ELTENI’S CYBER SCOOP

Latest News

July brings a heavy regulatory and enforcement docket for financial services and advisers. This issue covers the SEC’s continued focus on cybersecurity disclosure and Reg S-P amendments taking hold, a fresh wave of enforcement tied to incident-response and vendor-oversight failures, and the accelerating threat landscape driven by AI-enabled social engineering and third-party SaaS compromises. Client-facing takeaway: refresh your incident-response playbooks, revalidate vendor due diligence artifacts, and confirm Reg S-P written policies map cleanly to the 30-day customer notification standard.

REGULATORY CORNER

Reg S-P Amendments Move From “Prepare” to “Perform”

The SEC’s amended Regulation S-P compliance dates are now in the rear-view mirror for larger entities and closing in for smaller ones. Covered institutions — broker-dealers, investment companies, RIAs, and transfer agents — must maintain written incident-response programs, notify affected individuals of a breach of sensitive customer information as soon as practicable and no later than 30 days, and impose contractual/oversight requirements on service providers that receive customer information. Practically, this raises the bar on documented vendor due diligence, log retention, and forensic readiness — and it means “we’re still drafting” is no longer an acceptable answer during an exam.

Notes

Key questions firms may want to work through in advance of an incident include how the population of “affected individuals” would be identified and documented; when the notification clock would be treated as starting; how notification timing under Regulation S-P interacts with state breach notification statutes and other regulatory notification obligations; and what artifacts the firm relies on to evidence service-provider oversight. Vendor SOC 2 reports are one input to that oversight, but firms should assess whether additional diligence, contractual provisions, or ongoing monitoring are needed to meet the amended rule’s expectations.

ENFORCEMENT NEWS

Regulators Continue to Focus on Foundational Cybersecurity Controls

Cybersecurity-related enforcement activity from the SEC, NYDFS, and other regulators has continued to emphasize preventable control failures — including gaps in multi-factor authentication (MFA) coverage, stale access reviews, email security configuration weaknesses, and disclosures that regulators viewed as inaccurate or untimely. Resolutions have commonly combined monetary penalties with remediation undertakings such as independent consultant engagements, mandatory policy and procedure enhancements, and periodic reporting. The consistent theme across recent matters is that regulators expect firms to know their control environment, document it, and test it — and to disclose material cybersecurity events accurately and on the required timeline.

Notes

A useful reading of the current enforcement environment is that regulators are increasingly focused on program design and evidence — what a firm’s cybersecurity program looked like before an incident — rather than on the sophistication of any particular attack. Practical considerations for firms include: closing open findings from internal audits and penetration tests on a defined timeline; confirming MFA coverage across all remote-access paths, including legacy VPN, jump hosts, and administrative consoles; documenting the process by which cybersecurity events are assessed for materiality (including under Item 1.05 of Form 8-K for public companies and the applicable notification standards for advisers and broker-dealers); and ensuring board- and committee-level minutes reflect substantive discussion of cybersecurity risk, not only status reporting.

CYBER NEWS

Cybersecurity has never been more advanced.  So why are cyberattacks still succeeding?

AI is making cyber defenses stronger, but it may also be making it easier for criminals to launch attacks. Defenses advance; attackers still find the seams — and resilience keeps depending on fundamentals. The growing influence of AI means cybersecurity decisions can no longer be made solely within IT departments. Boards and business leaders will increasingly need to understand how AI is deployed, who is responsible for its actions, and what risks it introduces.

AI-Enabled Social Engineering Is a Growing Concern

Publicly reported incidents and threat-intelligence reporting from major vendors have highlighted an increase in social-engineering attacks that use generative AI, including voice cloning and synthetic videos to impersonate executives, employees, or trusted counterparties. Reported use cases include help-desk impersonation to reset credentials or MFA, fraudulent payment-instruction changes, and business email compromise variants that now extend to live audio and video calls. Firms may wish to evaluate whether helpdesk, treasury, and finance workflows designed for a pre-generative-AI environment remain fit for purpose.  Potentially useful mitigations include out-of-band callback verification; challenge-response protocols for high-value transactions; dual approval on changes to payment instructions and vendor bank details; and periodic training that addresses deep-fake and voice-cloning.

Third-Party and SaaS Concentration Risk Remains Elevated

Publicly disclosed incidents in the past several quarters have again highlighted the downstream impact of compromises at widely used SaaS platforms, identity providers, and other technology vendors, where a single compromise can expose data across many customer organizations. Reporting from several sources indicates continued attacker focus on OAuth tokens, service accounts, and administrative API keys — credentials that often bypass end-user MFA controls entirely.  Practical considerations for firms include maintaining an inventory of non-human identities (service principals, integration users, API keys); establishing a defined rotation cadence for secrets; requiring SaaS vendors to disclose security incidents within contractually specified timeframes; and confirming that vendor contracts and diligence artifacts reflect the amended Regulation S-P service-provider oversight expectations where applicable.