Eversheds Sutherland Cybersecurity and Privacy Insights Blog
content top

SEC Charges Investment Adviser with Failure to Adopt Required Cybersecurity Policies Prior to Breach

On September 22, the Securities and Exchange Commission (SEC) announced that it had entered into a settlement order with R.T. Jones Capital Equities Management, Inc., a St. Louis-based SEC registered investment adviser, for failure to establish required cybersecurity policies and procedures in advance of a breach. As a result of the firm’s failure to adopt reasonable cybersecurity...

NAIC Adopts New Cybersecurity Exam Tool

On September 21, the National Association of Insurance Commissioners IT Examination Working Group adopted amendments to the IT section of the Financial Condition Examiners Handbook to strengthen the Handbook’s already existing cybersecurity guidance. Charged with improving this guidance, the Working Group compared the Handbook’s guidance to the National Institute of Standards and...

They’re Baaaack . . . SECs Office of Compliance Inspections and Examinations Releases New Cybersecurity Risk Alert

Yesterday, the U.S. Securities and Exchange Commission (SEC) Office of Compliance Inspections and Examinations (OCIE) released a Risk Alert describing OCIE’s 2015 cybersecurity exam initiative.  [link to www.sec.gov/ocie/announcement/ocie-2015-cybersecurity-examination-initiative.pdf].  As the Risk Alert notes, OCIE’s new cybersecurity initiative builds on information OCIE learned from...

NAIC Cybersecurity Forum Focuses on Escalating Threats and Best Remediation Practices

On September 10, the National Association of Insurance Commissioners (NAIC) co-sponsored a cybersecurity forum at the Center for Strategic and International Studies in Washington, DC. Featuring an impressive line-up of senior government officials and knowledgeable experts, the forum aimed to increase understanding of the escalating threat environment, emerging best practices in cyber...

NIST Releases Access Management Guidance for Energy Companies

A division of the National Institute of Standards and Technology (NIST) has released draft guidance for energy companies to manage access to their networked resources, including industrial control systems and information technology. In the draft guidance, the National Cybersecurity Center of Excellence (NCCoE) offers step-by-step instructions to help energy companies address the risk...