2020-01-01 SEC Press press_release 61 KB 1,900 chars

SEC Office of Compliance Inspections and Examinations Publishes Observations on Cybersecurity and Resiliency Practices

Release
2020-20
summary

No fraud, charges, or financial penalties are described; the SEC’s OCIE issued non-enforcement cybersecurity best practices observations to promote compliance and operational resiliency among market participants.

paragraph

The SEC’s Office of Compliance Inspections and Examinations (OCIE) published observations on cybersecurity and operational resiliency practices among SEC-registered entities, including investment advisers, broker-dealers, and clearing agencies. The report highlights voluntary best practices in areas such as access controls, data loss prevention, incident response, and vendor management, with no allegations of misconduct, dollar amounts, or enforcement actions. Its purpose is informational and preventive, aimed at helping organizations strengthen their defenses against cyber threats and improve compliance with securities laws.

narrative

The SEC’s Office of Compliance Inspections and Examinations (OCIE) released a non-enforcement publication outlining observed cybersecurity and operational resiliency practices among SEC-registered market participants, including investment advisers, broker-dealers, and clearing agencies. The report details examples of effective controls in governance, access rights, data loss prevention, mobile security, incident response, vendor management, and training, but does not identify any specific entities, individuals, or instances of fraud. No financial penalties, charges, or allegations of wrongdoing are mentioned, as the document is purely advisory and intended to promote industry-wide improvement. SEC Chairman Jay Clayton and OCIE Director Peter Driscoll emphasized the critical role of cybersecurity in market integrity and encouraged organizations to adopt these practices proactively. The publication reflects OCIE’s risk-based examination mission to prevent fraud, monitor risk, and inform SEC policy without punitive action. By sharing these observations, OCIE aims to help firms assess and enhance their own cybersecurity frameworks. This initiative underscores the SEC’s focus on preventive regulation and industry collaboration rather than enforcement in this context.

Enriched metadata

Scheme
non-corporate (100%)
Classified non-corporate(confidence 100%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
examination observationsJay Claytonmarket participantspeter driscollSecurities and Exchange Commission
Keywords
ocieobservationscybersecurityresiliencyresiliency practicesexaminationspracticescompliance inspectionsinspections examinationscybersecurity resiliencyoperational resiliencymarket participantsseccomplianceexaminations publishes

Exhibits & Attached Documents (1)

Extracted insights

Entities 5
  • person examination observations
  • person Jay Clayton
  • person market participants
  • person peter driscoll
  • agency Securities and Exchange Commission
Triples 7
  • Securities and Exchange Commission issued examination observations
  • Jay Clayton said Data systems are critical to the functioning of our markets
  • Jay Clayton commended OCIE
  • Jay Clayton encouraged market participants
  • Peter Driscoll said We felt it was critical to share these observations
  • OCIE observed practices used to manage and combat cyber risk
  • OCIE conducts examinations
Text layers
Extracted body text (1,900c)
The Securities and Exchange Commission Commission's Office of Compliance Inspections and Examinations (OCIE) today issued examination observations related to cybersecurity and operational resiliency practices taken by market participants. The observations highlight certain approaches taken by market participants in the areas of governance and risk management, access rights and controls, data loss prevention, mobile security, incident response and resiliency, vendor management, and training and awareness. The observations highlight specific examples of cybersecurity and operational resiliency practices and controls that organizations have taken to potentially safeguard against threats and respond in the event of an incident. “Data systems are critical to the functioning of our markets and cybersecurity and resiliency are at the core of OCIE’s inspection efforts,” said SEC Chairman Jay Clayton. “I commend OCIE for compiling and sharing these observations with the industry and the public and encourage market participants to incorporate this information into their cybersecurity assessments.” “Through risk-targeted examinations in all five examination program areas, OCIE has observed a number of practices used to manage and combat cyber risk and to build operational resiliency,’ said Peter Driscoll, Director of OCIE. “We felt it was critical to share these observations in order to allow organizations the opportunity to reflect on their own cybersecurity practices.” OCIE conducts examinations of SEC-registered investment advisers, investment companies, broker-dealers, self-regulatory organizations, clearing agencies, transfer agents, and others. It uses a risk-based approach to examinations to fulfill its mission to promote compliance with U.S. securities laws, prevent fraud, monitor risk, and inform SEC policy. To see other OCIE publications, please visit www.sec.gov/ocie.
OCR text (1,900c · plain-text · 99% conf)
The Securities and Exchange Commission Commission's Office of Compliance Inspections and Examinations (OCIE) today issued examination observations related to cybersecurity and operational resiliency practices taken by market participants. The observations highlight certain approaches taken by market participants in the areas of governance and risk management, access rights and controls, data loss prevention, mobile security, incident response and resiliency, vendor management, and training and awareness. The observations highlight specific examples of cybersecurity and operational resiliency practices and controls that organizations have taken to potentially safeguard against threats and respond in the event of an incident. “Data systems are critical to the functioning of our markets and cybersecurity and resiliency are at the core of OCIE’s inspection efforts,” said SEC Chairman Jay Clayton. “I commend OCIE for compiling and sharing these observations with the industry and the public and encourage market participants to incorporate this information into their cybersecurity assessments.” “Through risk-targeted examinations in all five examination program areas, OCIE has observed a number of practices used to manage and combat cyber risk and to build operational resiliency,’ said Peter Driscoll, Director of OCIE. “We felt it was critical to share these observations in order to allow organizations the opportunity to reflect on their own cybersecurity practices.” OCIE conducts examinations of SEC-registered investment advisers, investment companies, broker-dealers, self-regulatory organizations, clearing agencies, transfer agents, and others. It uses a risk-based approach to examinations to fulfill its mission to promote compliance with U.S. securities laws, prevent fraud, monitor risk, and inform SEC policy. To see other OCIE publications, please visit www.sec.gov/ocie.