The U.S. Securities and Exchange Commission (SEC) on Wednesday voted in favor of creating a “cyber hygiene program” with rules that would require registered investment advisors and fund companies to implement cybersecurity policies that would be subject to recordkeeping requirements, and to report any cybersecurity incidents to the Commission within 48 hours.

The proposal passed 3-4 with Commissioner Hester Peirce casting the dissenting vote.
“Today’s proposal would require advisers and funds to tell investors about the cybersecurity risks they anticipate, how they would handle those threats, and the nature and scope of any significant cybersecurity incidents that occurred in the past two years,” Commissioner Caroline Crenshaw said in a statement.
Last year, the SEC took action against eight firms, including Cetera and Cambridge, fining them a total of $750,000 for inadequate policies and procedures to protect customer information, according to published reports.
Registered investment advisers, investment firms and business development companies already must comply with rules that “may implicate their cybersecurity practices, such as books-and-records, compliance, and business continuity regulations,” SEC Chair Gary Gensler said in a statement.
Gensler added that the proposed rule would strengthen cybersecurity hygiene and incident reporting by requiring:
- Investment advisers and funds to implement written cybersecurity policies and procedures “reasonably designed to address cybersecurity risks and incidents”;
- Related recordkeeping obligations for advisers and funds;
- Confidential reporting to the Commission by investment advisers if the adviser or funds they advise are subject to certain cybersecurity incidents; and
- Disclosure by advisers on brochures and registered funds on registration statements regarding certain cybersecurity incidents.
“I think such reforms could help reduce the risk for these registrants posed by significant cybersecurity incidents,” Gensler said. “I believe they could give clients and investors better information with which to make decisions, create incentives to improve cyber hygiene, and provide the Commission with more insight into intermediaries’ cyber risks.”
There’s a lot to unpack in this proposed rule, Steve Bomberger, head of SEI Sphere, told Bank Automation News. SEI Sphere is a platform and IT service provider that serves financial institutions. It was formed by financial services firm SEI, which manages, advises or administers approximately $1.3 trillion in hedge, private equity, mutual fund and pooled or separately managed assets, including approximately $399 billion in assets under management.
While there are existing regulations, this proposed SEC rule would be more comprehensive.
“There have been hints of this least from the SEC, from at least the fall of last year, that there is going to be more sweeping and comprehensive regulation around this,” Bomberger said. “Obviously, there’s guidelines and compliance within these regulated entities but there’s a lot of interpretation to what that is in between. I think it’s time and I think we can all say with a little bit more confidence that more regulation … will be coming down the pike.”
The challenge is that organizations tend to differ on how they structure their infrastructure, he added. This rule, if passed, will force organizations to ask some questions about their tech stack, such as “Am I missing anything? And “Do I have the operational support behind some of these policies and procedures to feel good about my cybersecurity posture,” he said.
Cybersecurity is becoming a bigger issue as financial institutions push digital transformation and the cloud, Bomberger added.
“All organizations, if they tackle it appropriately, can help each other and kind of support each other with better operations and compliance, to affect really the [return on investment] for the bad actors,” he said. “That’s what we are all trying to do, which is be stronger with our posture and our policy.”
The proposed rule now undergoes a public comment period for 60 days following publication on the SEC website, or 30 days following publication of the proposal’s release in the Federal Register, whichever period is longer.
Bank Automation Summit, taking place March 1-2 in Charlotte, is the first and only event to focus solely on automation in banking. The event will feature the brightest minds from across financial services on intelligent automation strategies and deployment. Learn more and register here for Bank Automation Summit 2022.





