Increased focus on cybersecurity by the Security Exchange Commission’s (“SEC”) continues as it recently issued charges against Morgan Stanley Smith Barney (“Morgan Stanley”) for failing to adopt written policies and procedures reasonably designed to protect confidential client information. These charges stemmed from a cybersecurity breach which began in 2011 and continued until 2014, resulting in the misappropriation of confidential client information in over 730,000 client accounts.
Broker-dealers and investment advisers are required pursuant to Regulation S-P and comparable regulation of the Federal Trade Commission to adopt written policies and procedures reasonably designed to protect client records and information. These policies and procedures must address the administrative, technical, and physical safeguards in place, and must be reasonably designed to insure the security and confidentiality of client records and information, protect against unanticipated threats, and prevent unauthorized access.