrative burdens.
The Securities and Exchange Commission proposed comprehensive amendments to Regulation S-P under the Gramm-Leach-Bliley Act to strengthen cybersecurity protections for broker-dealers, investment companies, registered investment advisers, and—newly—transfer agents. These amendments require all covered entities to adopt written incident response programs that mandate notification to affected customers within 30 days of discovering unauthorized access to sensitive customer information, including Social Security numbers, biometric data, or other identifiers capable of causing substantial harm, unless a reasonable investigation concludes no such harm is likely. The proposal broadens the scope of safeguarding and disposal requirements to encompass all nonpublic personal information, regardless of format or source, and extends contractual security obligations to third-party service providers, who must report breaches to their clients within 48 hours. Notice to affected individuals must include specific details about the incident and guidance on protective steps, such as credit monitoring and FTC resources. The SEC also introduced new recordkeeping mandates to document compliance and streamlined annual privacy notice delivery by aligning it with a statutory exception under GLBA. Designed to address rising cyber threats, inconsistent state laws, and systemic risks from remote work and third-party vendors, the rule rejects exemptions and estimates aggregate compliance costs of $465.7 million and 1.1 million hours across the industry.
Extracted insights
- person susan poklemba ×2
- person Aaron Ellias
- person Brice Prince
- person Devin Ryan
- person edward schellhorn
- person emily westerberg russell
- person James Wintering
- person Jessica Leonardo
- person john fahey
- person marc mehrespand
- agency Securities and Exchange Commission
- person Taylor Evenson
- person thoreau bartmann
- Securities and Exchange Commission is proposing rule amendments that would require broker-dealers, investment companies, and registered investment advisers to adopt written policies and procedures for incident response programs
- Commission will post all comments on the Commission’s website
- Comments should be received on or before June 5, 2023
- Susan Poklemba is listed as contact for further information
- Proposed amendments extend the application of the safeguards provisions to transfer agents
advisers”)
(“Commission” or “SEC”)
brokers and dealers (or “ ”)
registered with the Commission (“registered investment
Use the Commission’s internet comment form
post all comments on the Commission’s website (http://ww Comments are also available for website viewing and printing in the Commission’s Public
conditions may limit access to the Commission’s
lable on the Commission’s website. To ensure direct
Chief Counsel’s Office
the Code of Federal Regulations (“CFR”).
1
1
’s provisions include
(b) (“disposal rule”), which
to obtain, share, and maintain individuals’
] (“Reg. S Release”). Regulation S
Similarly, employees’ securities companies –
.” The term “covered institutions referred to as “you” in Regulation S
apply, are sometimes referred to as “covered ” is sometimes used in this release to refer to
FBI’s Internet Crime Complaint Center received 847,376 complaints in 2021
the Financial Industry Regulatory Authority (“ “) 2021 Report on FINRA’s
Examinations) (“EXAMS”),
(Apr. 16, 2019) (“Reg. S
Alert”),
(Observations Risk Alert”)
organization (“SRO”) rules requiring written supervisory procedures and written business
an institution’s preparedness and the
States also differ regarding a firm’s duty to investigate a data breach when
BA’s requirements for standards for safeguarding customer records and information
California residents of a data breach generally required when a resident’s personal information was or is reasonably believed to have been acquired by an unauthorized person; “pe ” is defined to mean an individual’s first or last name in combination with one of a list
likely to cause substantial harm to the resident to whom the information relates; “sensitive fying information” is defined as the resident’s first or last name in combination
As a result, a firm’s notific
defining “sensitive customer information” more broadly than the current definitions used by at
requirements of the entity’s “primary federal regulator.”
customers’ information
that financial institution’s
among other things, “
6801(b)(3) (emphasis added). We agree with the Federal Trade Commission (“FTC”) that pertaining to another institution’s customers is consistent with the purp
definition of “customer information” that would include both nonpublic personal information that
17 CFR 248.3(g)(2)(iii) (“An individual
dealer’s consumers in order to clear transactions.”).
nfidentiality of customers’ personal information.
unless otherwise noted, we refer to them collectively as “transfer agents” for
term “customer records and information” defined as “
ursuant to the Fair and Accurate Credit Transactions Act of 2003 (“FACT Act”),
“Consumer report information”
information”)
fining “customer records or information”)
(“Disposal Rule Adopting Release”). Section “requiring” but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ anddealer’s
(Mar. 13, 2008)] (“2008 Proposal”). The amendments to Regulation S dealer’s designated examining au ble financial responsibility rules (including the Commission’s customer applicable to “ which would have been defined report information” that is
suggested modifying the proposed amendments’ information security
Letter” Letter”
regulators’ ’s safeguards rule. The
financial institutions under the FTC’s GLBA jurisdiction to establish a written incident response
Information, 86 FR 70272 (Dec. 9, 2021) (“FTC Safeguards Release”). As amended, the FTC’s rule requires that a response plan address security events materially affecting the confidentiality, integrity, or availability of customer information in the financial institution’s an institution’s independent obligation to perform notification as required by state law. Union Administration (“NCUA”)
(Mar. 29, 2005) (“Banking Agencies’ Incident Response Guidance”). The Banking Agencies’ Incident Response Guidance provides,
protection of customers’ nonpublic personal information. These proposed amendments would
applying the protections of both rules to “customer information,” a newly defined term. We also
for the definition of “sensitive customer information.”
13524 (Mar. 9, 2022)] (“Investment Management Cybersecurity Proposal”); Cybersecurity Proposal” ) ( “Corporation Finance ( “Exchange ”) and , 2023), (“Regulation SCI Proposal”)
of a customer’s nonpublic personal
with approximately 330,000 different households, by accessing two of the firm’s portals. The (“PII”) such as customers’ full
92806 (Aug. 30, 2021) (“Cambridge Order”),
third parties resulting in the exposure of at least 2,177 customers’ PII stored i email accounts and potential exposure of another 3,800 customers’ PII); Commission Order
omers’ PII stored in the compromised email
92807 (Aug. 30, 2021) (“KMS Order”),
for example, phishing or credential stuffing. “Phishing” is “spoofed” email to trick a victim into taking action, such as downloading malicious software or website for the system or service, while “credential stuffing” is a means of gaining unauthorized
taking over a customer’s acc to obtain unauthorized entry to a customer’s online brokerag without the customer’s ’s
The “dark web” is a part of the internet that requires specialized software t specifically designed to facilitate anonymity by obscuring users’ identities, including by hiding users’ internet protocol addresses. The anonymity provided by the dark web has allowed users to
institution’s
and unauthorized trading scheme with at least one other person. The SEC’s complaint alleged
the unauthorized trading of stock in the victims’ accounts.
rule refer to “ “use.” ”, the word “ ” modifies both “access” and information.” for a discussion of “customer
avoid inadequate responses based on a covered institution’s
amendments would require that a covered institution’s
for the definition of “sensitive customer information ”
, which includes a discussion of “sensitive customer information.”
a covered institution’s
)(3)(i). The term “customer information systems” would mean the support the covered institution’s operations.
rules would be applicable to “Market Entities” s (collectively, “Covered Entities”) as well as broker “fund information system” and “fund information.”
the Market Entities’ institutions’ policies the proposed rule’s requirement that
.
a covered institution’s
the proposed rule’s requirements
the covered institutions’
For example, a bad actor could use a service provider’s access to a covered institution’s systems to infiltrate the covered institution’s network through a
(“Adviser Outsourcing Proposal”); FINRA Notice to
NIST defines a “cybersecurity compromise in the supply chain” as “an occurrence within the
and thereby gain unauthorized access to the covered institution’s customer
we propose to define the term “service provider” to
institution’s
anywhere during the life cycle of the system, product or service.”
(Best Practices in Cyber Supply Chain Risk Management”)
was able to gain a foothold in Target’s network through a third
a bad actor breached the Target Corporation’s
A “Kill Chain” Analysis of the 2013
institution’s
could create a risk of substantial harm to the covered institution’s c
The proposed amendments would require that a covered institution’s incident response
the proposed definition of “service provider”?
we exclude a covered institution’s
“service provider” in this ruledefinitions of “service provider” that should be included in the definition of “service providers?”
institution’s customer information. Is
P’s opt
ID’s requirements
11, “service provider” investment adviser. In the proposal, a “covered function” would mean cause a material negative impact on the adviser’s clients or on the adviser’s requires financial institutions subject to the Commission’s jurisdiction with covered
Banking Agencies’ Incident Response Guidance
Banking Agencies’ Incident Response Guidance
Is “as” an
such as “as soon as practicable”?
A risk of harm provision under a particular state’s rules
Notification Laws, (“NCSL Security Breach Notification Law Resource”),
sufficiently clear? Is a standard of “reasonably likely” appropriate? Should the
“reasonably possible” which would suggest a more expansive standard than “likely”?
. Is this standard “not reasonably
” for rebutting the presumption to notify the appropriate standard?
Should the standard be “not reasonably possible”?
some states’ laws
” likely risk of substantial harm or inconvenience.” definition of “sensitive customer information.”
ould create a “reasonably notice requirements would be information pertaining to a covered institution’s customers and customer’s Social Security number may not
linked to the individual, would be sensitive because they have been used in “Social Security only” or “synthetic” identity theft. In this type of identity theft, a Social Security create a new (or “synthetic”) identity, which then may allow the malicious actor to, among other information that can be used alone to authenticate an individual’s identity. A biometric record of
mother’s maiden name A mother’s maid
In this respect, our proposed definition is broader than the definition of “sensitive customer information” provided in the Banking Agencies’ Incident Response Guidance. That definition includes a customer’s name, address, or telephone number, only in conjunction with other pieces
Tapping “Synthetic Identity Fraud” to Commit
cipher text could be decrypted, it would also reduce the likelihood that the cipher text’s
definition of “sensitive customer
acquisition of certain “unencrypted, computerized data information,” and defining “encrypted” as data transformed “through the use of a one hundred twenty
confidential process or key” unless the data was “acquired in combination with any key, security data.”).
We request comment on the proposed rule’s definition of sensitive customer information
Should we broaden the proposed definition of “sensitive customer information” to
Agencies’ Incide
when linked would permit access to an individual’s accounts? Should the
ecurity number, driver’s license or other government identification number,
create a “reasonably likely” risk
For example, would a “reasonably foreseeable” standard
information the compromise of which “could” create a reasonably likely risk
customer information that “would” create such risk?
Should we provide additional or alternative examples of what constitutes “sensitive customer information” in the rule text?
Is encryption a relevant factor to a covered institution’s determination of the
,
covered institution’s determination that cipher text’s
Should we except from the definition of “sensitive customer information” encrypted
Definition of “Substantial Harm or Inconvenience”
We propose to define “substantial harm or inconvenience” to mean “personal injury, or
,” and provide
P requires a covered institution’s
malicious actor’s
,
Congress’s goal
We request comment on the proposed rule’s definition of substantial harm or
proposed definition of “substantial harm or inconvenience”?
other than “substantial” and “more than trivial” in describing the types of harms that
Is “more
“the policy of the Congress that each financial institution
the security and confidentiality of these customers’ nonpublic personal information.”
“more than trivial” the appropriate standard?
“immaterial” or “ significant”?
a numerical or other objective standard for “ substantial” harm or
Should a harm that is a “ personal injury,” such as phys
“trivial,” similar to our proposed treatment of
Should the standard for a harm that is a “ personal injury” be something other than “ trivial?”
notwithstanding a covered institution’s determination to
which specific individuals’ data
identify which specific individuals’ sensitive customer information has been accessed or used
. Accordingly, proposed rule 248.30(b)(3)(iii) and (b)(4)(i) refers to “affected individuals without authorization” rather than “customer.” This is because the term “customer” is defined in section 248.3(j) as “a consumer that has a customer relationship with the [covered] institution,”
institutions provide notices “as soon as practicable”
identity theft or other harm. The amount of time that would constitute “as soon as practicable” may vary based on several factors,
“as soon as practicable”The proposal’s as practicable.”
provide notices to affected customers “as soon
institution’s timely and uniform customer notification that customers’ sensitive customer information has
We request comment on the proposed rule’s notification timing requirements
Should the rule require institutions to provide notice “as soon as possible ”
Should the rule provide parameters to define “as soon as practicable,” “as soon as possible ” “as soon as reasonably practicable”
“becoming aware that unauthorized access to or use of customer information has
”?
for example, after the covered institution “reasonably should have
been aware” of the incident or, alternatively, after completing its assessment of the
the timing requirement should begin upon “becoming
” should we provide covered institutions
individuals may obtain “consumer reports” from consumer reporting we refer to “credit reports” in
Banking Agencies’ Incident Response Guidance notices include a recommendation that customers obtain “credit reports,” and in part, because we ” Consumer Financial Protection Bureau (“CFPB”),
and opt out notices) and 17 CFR 248.3(c)(1) (defining “clear and conspicuous”)
17 CFR 248.3(c)(2) (providing examples explaining what is meant by the terms “reasonably understandable” and “designed to call attention” ).
whether to provide certain information “as appropriate” on a case
“consumer reports” “credit reports” more familiar with the term “credit report”
of 45% of jobs involving teleworking “at least some of the time.”
“customer information,” a newly defined term
institution’s customers
defined “customer
” The Commission has “broad rulemaking authority” to effectuate “the policy of the Congress that information.” f these customers’ nonpublic personal
’s protect “customer records and information,” “consumer report information,” a
15 U.S.C. 6801(a) (“It is the policy of the Congress that each financial institution has an security and confidentiality of those customers’ nonpublic personal information.”) (emphasis
disposal of “consumer information, or any compilation of consumer information, derived from consumer reports for a business purpose.”
“consumer report information” about an individual “that is a consumer
report.” 17
“Consumer report”
the term “customer records and information” in the safeguards rule with term “customer information”
“customer information” to encompass any record containing “nonpublic personal information” about “a customer of a financial institution,” whether in paper,
GLBA, which focuses on protecting “nonpublic personal information” of those who are “customers” of financial institutions.
conform more closely to the definition of “customer information” in the safeguards rule adopted
to change the term “consumer report information” currently in Regulation S P to “consumer information” (without changing the definition) to conform to the term used by
Information Security Standards (“OCC Information Security Guidance”), at I.C. 2 to Part 208 (“FRB Information Security Guidance”), at I.C.2.b.
We propose a separate definition of “customer information” applicable to transfer agents.
16 CFR 314.2(d) (FTC safeguards rule defining “customer information” to mean “any record
“continuing obligation” to protect the security and confidentiality of customers’ nonpublic
FACT Act focuses on protecting “consumer information ”
eliminating an institution’s need to
rule more closely to the Banking Agencies’ Safeguards Guidance.
he Commission’s statutory mandate
or on behalf of you or your affiliates”). The proposed rules would not require covered institutions to be responsible for their affiliates’ policies and procedures for safeguarding customer
proposed rule 248.30(c)(1). “Customer information” is n
“customer information,” because the safeguards rule is adopted pursuant to the GLBA and therefore is limited to information about “customers.”
associations’ must develop, implement, and maintain appropriate measures to properly dispose of customer information and consumer information.”);
comment on the proposed definition of “ s’ Is the proposed definition of “customer information,” which includes nonpublic personal information about an institution’s own customers that
from a third party financial institution about that institution’s customers
P defines “customer” as “a consumer who has a customer relationship with you.” The
rule, therefore, only protects the “records and information” of individuals who are
d institution’s own
the custodian of a former client’s assets wou
individual’s c
The safeguards rule is applicable to “consumer information” only to the extent it overlaps with “customer information.”
P defines “financial institution” generally to mean any institution the business of
approach is consistent with the FTC’s
the scope? For example, should the rules’ protections for “customer information”
, an employee’s or former customer’s bank account
customers’ information that the covered institution
Should employees’ nonpublic personal information be
314.1(b) (providing that the FTC’s safeguards rule “applies to all customer information h information to you”)
--- page 64 ---
--- page 65 ---
--- page 66 ---
--- page 67 ---
--- page 68 ---
--- page 69 ---
--- page 70 ---
--- page 71 ---
--- page 72 ---
--- page 73 ---
--- page 74 ---
--- page 75 ---
--- page 76 ---
--- page 77 ---
--- page 78 ---
--- page 79 ---
--- page 80 ---
--- page 81 ---
--- page 82 ---
--- page 83 ---
--- page 84 ---
--- page 85 ---issuers the official record of ownership of such issuer’s securities; (ii) cancel old certificates, and other detailed and individualized information related to the transfer agents’ recordkeeping
Exchange Act Release No. 76743 (Dec. 22, 2015) [80 FR 81948, 81949 (Dec. 31, 2015)] (“2015 ”).
account for this, the proposed definition of “customer information” with respect to a transfer
“ nonpublic personal information...
Currently, the disposal rule only applies to those transfer agents “registered with the Commission.”
proposed definition of a “covered institution” as “a transfer agent registered with the ate regulatory agency.”
ection 216 of the FACT Act was to “prevent unauthorized disclosure of information contained
ud or related crimes, including identity theft.” that covered entities’ consumers would
indicated that the disposal rule as proposed would impose “minimal costs” on firms in the form
under the disposal rule through the taking of “reasonable measures” to protect against
“minimize the burden of compliance for smaller entities.”
FR 56304 (Sept. 20, 2004)] (“2004 Proposing Release”), at 56308.
“residual jurisdiction” under the same congressional mandate, to enact both
registered, the Commission “is empowered with broad rulemaking authority over all a transfer agent’s activities as a transfer agent.”
(d)(1) (providing that “n as ... transfer agent such rules and regulations” as the Commission may prescribe); Exchange Act (providing that “Nothing in the preceding imit ... the Commission’s der.”).
Commission’s experience administering the transfer agent examination program, we are aware
A transfer agent’s failure to account for such risks and take appropriate steps to
found on the systems they maintain will help prevent securityholders’ customer information from
We use the term “paying agent services” here to refer to administrative, recordkeeping, and
definition of “customer information” appropriate with
of “customer information”
Notice
Dealer Release”).
dealers from the rule’s scope noting its belief that Congress did not intend for the Commission’s FACT Act rules to apply to entities subject to primary oversight by
and the disposal rule. First, the proposed rule would define a “covered institution” to include “any broker or dealer,” without excluding notice
P’s disposal rule (currently rule 248.30(b)).
at n.23 (stating “
”);
.”).
page 97 ---
P’s substituted compliance provisions would still apply to notice
also employ this proposed definition of a “covered institution ” it would retain the disposal rule’s
the CFTC’s financial privacy rules, the Commission believes the benefits and
page 98 ---
alter the scope of either rule’s application to notice
institution’s
tain investment companies, such as some employees’ securities
page 99 ---
covered institution’s periodic
(“proper disposal policies and procedures are enc
”)
page 100 ---
informing them about the institution’s privacy policies.
informing them about the institution’s privacy policies.
Fixing America’s Surface Transportation (“FAST ”)
new section 503(f) to GLBA (“statutory exception”).
“consumer” as “
P, an institution’s customer is a “consumer” that has a
” 17 CFR 248.3(g).
page 104 ---
the requirement to provide customers an opportunity to opt out of the institution’s information
the words “Except as provided by paragraph (e) of this section ....”
page 105 ---
’s policies
he institution’s most recent privacy notice sent to customers. We are not
the notice to describe the customer’s right to opt out of the
requiring an institution’s privacy notice to include any
institution’s affiliates and do not affect whether the statutory exception is satisfied 603(d)(2)(iii) (excluding from the term “consumer report” communication of other
the Fixing America’s Surface Transportation Act, 83 FR 63450 (Dec. 10, 2018), at n.17; CFPB,
page 106 ---
notice to an individual who becomes the institution’s customer no later than when it
“ annually”
page 107 ---
institution’s change in policies or practices. tion’s change in policies or practices does not
page 108 ---
-
page 109 ---
collectively, “departing personnel”)
he shared information could not include any customer’s account number, Social
page 110 ---
from this proposal’s notice and opt out requirements
opriate in light of the GLBA’s goals? If so, is
page 111 ---
“cybersecurity risk” as “an effect of uncertainty on or within information and technology.”
page 112 ---
alternative trading systems (“ “)
and surrounding text as to the meaning of “covered institution.”
An “SCI Entity” is currently defined to include
page 113 ---
“SCI entity”
based trading threshold in national market system (“NMS”) stocks, exchange
17 CFR 242.1000 (defining the terms “SCI alternative trading system,” “SCI self system,” and “Exempt clearing agency subject to ARP,” and including all of those defined terms in the definition of “SCI ties”)
page 114 ---
P’s requirements apply to all br dealers, except for “notice dealers” (as defined in 17 CFR 248.30), who in most cases will be deemed to be in
P’s obligations.
. of this release, the term “broker dealer”
the Commission (“registered transfer agents”) (but not transfer agents registered with another P’s disposal rule.
ntity’s policies and
page 115 ---
the policies and procedures required by Regulation SCI focus on the SCI entities’
page 116 ---
-
page 117 ---
the Commission (“registered transfer agents”) (but not transfer agents registered with another P’s disposal rule.
ntity’s policies and
page 118 ---
-P currently defines the term “disposal” to mean: (1) the Regulation SCI’s obligation to take corrective action ma
Covered Entity’s
and remediate any cybersecurity threats and vulnerabilities with respect to the Covered Entity’s
, a Covered Entity’s policies and procedures would
ntity’s information systems and the information residing
To the extent an entity’s policies and procedures under the Exchange Act Cybersecurity Proposal
’s risk
Covered Entity’s policies and
need to require periodic assessments of cybersecurity risks associated with the Covered Entity’s
Entity’s information systems and any of the Covered Entity’s information residing on those
riity risks associated with the Covered Entity’s use of these
, a Covered Entity’s policies and
Covered Entity’s information, or are otherwise permitted to access the Covered Entity’s
to protect the Covered Entity’s information systems and information residing on those systems.
P’s proposed policy
y’s policies and
behavior for individuals authorized to access the Covered Entity’s information systems and the
, a Covered Entity’s policies and include measures designed to protect the Covered Entity’s information
based on a periodic assessment of the Covered Entity’s information systems and the information
--- page 125 ---
formation to the Covered Entity’s business operations;
--- page 126 ---
-
--- page 127 ---
would, if it experiences a “significant cybersecurity incident,” be required to
entity’s business and operations and how the covered entity assesses, prioritizes, and addresses
--- page 128 ---
summary description of the incident via EDGAR and the entity’s business
Covered Entity’s exposure to materia
a way for market participants to evaluate the Covered Entity’s cybersecurity risks and
--- page 129 ---
dealer, with information they can use to evaluate the event’s impact on their trading and
--- page 130 ---
and business development companies (“covered IM entities”)
--- page 131 ---
confidentiality, integrity, or availability of an adviser or fund’s information or information
impact on the adviser’s clients or on the adviser’s ability to provide investment advisory services
--- page 132 ---
such persons’
--- page 133 ---
-
--- page 134 ---
-
--- page 135 ---
<table>
<tr>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
</tr>
</table>
--- page 136 ---
"smaller " for this purpose?
--- page 137 ---
As discussed above, “customers” includes not only custo the possession of covered institutions. In addition, with respect to a transfer agent, “customers” refers to “
--- page 138 ---
covered records to “customer information” and extending the covered population
--- page 139 ---
notices improve customers’ ability to take
--- page 140 ---
defining “sensitive customer information” more broadly than the
Throughout this economic analysis, “compliance costs” refers to the direct costs that borne in order to avoid violating the Commission’s rules.
costs” excludes costs that are not require Commission’s rules ( As used here, “compliance
--- page 141 ---
customers’ customers, and that both these effects would improve customers’ ability to act to protect their customers’ sensitive information.
--- page 142 ---
’ ability to compete with t
In a perfectly competitive market, market forces would lead firms to “efficiently”
--- page 143 ---
information about the firm’s product or service
customers’ (current
covered institutions’
economic texts, this “efficient” safeguarding of customer information would correspond to
Here, “adequate safeguards” can be thought of as the level of safeguards in a world where the level of firms’ efforts (and the costs of these
Press release, U.S. Fed. Trade Comm’n,
--- page 144 ---
, “underspend”)
covered institution’
and in so doing influence firms’ efforts toward protecting customer information.
enhance firms’
“underspending” on cybersecurity.
(Mar. 2020) (“IIF/McKinsey Report”),
In the case of transfer agents such effects would be mediated through firms’ choice of transfer prefer to avoid employing the services of transfer agents that allow their investors’ information to
(“ ”)
--- page 145 ---
,
competitive “race to the bottom.”
by the proposed amendments (“covered institutions”
The “bottom” in such a race is a level of cybersecurity spending that is too low from an efficiency
--- page 146 ---
1
--- page 147 ---
“underspending” on cybersecurity
(stating 58% of surveyed banks’ Chief Risk Officers cite “inability to manage cybersecurity risk” as the top strategic risk); s Public cloud security ‘just barely adequate,’ experts say,
providers “should be doing more on security.”)
--- page 148 ---
regulations that affect covered institutions’ effort toward safeguarding customers’ information.
Annual Report”),
Annual Report (Jan. 2022) (“ITRC Data Breach (“IBM Cost of Data Breach Report”),
--- page 149 ---
regulations aimed at increasing firms’ efforts toward safeguarding customer information reduce
“personal information” of a state’s resident is either accessed or acquired in an unauthorized
number, driver’s license number
information. “States” in this discussion includes the 50 U.S. states and the District of Columbia,
--- page 150 ---
certain harms (“ harm exception”).
commonly include: “harm” generally (12), identity theft or other fraud (10), misuse of personal
harms referenced in states’
3501, (defining “personal information” to include credit card
551 (defining “personal information” to include an individual’smade “without unreasonable delay,” or “in the most expedient time possible and without unreasonable delay”).
“ not later than 30 days after the date of determination that the breach occurred”
1798.82(a) (disclosure to be made “in the most expedient time possible and without unreasonable delay” but allowing for needs of law enforcement and
716 (notice to be made “in the most expedient time possible
integrity of the computerized data system”); Fla. Stat. 501.171(4)(a) (notice to be made “as ly as practicable and without unreasonable delay ... but no later than 30 days after the determination of a breach” unless delayed at the request of law enforcement or waived pursuant to the state’s no
[68 FR 74714 (Dec. 24, 2003)], at n.22 (“Compliance Program Release”) ID applies to “financial institutions” or “creditors” that offer or maintain “covered accounts.” 2013)] (“
Some covered institutions may also be subject to other regulators’ rules implicating
cies’ Incident Response Guidance.
Agencies’ guidelines require covered financial institutions to develop a response program
sensitive customer information “has occurred or is reasonably possible ”
notices to occur “as soon as possible ” but permit delays if “an appropriate law
” Under the guidelines, “sensitive customer information” means “a customer’s name, address, or
customer’s ecuirty number, driver’s license number, account number, credit or debit card
customer’s account.” ddition “any combination of components of customer information
that would allow someone to log onto or access the customer’s account, such as user name and
Banking Agencies’ Incident Response Guidance
Commission’s recently amended Standards for Safeguarding Customer Information (“ Safeguards Rule”) that contains a number of modifications to the existing rule with respect to
fecting customers’ securities transactions, providing
holding customers’ funds and securities; (4) handling clearance and settlement of trades; (5)
Such information would include the customers’ names, tax numbers, telephone numbers, broker,
dealers are not “carrying broker dealers” and therefore do not report the numbers of customer
of clients’
Here, “custody” means “holding, directly or i authority to obtain possession of them.” An adviser also has “custody” if “a related person holds, n connection with advisory services [the adviser] provide[s] to clients.”
a “ ng”
# Advisers
# States
companies (‘‘ ’’) Unit Investment Trusts (‘‘ ’’) entities’ companies
Because they are not operating companies, investment companies do not have ‘‘customers’’ as such, and thus are unlikely to possess significant amounts of nonpublic ‘‘customer’’ information
employees’ securities companies
the investment companies that would be subject to the proposed rules are part of a ‘‘family’’ of
As used here, ‘‘family’’ refers to a set of funds reporting the same family investment company
changes of ownership (“transfers”), communicat
registered securities are held in “street name” where the ultimate ownership
Rather the individual’s broker maintains the records of the individual’s
transfers a transfer agent would need to provide a customer’s identification information in the
—to other transfer agents (“service companies”).
” institutions’ ’ core functions would generally offering more “traditional” “otherwise [] permitted access to customer information” reliance on third parties for
ed institutions to “develop, implement safeguards for the protection of customer information” “designed to detect, respond to, and recover from unauthorized access to or use of customer
institutions’ response programs
or example, NIST’s Computer Security
Similar analogues are found in other reports, recommendations, and other regulators’
improvements to covered institutions’ processe
process for handling them is unlikely to be routine for a covered institution’s covered institution’s
institutions’ with the proposed rule’s requirements For example, the Banking Agencies’ Guidance states that covered institutions that are king Agencies’ geographic catering and that these entities will all have a “national presence ”
customers’ perceptions of the firm). Thus, the costs of
“Cybersecurity Incident Response and Recovery” element of the policies and procedure required
covered institutions’ customers—
proposed amendments would require that a covered institution’s incident response
“service provider” is defined broadly, as “
institution.”
to facilitate covered institutions’ compliance with the proposed requirements.
institutions’ compliance with the proposed amendments.
critical function likely “ processes, or otherwise is permitted access to customer information”
d institutions’ compliance, but may be unwilling to enter into suitable
address “generic” vulnerabilities that apply to all customers ( mitigate vulnerabilities “specific” to a given customer ( Smaller, “upstart” service providers may be more willing to provide unrealistic contractual
The “strength” of a data breach laws generally applicable to compromises of their residents’ information.
each customer’s state of residence, with the
provisions to the overall “strength”
“strength” of individualextends to “all customer information in the possession of a covered institution, institutions and has been provided to the covered institution.”
s from the covered institution’s “core” customer account management systems
These “GLBA Safe Harbors”
1
in the most
notification deadlines should increase customers’ ability to take effective
state statute requires notice be given “without unreasonable delay, and no more than thirty system” RCW 19.255.010(8).
Days to Identify Breach
data from the Washington Attorney General’s Office for 2021, “containment” of data breaches it takes an average of 75 days to “contain” ccording to IBM’s study for 2021, of “containment ” raising the attack’s
, “sensitive customer information” is defined
—cases where the “sensitive customer information” be problematic if they reduce customers’ sensitivity to data breach notices. In addition,
“sensitive customer information” is defined as “any component of
” ’s basis in “any compon customer information”
mother’s maiden name,
a customer’s name together with one or
a driver’s license number, or a
a covered institution’s compromise of the customer’s
linked with the customer’s name) can trigger the not
customer’s email address in combination with a security question and answer would only trigger
moreover, the compromise of information such as a customer’s name, combined with her
increase customers’ ability to take actions to mit
Under the proposal, the access or use without authorization of an individual’s sensitive
Currently, 21 states’ notification laws do
ed recordkeeping requirements would help facilitate the Commission’s
We distinguish here between the theoretical “baseline” in which the self of the statute have not come into effect and the current “status quo” (in which they have).
of covered institutions’ response to incidents,
’ service providers, the overall
obtain “reasonable assurances”
Under this alternative we would use the proposal’s “service provider ” institution.”
“maintain” computerized data containing private information
d institutions’ compliance with the proposed
proposal’s requirement for written contracts, we expect that “reasonable assurances” would
to document the “reasonable assurances,”
red to “reasonable assurances,” a written contract is clearer,
critical function likely “
processes, or otherwise is permitted access to customer information”
the “possible misuse” of sensitive customer information (rather than the proposed
Additionally, the service provider’s standard terms and conditions might in some
customers’
proposed, notification is triggered by the “reasonable likelihood” that sensitive
an express safe harbor may not be as protective as the proposal’s
“a reasonably likely risk of substantial harm or incon
Here, “secure procedures” refers to the secure implementation of encryption algorithms and
credentials belonging to LastPass’ customers was exfil
attempts to decrypt the passwords by guessing a customer’s
customers’
attacker’s location, identity
enhance law enforcement’s
Banking Agencies’ Inci
investigators may “avoid tipping off the adversary that their presence in the network has been discovered”).
law enforcement’s knowledge of attackers’ recovery of criminals’ ill
contain “ ” Paperwork Reduction Act of 1995 (“PRA”).
(“OMB”) for review in accordance with the PRA.
0610, the title of which is, “Rule 248.30, Procedures ion; disposal of consumer report information.”
P’s notice and opt
— 3 —
Q; and data on employees’ securities companies
The Commission’s estimates of the relevant wage rates are based on
The Commission’s estimates of the relevant wage rates for external time costs, such
covered institution’s
accuracy of the Commission’s estimate of the burden of the proposed collection of information;
(RFA")
Analysis (“IRFA”) that describes the impact of the proposed rule on small entities, unless the
enhance the protection of customers’ nonpublic personal
by applying the protections of both rules to “customer information ”
P’s annual
Improve covered institutions’
that a covered institution’s response program include policies and procedures
organization (collectively, “small entity”) for purposes
P’s annual privacy notice delive
ce a fraud alert in the individual’s credit reports to put the individual’s sion’s website address where individuals may obtain government
P’s annual privacy notice delivery provisions
records covered by the rule, and an institution’s
Banking Agencies’ Incident Response Guidance
Agencies’ Incident Response Guidance
overlap or conflict with the Banking Agencies’ Incident Response Guidanc
ubpart C, (requiring financial institutions subject to the Commission’s jurisdiction
protections for these entities’ customers and compro
overlap or conflict with the Banking Agencies’ Incident Response Guidance(SBREFA’’), the Commission must advise OMB whether a proposed regulation considered “major” rule. Under SBREFA, a rule is “major” where, if adopted, it results in or is
We request comment on whether our proposal would be a “major rule” for purposes of
by, in paragraph (b), replacing the words “ ” with “ ”; and replacing the words “Federal Trade Commission’s” with “Consumer Financial Protection Bureau’s.”
unable to identify which specific individuals’ sensitive customer informati
individual’
(“ARA”)
institution’s operations.
combination with similar information that could be used to gain access to the customer’s account
,
In paragraph (a)(7), removing the period at the end of paragraph and adding “; and” inadvisers”)
(“Commission” or “SEC”)
brokers and dealers (or “ ”)
registered with the Commission (“registered investment
Use the Commission’s internet comment form
post all comments on the Commission’s website (http://ww Comments are also available for website viewing and printing in the Commission’s Public
conditions may limit access to the Commission’s
lable on the Commission’s website. To ensure direct
Chief Counsel’s Office
the Code of Federal Regulations (“CFR”).
1
1
’s provisions include
(b) (“disposal rule”), which
to obtain, share, and maintain individuals’
] (“Reg. S Release”). Regulation S
Similarly, employees’ securities companies –
.” The term “covered institutions referred to as “you” in Regulation S
apply, are sometimes referred to as “covered ” is sometimes used in this release to refer to
FBI’s Internet Crime Complaint Center received 847,376 complaints in 2021
the Financial Industry Regulatory Authority (“ “) 2021 Report on FINRA’s
Examinations) (“EXAMS”),
(Apr. 16, 2019) (“Reg. S
Alert”),
(Observations Risk Alert”)
organization (“SRO”) rules requiring written supervisory procedures and written business
an institution’s preparedness and the
States also differ regarding a firm’s duty to investigate a data breach when
BA’s requirements for standards for safeguarding customer records and information
California residents of a data breach generally required when a resident’s personal information was or is reasonably believed to have been acquired by an unauthorized person; “pe ” is defined to mean an individual’s first or last name in combination with one of a list
likely to cause substantial harm to the resident to whom the information relates; “sensitive fying information” is defined as the resident’s first or last name in combination
As a result, a firm’s notific
defining “sensitive customer information” more broadly than the current definitions used by at
requirements of the entity’s “primary federal regulator.”
customers’ information
that financial institution’s
among other things, “
6801(b)(3) (emphasis added). We agree with the Federal Trade Commission (“FTC”) that pertaining to another institution’s customers is consistent with the purp
definition of “customer information” that would include both nonpublic personal information that
17 CFR 248.3(g)(2)(iii) (“An individual
dealer’s consumers in order to clear transactions.”).
nfidentiality of customers’ personal information.
unless otherwise noted, we refer to them collectively as “transfer agents” for
term “customer records and information” defined as “
ursuant to the Fair and Accurate Credit Transactions Act of 2003 (“FACT Act”),
“Consumer report information”
information”)
fining “customer records or information”)
(“Disposal Rule Adopting Release”). Section “requiring” but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ and “ but “ anddealer’s
(Mar. 13, 2008)] (“2008 Proposal”). The amendments to Regulation S dealer’s designated examining au ble financial responsibility rules (including the Commission’s customer applicable to “ which would have been defined report information” that is
suggested modifying the proposed amendments’ information security
Letter” Letter”
regulators’ ’s safeguards rule. The
financial institutions under the FTC’s GLBA jurisdiction to establish a written incident response
Information, 86 FR 70272 (Dec. 9, 2021) (“FTC Safeguards Release”). As amended, the FTC’s rule requires that a response plan address security events materially affecting the confidentiality, integrity, or availability of customer information in the financial institution’s an institution’s independent obligation to perform notification as required by state law. Union Administration (“NCUA”)
(Mar. 29, 2005) (“Banking Agencies’ Incident Response Guidance”). The Banking Agencies’ Incident Response Guidance provides,
protection of customers’ nonpublic personal information. These proposed amendments would
applying the protections of both rules to “customer information,” a newly defined term. We also
for the definition of “sensitive customer information.”
13524 (Mar. 9, 2022)] (“Investment Management Cybersecurity Proposal”); Cybersecurity Proposal” ) ( “Corporation Finance ( “Exchange ”) and , 2023), (“Regulation SCI Proposal”)
of a customer’s nonpublic personal
with approximately 330,000 different households, by accessing two of the firm’s portals. The (“PII”) such as customers’ full
92806 (Aug. 30, 2021) (“Cambridge Order”),
third parties resulting in the exposure of at least 2,177 customers’ PII stored i email accounts and potential exposure of another 3,800 customers’ PII); Commission Order
omers’ PII stored in the compromised email
92807 (Aug. 30, 2021) (“KMS Order”),
for example, phishing or credential stuffing. “Phishing” is “spoofed” email to trick a victim into taking action, such as downloading malicious software or website for the system or service, while “credential stuffing” is a means of gaining unauthorized
taking over a customer’s acc to obtain unauthorized entry to a customer’s online brokerag without the customer’s ’s
The “dark web” is a part of the internet that requires specialized software t specifically designed to facilitate anonymity by obscuring users’ identities, including by hiding users’ internet protocol addresses. The anonymity provided by the dark web has allowed users to
institution’s
and unauthorized trading scheme with at least one other person. The SEC’s complaint alleged
the unauthorized trading of stock in the victims’ accounts.
rule refer to “ “use.” ”, the word “ ” modifies both “access” and information.” for a discussion of “customer
avoid inadequate responses based on a covered institution’s
amendments would require that a covered institution’s
for the definition of “sensitive customer information ”
, which includes a discussion of “sensitive customer information.”
a covered institution’s
)(3)(i). The term “customer information systems” would mean the support the covered institution’s operations.
rules would be applicable to “Market Entities” s (collectively, “Covered Entities”) as well as broker “fund information system” and “fund information.”
the Market Entities’ institutions’ policies the proposed rule’s requirement that
.
a covered institution’s
the proposed rule’s requirements
the covered institutions’
For example, a bad actor could use a service provider’s access to a covered institution’s systems to infiltrate the covered institution’s network through a
(“Adviser Outsourcing Proposal”); FINRA Notice to
NIST defines a “cybersecurity compromise in the supply chain” as “an occurrence within the
and thereby gain unauthorized access to the covered institution’s customer
we propose to define the term “service provider” to
institution’s
anywhere during the life cycle of the system, product or service.”
(Best Practices in Cyber Supply Chain Risk Management”)
was able to gain a foothold in Target’s network through a third
a bad actor breached the Target Corporation’s
A “Kill Chain” Analysis of the 2013
institution’s
could create a risk of substantial harm to the covered institution’s c
The proposed amendments would require that a covered institution’s incident response
the proposed definition of “service provider”?
we exclude a covered institution’s
“service provider” in this ruledefinitions of “service provider” that should be included in the definition of “service providers?”
institution’s customer information. Is
P’s opt
ID’s requirements
11, “service provider” investment adviser. In the proposal, a “covered function” would mean cause a material negative impact on the adviser’s clients or on the adviser’s requires financial institutions subject to the Commission’s jurisdiction with covered
Banking Agencies’ Incident Response Guidance
Banking Agencies’ Incident Response Guidance
Is “as” an
such as “as soon as practicable”?
A risk of harm provision under a particular state’s rules
Notification Laws, (“NCSL Security Breach Notification Law Resource”),
sufficiently clear? Is a standard of “reasonably likely” appropriate? Should the
“reasonably possible” which would suggest a more expansive standard than “likely”?
. Is this standard “not reasonably
” for rebutting the presumption to notify the appropriate standard?
Should the standard be “not reasonably possible”?
some states’ laws
” likely risk of substantial harm or inconvenience.” definition of “sensitive customer information.”
ould create a “reasonably notice requirements would be information pertaining to a covered institution’s customers and customer’s Social Security number may not
linked to the individual, would be sensitive because they have been used in “Social Security only” or “synthetic” identity theft. In this type of identity theft, a Social Security create a new (or “synthetic”) identity, which then may allow the malicious actor to, among other information that can be used alone to authenticate an individual’s identity. A biometric record of
mother’s maiden name A mother’s maid
In this respect, our proposed definition is broader than the definition of “sensitive customer information” provided in the Banking Agencies’ Incident Response Guidance. That definition includes a customer’s name, address, or telephone number, only in conjunction with other pieces
Tapping “Synthetic Identity Fraud” to Commit
cipher text could be decrypted, it would also reduce the likelihood that the cipher text’s
definition of “sensitive customer
acquisition of certain “unencrypted, computerized data information,” and defining “encrypted” as data transformed “through the use of a one hundred twenty
confidential process or key” unless the data was “acquired in combination with any key, security data.”).
We request comment on the proposed rule’s definition of sensitive customer information
Should we broaden the proposed definition of “sensitive customer information” to
Agencies’ Incide
when linked would permit access to an individual’s accounts? Should the
ecurity number, driver’s license or other government identification number,
create a “reasonably likely” risk
For example, would a “reasonably foreseeable” standard
information the compromise of which “could” create a reasonably likely risk
customer information that “would” create such risk?
Should we provide additional or alternative examples of what constitutes “sensitive customer information” in the rule text?
Is encryption a relevant factor to a covered institution’s determination of the
,
covered institution’s determination that cipher text’s
Should we except from the definition of “sensitive customer information” encrypted
Definition of “Substantial Harm or Inconvenience”
We propose to define “substantial harm or inconvenience” to mean “personal injury, or
,” and provide
P requires a covered institution’s
malicious actor’s
,
Congress’s goal
We request comment on the proposed rule’s definition of substantial harm or
proposed definition of “substantial harm or inconvenience”?
other than “substantial” and “more than trivial” in describing the types of harms that
Is “more
“the policy of the Congress that each financial institution
the security and confidentiality of these customers’ nonpublic personal information.”
“more than trivial” the appropriate standard?
“immaterial” or “ significant”?
a numerical or other objective standard for “ substantial” harm or
Should a harm that is a “ personal injury,” such as phys
“trivial,” similar to our proposed treatment of
Should the standard for a harm that is a “ personal injury” be something other than “ trivial?”
notwithstanding a covered institution’s determination to
which specific individuals’ data
identify which specific individuals’ sensitive customer information has been accessed or used
. Accordingly, proposed rule 248.30(b)(3)(iii) and (b)(4)(i) refers to “affected individuals without authorization” rather than “customer.” This is because the term “customer” is defined in section 248.3(j) as “a consumer that has a customer relationship with the [covered] institution,”
institutions provide notices “as soon as practicable”
identity theft or other harm. The amount of time that would constitute “as soon as practicable” may vary based on several factors,
“as soon as practicable”The proposal’s as practicable.”
provide notices to affected customers “as soon
institution’s timely and uniform customer notification that customers’ sensitive customer information has
We request comment on the proposed rule’s notification timing requirements
Should the rule require institutions to provide notice “as soon as possible ”
Should the rule provide parameters to define “as soon as practicable,” “as soon as possible ” “as soon as reasonably practicable”
“becoming aware that unauthorized access to or use of customer information has
”?
for example, after the covered institution “reasonably should have
been aware” of the incident or, alternatively, after completing its assessment of the
the timing requirement should begin upon “becoming
” should we provide covered institutions
individuals may obtain “consumer reports” from consumer reporting we refer to “credit reports” in
Banking Agencies’ Incident Response Guidance notices include a recommendation that customers obtain “credit reports,” and in part, because we ” Consumer Financial Protection Bureau (“CFPB”),
and opt out notices) and 17 CFR 248.3(c)(1) (defining “clear and conspicuous”)
17 CFR 248.3(c)(2) (providing examples explaining what is meant by the terms “reasonably understandable” and “designed to call attention” ).
whether to provide certain information “as appropriate” on a case
“consumer reports” “credit reports” more familiar with the term “credit report”
of 45% of jobs involving teleworking “at least some of the time.”
“customer information,” a newly defined term
institution’s customers
defined “customer
” The Commission has “broad rulemaking authority” to effectuate “the policy of the Congress that information.” f these customers’ nonpublic personal
’s protect “customer records and information,” “consumer report information,” a
15 U.S.C. 6801(a) (“It is the policy of the Congress that each financial institution has an security and confidentiality of those customers’ nonpublic personal information.”) (emphasis
disposal of “consumer information, or any compilation of consumer information, derived from consumer reports for a business purpose.”
“consumer report information” about an individual “that is a consumer
report.” 17
“Consumer report”
the term “customer records and information” in the safeguards rule with term “customer information”
“customer information” to encompass any record containing “nonpublic personal information” about “a customer of a financial institution,” whether in paper,
GLBA, which focuses on protecting “nonpublic personal information” of those who are “customers” of financial institutions.
conform more closely to the definition of “customer information” in the safeguards rule adopted
to change the term “consumer report information” currently in Regulation S P to “consumer information” (without changing the definition) to conform to the term used by
Information Security Standards (“OCC Information Security Guidance”), at I.C. 2 to Part 208 (“FRB Information Security Guidance”), at I.C.2.b.
We propose a separate definition of “customer information” applicable to transfer agents.
16 CFR 314.2(d) (FTC safeguards rule defining “customer information” to mean “any record
“continuing obligation” to protect the security and confidentiality of customers’ nonpublic
FACT Act focuses on protecting “consumer information ”
eliminating an institution’s need to
rule more closely to the Banking Agencies’ Safeguards Guidance.
he Commission’s statutory mandate
or on behalf of you or your affiliates”). The proposed rules would not require covered institutions to be responsible for their affiliates’ policies and procedures for safeguarding customer
proposed rule 248.30(c)(1). “Customer information” is n
“customer information,” because the safeguards rule is adopted pursuant to the GLBA and therefore is limited to information about “customers.”
associations’ must develop, implement, and maintain appropriate measures to properly dispose of customer information and consumer information.”);
comment on the proposed definition of “ s’ Is the proposed definition of “customer information,” which includes nonpublic personal information about an institution’s own customers that
from a third party financial institution about that institution’s customers
P defines “customer” as “a consumer who has a customer relationship with you.” The
rule, therefore, only protects the “records and information” of individuals who are
d institution’s own
the custodian of a former client’s assets wou
individual’s c
The safeguards rule is applicable to “consumer information” only to the extent it overlaps with “customer information.”
P defines “financial institution” generally to mean any institution the business of
approach is consistent with the FTC’s
the scope? For example, should the rules’ protections for “customer information”
, an employee’s or former customer’s bank account
customers’ information that the covered institution
Should employees’ nonpublic personal information be
314.1(b) (providing that the FTC’s safeguards rule “applies to all customer information h information to you”)
--- page 64 ---
--- page 65 ---
--- page 66 ---
--- page 67 ---
--- page 68 ---
--- page 69 ---
--- page 70 ---
--- page 71 ---
--- page 72 ---
--- page 73 ---
--- page 74 ---
--- page 75 ---
--- page 76 ---
--- page 77 ---
--- page 78 ---
--- page 79 ---
--- page 80 ---
--- page 81 ---
--- page 82 ---
--- page 83 ---
--- page 84 ---
--- page 85 ---issuers the official record of ownership of such issuer’s securities; (ii) cancel old certificates, and other detailed and individualized information related to the transfer agents’ recordkeeping
Exchange Act Release No. 76743 (Dec. 22, 2015) [80 FR 81948, 81949 (Dec. 31, 2015)] (“2015 ”).
account for this, the proposed definition of “customer information” with respect to a transfer
“ nonpublic personal information...
Currently, the disposal rule only applies to those transfer agents “registered with the Commission.”
proposed definition of a “covered institution” as “a transfer agent registered with the ate regulatory agency.”
ection 216 of the FACT Act was to “prevent unauthorized disclosure of information contained
ud or related crimes, including identity theft.” that covered entities’ consumers would
indicated that the disposal rule as proposed would impose “minimal costs” on firms in the form
under the disposal rule through the taking of “reasonable measures” to protect against
“minimize the burden of compliance for smaller entities.”
FR 56304 (Sept. 20, 2004)] (“2004 Proposing Release”), at 56308.
“residual jurisdiction” under the same congressional mandate, to enact both
registered, the Commission “is empowered with broad rulemaking authority over all a transfer agent’s activities as a transfer agent.”
(d)(1) (providing that “n as ... transfer agent such rules and regulations” as the Commission may prescribe); Exchange Act (providing that “Nothing in the preceding imit ... the Commission’s der.”).
Commission’s experience administering the transfer agent examination program, we are aware
A transfer agent’s failure to account for such risks and take appropriate steps to
found on the systems they maintain will help prevent securityholders’ customer information from
We use the term “paying agent services” here to refer to administrative, recordkeeping, and
definition of “customer information” appropriate with
of “customer information”
Notice
Dealer Release”).
dealers from the rule’s scope noting its belief that Congress did not intend for the Commission’s FACT Act rules to apply to entities subject to primary oversight by
and the disposal rule. First, the proposed rule would define a “covered institution” to include “any broker or dealer,” without excluding notice
P’s disposal rule (currently rule 248.30(b)).
at n.23 (stating “
”);
.”).
page 97 ---
P’s substituted compliance provisions would still apply to notice
also employ this proposed definition of a “covered institution ” it would retain the disposal rule’s
the CFTC’s financial privacy rules, the Commission believes the benefits and
page 98 ---
alter the scope of either rule’s application to notice
institution’s
tain investment companies, such as some employees’ securities
page 99 ---
covered institution’s periodic
(“proper disposal policies and procedures are enc
”)
page 100 ---
informing them about the institution’s privacy policies.
informing them about the institution’s privacy policies.
Fixing America’s Surface Transportation (“FAST ”)
new section 503(f) to GLBA (“statutory exception”).
“consumer” as “
P, an institution’s customer is a “consumer” that has a
” 17 CFR 248.3(g).
page 104 ---
the requirement to provide customers an opportunity to opt out of the institution’s information
the words “Except as provided by paragraph (e) of this section ....”
page 105 ---
’s policies
he institution’s most recent privacy notice sent to customers. We are not
the notice to describe the customer’s right to opt out of the
requiring an institution’s privacy notice to include any
institution’s affiliates and do not affect whether the statutory exception is satisfied 603(d)(2)(iii) (excluding from the term “consumer report” communication of other
the Fixing America’s Surface Transportation Act, 83 FR 63450 (Dec. 10, 2018), at n.17; CFPB,
page 106 ---
notice to an individual who becomes the institution’s customer no later than when it
“ annually”
page 107 ---
institution’s change in policies or practices. tion’s change in policies or practices does not
page 108 ---
-
page 109 ---
collectively, “departing personnel”)
he shared information could not include any customer’s account number, Social
page 110 ---
from this proposal’s notice and opt out requirements
opriate in light of the GLBA’s goals? If so, is
page 111 ---
“cybersecurity risk” as “an effect of uncertainty on or within information and technology.”
page 112 ---
alternative trading systems (“ “)
and surrounding text as to the meaning of “covered institution.”
An “SCI Entity” is currently defined to include
page 113 ---
“SCI entity”
based trading threshold in national market system (“NMS”) stocks, exchange
17 CFR 242.1000 (defining the terms “SCI alternative trading system,” “SCI self system,” and “Exempt clearing agency subject to ARP,” and including all of those defined terms in the definition of “SCI ties”)
page 114 ---
P’s requirements apply to all br dealers, except for “notice dealers” (as defined in 17 CFR 248.30), who in most cases will be deemed to be in
P’s obligations.
. of this release, the term “broker dealer”
the Commission (“registered transfer agents”) (but not transfer agents registered with another P’s disposal rule.
ntity’s policies and
page 115 ---
the policies and procedures required by Regulation SCI focus on the SCI entities’
page 116 ---
-
page 117 ---
the Commission (“registered transfer agents”) (but not transfer agents registered with another P’s disposal rule.
ntity’s policies and
page 118 ---
-P currently defines the term “disposal” to mean: (1) the Regulation SCI’s obligation to take corrective action ma
Covered Entity’s
and remediate any cybersecurity threats and vulnerabilities with respect to the Covered Entity’s
, a Covered Entity’s policies and procedures would
ntity’s information systems and the information residing
To the extent an entity’s policies and procedures under the Exchange Act Cybersecurity Proposal
’s risk
Covered Entity’s policies and
need to require periodic assessments of cybersecurity risks associated with the Covered Entity’s
Entity’s information systems and any of the Covered Entity’s information residing on those
riity risks associated with the Covered Entity’s use of these
, a Covered Entity’s policies and
Covered Entity’s information, or are otherwise permitted to access the Covered Entity’s
to protect the Covered Entity’s information systems and information residing on those systems.
P’s proposed policy
y’s policies and
behavior for individuals authorized to access the Covered Entity’s information systems and the
, a Covered Entity’s policies and include measures designed to protect the Covered Entity’s information
based on a periodic assessment of the Covered Entity’s information systems and the information
--- page 125 ---
formation to the Covered Entity’s business operations;
--- page 126 ---
-
--- page 127 ---
would, if it experiences a “significant cybersecurity incident,” be required to
entity’s business and operations and how the covered entity assesses, prioritizes, and addresses
--- page 128 ---
summary description of the incident via EDGAR and the entity’s business
Covered Entity’s exposure to materia
a way for market participants to evaluate the Covered Entity’s cybersecurity risks and
--- page 129 ---
dealer, with information they can use to evaluate the event’s impact on their trading and
--- page 130 ---
and business development companies (“covered IM entities”)
--- page 131 ---
confidentiality, integrity, or availability of an adviser or fund’s information or information
impact on the adviser’s clients or on the adviser’s ability to provide investment advisory services
--- page 132 ---
such persons’
--- page 133 ---
-
--- page 134 ---
-
--- page 135 ---
<table>
<tr>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
</tr>
</table>
--- page 136 ---
"smaller " for this purpose?
--- page 137 ---
As discussed above, “customers” includes not only custo the possession of covered institutions. In addition, with respect to a transfer agent, “customers” refers to “
--- page 138 ---
covered records to “customer information” and extending the covered population
--- page 139 ---
notices improve customers’ ability to take
--- page 140 ---
defining “sensitive customer information” more broadly than the
Throughout this economic analysis, “compliance costs” refers to the direct costs that borne in order to avoid violating the Commission’s rules.
costs” excludes costs that are not require Commission’s rules ( As used here, “compliance
--- page 141 ---
customers’ customers, and that both these effects would improve customers’ ability to act to protect their customers’ sensitive information.
--- page 142 ---
’ ability to compete with t
In a perfectly competitive market, market forces would lead firms to “efficiently”
--- page 143 ---
information about the firm’s product or service
customers’ (current
covered institutions’
economic texts, this “efficient” safeguarding of customer information would correspond to
Here, “adequate safeguards” can be thought of as the level of safeguards in a world where the level of firms’ efforts (and the costs of these
Press release, U.S. Fed. Trade Comm’n,
--- page 144 ---
, “underspend”)
covered institution’
and in so doing influence firms’ efforts toward protecting customer information.
enhance firms’
“underspending” on cybersecurity.
(Mar. 2020) (“IIF/McKinsey Report”),
In the case of transfer agents such effects would be mediated through firms’ choice of transfer prefer to avoid employing the services of transfer agents that allow their investors’ information to
(“ ”)
--- page 145 ---
,
competitive “race to the bottom.”
by the proposed amendments (“covered institutions”
The “bottom” in such a race is a level of cybersecurity spending that is too low from an efficiency
--- page 146 ---
1
--- page 147 ---
“underspending” on cybersecurity
(stating 58% of surveyed banks’ Chief Risk Officers cite “inability to manage cybersecurity risk” as the top strategic risk); s Public cloud security ‘just barely adequate,’ experts say,
providers “should be doing more on security.”)
--- page 148 ---
regulations that affect covered institutions’ effort toward safeguarding customers’ information.
Annual Report”),
Annual Report (Jan. 2022) (“ITRC Data Breach (“IBM Cost of Data Breach Report”),
--- page 149 ---
regulations aimed at increasing firms’ efforts toward safeguarding customer information reduce
“personal information” of a state’s resident is either accessed or acquired in an unauthorized
number, driver’s license number
information. “States” in this discussion includes the 50 U.S. states and the District of Columbia,
--- page 150 ---
certain harms (“ harm exception”).
commonly include: “harm” generally (12), identity theft or other fraud (10), misuse of personal
harms referenced in states’
3501, (defining “personal information” to include credit card
551 (defining “personal information” to include an individual’smade “without unreasonable delay,” or “in the most expedient time possible and without unreasonable delay”).
“ not later than 30 days after the date of determination that the breach occurred”
1798.82(a) (disclosure to be made “in the most expedient time possible and without unreasonable delay” but allowing for needs of law enforcement and
716 (notice to be made “in the most expedient time possible
integrity of the computerized data system”); Fla. Stat. 501.171(4)(a) (notice to be made “as ly as practicable and without unreasonable delay ... but no later than 30 days after the determination of a breach” unless delayed at the request of law enforcement or waived pursuant to the state’s no
[68 FR 74714 (Dec. 24, 2003)], at n.22 (“Compliance Program Release”) ID applies to “financial institutions” or “creditors” that offer or maintain “covered accounts.” 2013)] (“
Some covered institutions may also be subject to other regulators’ rules implicating
cies’ Incident Response Guidance.
Agencies’ guidelines require covered financial institutions to develop a response program
sensitive customer information “has occurred or is reasonably possible ”
notices to occur “as soon as possible ” but permit delays if “an appropriate law
” Under the guidelines, “sensitive customer information” means “a customer’s name, address, or
customer’s ecuirty number, driver’s license number, account number, credit or debit card
customer’s account.” ddition “any combination of components of customer information
that would allow someone to log onto or access the customer’s account, such as user name and
Banking Agencies’ Incident Response Guidance
Commission’s recently amended Standards for Safeguarding Customer Information (“ Safeguards Rule”) that contains a number of modifications to the existing rule with respect to
fecting customers’ securities transactions, providing
holding customers’ funds and securities; (4) handling clearance and settlement of trades; (5)
Such information would include the customers’ names, tax numbers, telephone numbers, broker,
dealers are not “carrying broker dealers” and therefore do not report the numbers of customer
of clients’
Here, “custody” means “holding, directly or i authority to obtain possession of them.” An adviser also has “custody” if “a related person holds, n connection with advisory services [the adviser] provide[s] to clients.”
a “ ng”
# Advisers
# States
companies (‘‘ ’’) Unit Investment Trusts (‘‘ ’’) entities’ companies
Because they are not operating companies, investment companies do not have ‘‘customers’’ as such, and thus are unlikely to possess significant amounts of nonpublic ‘‘customer’’ information
employees’ securities companies
the investment companies that would be subject to the proposed rules are part of a ‘‘family’’ of
As used here, ‘‘family’’ refers to a set of funds reporting the same family investment company
changes of ownership (“transfers”), communicat
registered securities are held in “street name” where the ultimate ownership
Rather the individual’s broker maintains the records of the individual’s
transfers a transfer agent would need to provide a customer’s identification information in the
—to other transfer agents (“service companies”).
” institutions’ ’ core functions would generally offering more “traditional” “otherwise [] permitted access to customer information” reliance on third parties for
ed institutions to “develop, implement safeguards for the protection of customer information” “designed to detect, respond to, and recover from unauthorized access to or use of customer
institutions’ response programs
or example, NIST’s Computer Security
Similar analogues are found in other reports, recommendations, and other regulators’
improvements to covered institutions’ processe
process for handling them is unlikely to be routine for a covered institution’s covered institution’s
institutions’ with the proposed rule’s requirements For example, the Banking Agencies’ Guidance states that covered institutions that are king Agencies’ geographic catering and that these entities will all have a “national presence ”
customers’ perceptions of the firm). Thus, the costs of
“Cybersecurity Incident Response and Recovery” element of the policies and procedure required
covered institutions’ customers—
proposed amendments would require that a covered institution’s incident response
“service provider” is defined broadly, as “
institution.”
to facilitate covered institutions’ compliance with the proposed requirements.
institutions’ compliance with the proposed amendments.
critical function likely “ processes, or otherwise is permitted access to customer information”
d institutions’ compliance, but may be unwilling to enter into suitable
address “generic” vulnerabilities that apply to all customers ( mitigate vulnerabilities “specific” to a given customer ( Smaller, “upstart” service providers may be more willing to provide unrealistic contractual
The “strength” of a data breach laws generally applicable to compromises of their residents’ information.
each customer’s state of residence, with the
provisions to the overall “strength”
“strength” of individualextends to “all customer information in the possession of a covered institution, institutions and has been provided to the covered institution.”
s from the covered institution’s “core” customer account management systems
These “GLBA Safe Harbors”
1
in the most
notification deadlines should increase customers’ ability to take effective
state statute requires notice be given “without unreasonable delay, and no more than thirty system” RCW 19.255.010(8).
Days to Identify Breach
data from the Washington Attorney General’s Office for 2021, “containment” of data breaches it takes an average of 75 days to “contain” ccording to IBM’s study for 2021, of “containment ” raising the attack’s
, “sensitive customer information” is defined
—cases where the “sensitive customer information” be problematic if they reduce customers’ sensitivity to data breach notices. In addition,
“sensitive customer information” is defined as “any component of
” ’s basis in “any compon customer information”
mother’s maiden name,
a customer’s name together with one or
a driver’s license number, or a
a covered institution’s compromise of the customer’s
linked with the customer’s name) can trigger the not
customer’s email address in combination with a security question and answer would only trigger
moreover, the compromise of information such as a customer’s name, combined with her
increase customers’ ability to take actions to mit
Under the proposal, the access or use without authorization of an individual’s sensitive
Currently, 21 states’ notification laws do
ed recordkeeping requirements would help facilitate the Commission’s
We distinguish here between the theoretical “baseline” in which the self of the statute have not come into effect and the current “status quo” (in which they have).
of covered institutions’ response to incidents,
’ service providers, the overall
obtain “reasonable assurances”
Under this alternative we would use the proposal’s “service provider ” institution.”
“maintain” computerized data containing private information
d institutions’ compliance with the proposed
proposal’s requirement for written contracts, we expect that “reasonable assurances” would
to document the “reasonable assurances,”
red to “reasonable assurances,” a written contract is clearer,
critical function likely “
processes, or otherwise is permitted access to customer information”
the “possible misuse” of sensitive customer information (rather than the proposed
Additionally, the service provider’s standard terms and conditions might in some
customers’
proposed, notification is triggered by the “reasonable likelihood” that sensitive
an express safe harbor may not be as protective as the proposal’s
“a reasonably likely risk of substantial harm or incon
Here, “secure procedures” refers to the secure implementation of encryption algorithms and
credentials belonging to LastPass’ customers was exfil
attempts to decrypt the passwords by guessing a customer’s
customers’
attacker’s location, identity
enhance law enforcement’s
Banking Agencies’ Inci
investigators may “avoid tipping off the adversary that their presence in the network has been discovered”).
law enforcement’s knowledge of attackers’ recovery of criminals’ ill
contain “ ” Paperwork Reduction Act of 1995 (“PRA”).
(“OMB”) for review in accordance with the PRA.
0610, the title of which is, “Rule 248.30, Procedures ion; disposal of consumer report information.”
P’s notice and opt
— 3 —
Q; and data on employees’ securities companies
The Commission’s estimates of the relevant wage rates are based on
The Commission’s estimates of the relevant wage rates for external time costs, such
covered institution’s
accuracy of the Commission’s estimate of the burden of the proposed collection of information;
(RFA")
Analysis (“IRFA”) that describes the impact of the proposed rule on small entities, unless the
enhance the protection of customers’ nonpublic personal
by applying the protections of both rules to “customer information ”
P’s annual
Improve covered institutions’
that a covered institution’s response program include policies and procedures
organization (collectively, “small entity”) for purposes
P’s annual privacy notice delive
ce a fraud alert in the individual’s credit reports to put the individual’s sion’s website address where individuals may obtain government
P’s annual privacy notice delivery provisions
records covered by the rule, and an institution’s
Banking Agencies’ Incident Response Guidance
Agencies’ Incident Response Guidance
overlap or conflict with the Banking Agencies’ Incident Response Guidanc
ubpart C, (requiring financial institutions subject to the Commission’s jurisdiction
protections for these entities’ customers and compro
overlap or conflict with the Banking Agencies’ Incident Response Guidance(SBREFA’’), the Commission must advise OMB whether a proposed regulation considered “major” rule. Under SBREFA, a rule is “major” where, if adopted, it results in or is
We request comment on whether our proposal would be a “major rule” for purposes of
by, in paragraph (b), replacing the words “ ” with “ ”; and replacing the words “Federal Trade Commission’s” with “Consumer Financial Protection Bureau’s.”
unable to identify which specific individuals’ sensitive customer informati
individual’
(“ARA”)
institution’s operations.
combination with similar information that could be used to gain access to the customer’s account
,
In paragraph (a)(7), removing the period at the end of paragraph and adding “; and” in