Finra Releases Cybersecurity Practices Report
Eight sections with suggested practices broker-dealers should adopt

The 46-page report is based off of a targeted examination, also known as a sweep, of an assortment of firms that looked into the types of threats firms face, the parts of firms' systems that might be susceptible to an attack, and how they're handling cybersecurity threats.
The results from the sweep mirrored that of a 2011 Finra survey where firms considered their top three cybersecurity threats: hackers, insiders compromising data and operational risks (power failures, earthquakes, etc.)
The report is broken down into eight sections, each of which includes a "Principles and Effective Practices" portion that summarizes what firms should implement to best protect themselves against cybersecurity. The sections are:
·Governance and risk management for cybersecurity
·Cybersecurity risk assessment
·Technical controls
·Incident response planning
·Vendor management
·Staff training
·Cyber intelligence and information sharing
·Cyber insurance
The report falls in line with Finra's 2015 Regulatory and Examinations Priority letter released earlier this year. The letter identified cybersecurity as one of five key areas of focus for the coming year.
"Broker-dealers face a variety of rapidly evolving cybersecurity threats, which require a well-designed and adaptable cybersecurity program," said Susan Axelrod, executive vice president for regulatory operations at Finra. "Finra is keenly focused on cybersecurity, and firms must make responding to these threats a high priority. This report builds on the insights from our recent cybersecurity sweep and highlights a series of principles and effective practices that firms can adapt to their particular circumstances."
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: http://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Regulation
Experts say HKEX’s plan for T+1 in 2025 is ‘sensible’
The exchange will continue providing core post-trade processing through CCASS but will engage with market participants on the service’s future as HKEX rolls out new OCP features.
No, no, no, and no: Overnight trading fails in SIP votes
The CTA and UTP operating committees voted yesterday on proposals from US exchanges to expand their trading hours and could not reach unanimous consensus.
Big xyt exploring bid to provide EU equities CT
So far, only one group, a consortium of the major European exchanges, has formally kept its hat in the ring to provide Europe’s consolidated tape for equities.
Jump Trading CIO: 24/7 trading ‘inevitable’
Execs from Jump, JP Morgan, Goldman Sachs, and the DTCC say round-the-clock trading—whether five or seven days a week—is the future, but tech and data hurdles still exist.
Pisces season: Platform providers feed UK plan for private stock market
Several companies in the US and the UK are considering participating in a UK program to build a private stock market composed of separate trading platforms.
How to navigate regional nuances that complicate T+1 in Europe
European and UK firms face unique challenges in moving to T+1 settlement, writes Broadridge’s Carl Bennett, and they will need to follow a series of steps to ensure successful adoption by 2027.
Nasdaq leads push to reform options regulatory fee
A proposed rule change would pare costs for traders, raise them for banks, and defund smaller venues.
The CAT declawed as Citadel’s case reaches end game
The SEC reduced the CAT’s capacity to collect information on investors, in a move that will have knock-on effects for its ongoing funding model case with Citadel.