2011-04-07 SEC Press press_release 8 KB 4,804 chars

SEC Charges Brokerage Executives With Failing to Protect Confidential Customer Information

Release
2011-86
Caption
Securities and Exchange Commission v. Brokerage Executives, et al.
summary

The SEC charged three former GunnAllen Financial executives—Frederick Kraus, David Levine, and Mark Ellis—with violating Regulation S-P by improperly transferring 16,000+ customers' confidential data without notice and failing to update security policies despite prior breaches, resulting in $20K penalties for Kraus and Levine and a $15K penalty for Ellis—the first such individual fines under Regulation S-P.

paragraph

The SEC charged Frederick O. Kraus, David C. Levine, and Mark A. Ellis with violating Regulation S-P during GunnAllen Financial’s 2010 wind-down, after Kraus authorized Levine to download customer names, addresses, account numbers, and asset values onto a thumb drive and transfer them to a new employer without providing customers notice or an opt-out option. Ellis, as chief compliance officer, failed to revise the firm’s inadequate policies despite multiple prior security breaches, including stolen laptops and compromised email accounts. All three consented to cease-and-desist orders and censures without admitting or denying the allegations; Kraus and Levine each paid $20,000 in penalties, and Ellis paid $15,000—the first time the SEC imposed financial penalties on individuals solely for Regulation S-P violations.

narrative

The SEC charged three former executives of Tampa-based GunnAllen Financial—Frederick O. Kraus, David C. Levine, and Mark A. Ellis—with violating Regulation S-P during the firm’s 2010 wind-down by failing to protect confidential customer information. Kraus authorized Levine to download personal and financial data from over 16,000 customer accounts—including names, addresses, account numbers, and asset values—onto a portable thumb drive and transfer it to Levine’s new employer without providing customers advance notice or an opportunity to opt out, a clear violation of Regulation S-P. Ellis, as chief compliance officer, neglected to update the firm’s policies despite multiple prior security incidents between 2005 and 2009, such as the theft of three laptops and unauthorized access to the firm’s email system via stolen credentials. The SEC determined that all three willfully aided and abetted GunnAllen’s violations of Rules 30(a), 7(a), and 10(a) of Regulation S-P under the Securities Exchange Act of 1934. Without admitting or denying the findings, each executive consented to a cease-and-desist order and a formal censure. Kraus and Levine were each ordered to pay a $20,000 civil penalty, while Ellis paid a $15,000 penalty—the first time the SEC imposed financial penalties on individuals solely for Regulation S-P violations. The case underscored the SEC’s heightened focus on protecting customer data during broker-dealer transitions and holding compliance officers accountable for systemic failures.

Enriched metadata

Scheme
broker-dealer-fraud (80%)
Outcome
settled
Civil penalty
$15,000
Classified broker-dealer-fraud(confidence 80%). EDGAR detection: forms Form D· recall 29% / precision 9%. detection rule →
Parties
brokerage executiveseric i. bustilloglenn s. gordonsec’s charges against themsec’s order against ellissec’s ordersSecurities and Exchange Commission
Keywords
seccustomer informationinformationkraus levinecustomerlevineconfidential customerkrausgunnallenprotect confidentialmiami regionalellisprotectconfidentialbrokerage executives

Exhibits & Attached Documents (3)

Extracted insights

Dollar amounts 2
  • $20K $20,000 $10K–$100K
  • $15K $15,000 $10K–$100K
Entities 7
  • person brokerage executives
  • person eric i. bustillo
  • person glenn s. gordon
  • agency sec’s charges against them
  • agency sec’s order against ellis
  • agency sec’s orders
  • agency Securities and Exchange Commission
Triples 20
  • Sec Charge Brokerage Executives
  • Sec Find Former President Frederick O. Kraus And Former National Sales Manager David C. Levine Violated Customer Privacy Rules
  • Sec Find Former Chief Compliance Officer Mark A. Ellis Failed To Ensure Firm’S Policies And Procedures Were Reasonably Designed To Safeguard Confidential Customer Information
  • Kraus, Levine, And Ellis Agree To Settle Sec’S Charges Against Them
  • Sec Assess Financial Penalties Individuals Charged Solely With Violations Of Regulation S-P
  • Eric I. Bustillo Say Brokerage Customers Should Be Able To Trust That Sufficient Safeguards Are In Place To Protect Their Private Information From Unauthorized Access And Misuse
  • Glenn S. Gordon Add Kraus And Levine Violated The Law By Transferring Customers’ Private Information Without Giving Them Reasonable Notice To Opt Out
  • Kraus Authorize Levine To Take Information From More Than 16,000 GunnAllen Accounts To His New Employer
  • Levine Download Customer Names And Addresses, Account Numbers, And Asset Values To A Portable Thumb Drive
  • Levine Provide The Records To His New Employer After Resigning From GunnAllen
  • Sec Find The Record Transfer Violated Regulation S-P Because Account Holders Were Only Informed About It After The Fact
  • Cases Against Kraus And Levine Mark First Time That The Sec Has Charged Individuals With Regulation S-P Violations Arising When A Departing Representative Takes Customer Information To A New Employer Without Providing Sufficient Notice And Opt-Out Procedures
  • Sec’S Order Against Ellis Find GunnAllen’S Policies And Procedures To Protect Customer Information Were Vague And Did Little More Than Recite A Provision Of Regulation S-P Known As The Safeguard Rule
  • GunnAllen Have Several Serious Security Breaches From July 2005 To February 2009
  • GunnAllen Theft Three Laptop Computers Belonging To GunnAllen’S Registered Representatives
  • GunnAllen Have Unlawful Access Of Its E-Mail System By A Terminated Employee Using Stolen Password Credentials
  • Ellis Fail To Revise Or Supplement GunnAllen’S Policies And Procedures For Safeguarding Customer Information
  • Sec’S Orders Find Kraus, Levine, And Ellis Willfully Aided And Abetted And Caused GunnAllen’S Violations Of Rule 30(A) Of Regulation S-P Under The Securities Exchange Act Of 1934
  • Sec’S Orders Find Kraus And Levine Willfully Aided And Abetted The Firm’S Violations Of Rules 7(A) And 10(A) Of The Same Regulation
  • Kraus, Levine, And Ellis Consent To Entry Of An Sec Order Censures Them And Requires Them To Cease And Desist From Committ
Text layers
Extracted body text (4,804c)
SEC Charges Brokerage Executives With Failing to Protect Confidential Customer Information FOR IMMEDIATE RELEASE 2011-86 Washington, D.C., April 7, 2011 – The Securities and Exchange Commission today charged three former brokerage executives for failing to protect confidential information about their customers. The SEC’s investigation found that while Tampa-based GunnAllen Financial Inc. was winding down its business operations last year, former president Frederick O. Kraus and former national sales manager David C. Levine violated customer privacy rules by improperly transferring customer records to another firm. The SEC also found that former chief compliance officer Mark A. Ellis failed to ensure that the firm’s policies and procedures were reasonably designed to safeguard confidential customer information. Additional Materials SEC Order Against Marc A. Ellis SEC Order Against Frederick O. Kraus SEC Order Against David C. Levine Kraus, Levine, and Ellis each agreed to settle the SEC’s charges against them. This is the first time that the SEC has assessed financial penalties against individuals charged solely with violations of Regulation S-P, an SEC rule that requires financial firms to protect confidential customer information from unauthorized release to unaffiliated third parties. “Brokerage customers should be able to trust that sufficient safeguards are in place to protect their private information from unauthorized access and misuse,” said Eric I. Bustillo, Director of the SEC’s Miami Regional Office. “Protecting confidential customer information is particularly important when a broker-dealer is winding down operations.” Glenn S. Gordon, Associate Director of the Miami Regional Office, added, “Kraus and Levine violated the law by transferring customers’ private information without giving them reasonable notice to opt out. GunnAllen did not have adequate policies or procedures in place to safeguard client information, ignoring several red flags from security breaches at the firm in prior years.” According to the SEC’s orders instituting administrative proceedings, Kraus authorized Levine to take information from more than 16,000 GunnAllen accounts to his new employer as the firm wound down operations in April 2010. Levine downloaded customer names and addresses, account numbers, and asset values to a portable thumb drive, and provided the records to his new employer after resigning from GunnAllen. The SEC found that the record transfer violated Regulation S-P because account holders were only informed about it after the fact. The cases against Kraus and Levine mark the first time that the SEC has charged individuals with Regulation S-P violations arising when a departing representative takes customer information to a new employer without providing sufficient notice and opt-out procedures. According to the SEC’s order against Ellis, GunnAllen’s policies and procedures to protect customer information were vague and did little more than recite a provision of Regulation S-P known as the Safeguard Rule. There were several serious security breaches at GunnAllen from July 2005 to February 2009, including the theft of three laptop computers belonging to GunnAllen’s registered representatives and the unlawful access of its e-mail system by a terminated employee using stolen password credentials. Despite the security breaches, Ellis failed to revise or supplement GunnAllen’s policies and procedures for safeguarding customer information. The SEC’s orders found that Kraus, Levine, and Ellis willfully aided and abetted and caused GunnAllen’s violations of Rule 30(a) of Regulation S-P under the Securities Exchange Act of 1934, and that Kraus and Levine willfully aided and abetted the firm’s violations of Rules 7(a) and 10(a) of the same regulation. Without admitting or denying the SEC’s findings, Kraus, Levine, and Ellis each consented to the entry of an SEC order that censures them and requires them to cease and desist from committing or causing any violations or future violations of the provisions charged. Kraus and Levine have been ordered to pay penalties of $20,000 each, and Ellis has been ordered to pay a $15,000 penalty. This case was investigated by Sue Curtin and Teresa Verges of the SEC’s Miami Regional Office in coordination with an examination of the firm conducted by Debra Williamson, George Franceschini, Steven Bilezikjian, Anson Kwong, Michael Nakis, William Tudor and Nicholas Monaco of the Miami office. # # # For more information about this enforcement action, contact: Glenn S. Gordon, Associate Regional Director, SEC’s Miami Regional Office Teresa Verges, Assistant Director, SEC’s Miami Regional Office (305) 982-6300 http://www.sec.gov/news/press/2011/2011-86.htm Home | Previous Page Modified: 04/07/2011
OCR text (4,804c · plain-text · 99% conf)
SEC Charges Brokerage Executives With Failing to Protect Confidential Customer Information FOR IMMEDIATE RELEASE 2011-86 Washington, D.C., April 7, 2011 – The Securities and Exchange Commission today charged three former brokerage executives for failing to protect confidential information about their customers. The SEC’s investigation found that while Tampa-based GunnAllen Financial Inc. was winding down its business operations last year, former president Frederick O. Kraus and former national sales manager David C. Levine violated customer privacy rules by improperly transferring customer records to another firm. The SEC also found that former chief compliance officer Mark A. Ellis failed to ensure that the firm’s policies and procedures were reasonably designed to safeguard confidential customer information. Additional Materials SEC Order Against Marc A. Ellis SEC Order Against Frederick O. Kraus SEC Order Against David C. Levine Kraus, Levine, and Ellis each agreed to settle the SEC’s charges against them. This is the first time that the SEC has assessed financial penalties against individuals charged solely with violations of Regulation S-P, an SEC rule that requires financial firms to protect confidential customer information from unauthorized release to unaffiliated third parties. “Brokerage customers should be able to trust that sufficient safeguards are in place to protect their private information from unauthorized access and misuse,” said Eric I. Bustillo, Director of the SEC’s Miami Regional Office. “Protecting confidential customer information is particularly important when a broker-dealer is winding down operations.” Glenn S. Gordon, Associate Director of the Miami Regional Office, added, “Kraus and Levine violated the law by transferring customers’ private information without giving them reasonable notice to opt out. GunnAllen did not have adequate policies or procedures in place to safeguard client information, ignoring several red flags from security breaches at the firm in prior years.” According to the SEC’s orders instituting administrative proceedings, Kraus authorized Levine to take information from more than 16,000 GunnAllen accounts to his new employer as the firm wound down operations in April 2010. Levine downloaded customer names and addresses, account numbers, and asset values to a portable thumb drive, and provided the records to his new employer after resigning from GunnAllen. The SEC found that the record transfer violated Regulation S-P because account holders were only informed about it after the fact. The cases against Kraus and Levine mark the first time that the SEC has charged individuals with Regulation S-P violations arising when a departing representative takes customer information to a new employer without providing sufficient notice and opt-out procedures. According to the SEC’s order against Ellis, GunnAllen’s policies and procedures to protect customer information were vague and did little more than recite a provision of Regulation S-P known as the Safeguard Rule. There were several serious security breaches at GunnAllen from July 2005 to February 2009, including the theft of three laptop computers belonging to GunnAllen’s registered representatives and the unlawful access of its e-mail system by a terminated employee using stolen password credentials. Despite the security breaches, Ellis failed to revise or supplement GunnAllen’s policies and procedures for safeguarding customer information. The SEC’s orders found that Kraus, Levine, and Ellis willfully aided and abetted and caused GunnAllen’s violations of Rule 30(a) of Regulation S-P under the Securities Exchange Act of 1934, and that Kraus and Levine willfully aided and abetted the firm’s violations of Rules 7(a) and 10(a) of the same regulation. Without admitting or denying the SEC’s findings, Kraus, Levine, and Ellis each consented to the entry of an SEC order that censures them and requires them to cease and desist from committing or causing any violations or future violations of the provisions charged. Kraus and Levine have been ordered to pay penalties of $20,000 each, and Ellis has been ordered to pay a $15,000 penalty. This case was investigated by Sue Curtin and Teresa Verges of the SEC’s Miami Regional Office in coordination with an examination of the firm conducted by Debra Williamson, George Franceschini, Steven Bilezikjian, Anson Kwong, Michael Nakis, William Tudor and Nicholas Monaco of the Miami office. # # # For more information about this enforcement action, contact: Glenn S. Gordon, Associate Regional Director, SEC’s Miami Regional Office Teresa Verges, Assistant Director, SEC’s Miami Regional Office (305) 982-6300 http://www.sec.gov/news/press/2011/2011-86.htm Home | Previous Page Modified: 04/07/2011