{"id":19606,"date":"2024-06-07T12:02:41","date_gmt":"2024-06-07T16:02:41","guid":{"rendered":"https:\/\/www.elteni.com\/?p=19606"},"modified":"2024-06-07T12:02:41","modified_gmt":"2024-06-07T16:02:41","slug":"2024-june-newsletter","status":"publish","type":"post","link":"https:\/\/www.elteni.com\/insights\/?p=19606","title":{"rendered":"2024 June Newsletter"},"content":{"rendered":"<h1>ELTENI&#8217;S CYBER SCOOP<\/h1>\n<h3>Latest News<\/h3>\n<p>In this newsletter, we highlight the SEC\u2019s rule amendments to Regulation S-P as well as the importance of prompt reporting of cyber incidents.<\/p>\n<h1>REGULATORY CORNER<\/h1>\n<p><strong>SEC Adopts Rule Amendments to Regulations S-P to Enhance Protection of Customer Information<\/strong><\/p>\n<p><em>The amendments require covered institutions to develop, implement, and maintain written policies and procedures for an incident response program that is reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. These amendments also require that the response program include procedures for, with certain limited exceptions, covered institutions to provide notice to individuals whose sensitive customer information was or is reasonably likely to have been accessed or used without authorization.<\/em><\/p>\n<h3>Notes<\/h3>\n<p>In today&#8217;s digital age, where sensitive information is frequently transmitted and stored during routine financial transactions, ensuring the confidentiality and integrity of such data is paramount for financial institutions. Prompted by technological advancements and escalating cyber risks, the amendment to the Regulation S-P rule aims to strengthen the safeguarding of consumers&#8217; nonpublic personal information. This amendment aligns with other approved and pending rules for financial services firms that aim to enhance cybersecurity protections for themselves and their clients. Highlighted among these initiatives is proactive Incident Response Planning and notification protocols.<\/p>\n<p><a href=\"https:\/\/www.sec.gov\/news\/press-release\/2024-58\">SEC Adopts Rule Amendments to Regulation S-P to Enhance Protection of Customer Information | SEC.gov<\/a><\/p>\n<h1>ENFORCEMENT NEWS<\/h1>\n<p><strong>SEC Charges Intercontinental Exchange and Nine Affiliates Including the New York Stock Exchange with Failing to Inform the Commission of a Cyber Intrusion<\/strong><\/p>\n<p><em>The Securities and Exchange Commission announced that The Intercontinental Exchange, Inc. (ICE) agreed to pay a $10 million penalty to settle charges that it caused the failure of nine wholly owned subsidiaries, including the New York Stock Exchange, to timely inform the SEC of a cyber intrusion as required by Regulation Systems Compliance and Integrity (Regulation SCI).<\/em><\/p>\n<p><em>\u00a0<\/em><em>According to the SEC\u2019s order, in April 2021, a third-party informed ICE that ICE was potentially impacted by a system intrusion involving a previously unknown vulnerability in ICE\u2019s virtual private network (VPN).<\/em><\/p>\n<h3>Notes<\/h3>\n<p>This incident underscores the critical need for financial institutions to maintain a robust cybersecurity program that proactively addresses vulnerabilities and potential threats. It is essential to report these threats promptly, in compliance with regulatory obligations, to ensure a comprehensive defense strategy. A swift and effective response not only mitigates damage and prevents escalation but can also significantly limit the financial impact on the firm and its clients, protecting their assets and maintaining operational continuity. Moreover, timely incident management preserves trust with stakeholders, demonstrating the institution&#8217;s commitment to safeguarding sensitive information. This trust is crucial for maintaining client relationships and reputation in the industry. Proactive cybersecurity measures also encourage continuous learning and improvement within the organization, fostering a culture of vigilance and preparedness.<\/p>\n<p>Enhancing overall cyber resilience involves not just reactive measures, but also preventive strategies, regular risk assessments, and employee training. By integrating these elements into a cohesive cybersecurity program, financial institutions can better anticipate and counteract emerging threats, thereby ensuring long-term stability and security in an increasingly digital financial landscape.<\/p>\n<p><a href=\"https:\/\/www.sec.gov\/news\/press-release\/2024-63?utm_medium=email&amp;utm_source=govdelivery\">SEC Charges Intercontinental Exchange and Nine Affiliates Including the New York Stock Exchange with Failing to Inform the Commission of a Cyber Intrusion | SEC.gov<\/a><\/p>\n<h1>CYBER NEWS<\/h1>\n<p><u><a href=\"https:\/\/www.cnbc.com\/2024\/05\/21\/family-offices-target-cyber-hacks-ransomware.html\">Family offices become prime targets for cyber hacks and ransomware | CNBC<\/a><\/u><\/p>\n<p>Family offices are increasingly targeted by cybercriminals, with many lacking the necessary staff and technology for defense, according to a survey by Dentons. 79% of North American family offices believe cyberattack risks have significantly increased. In 2023, 25% reported a cyberattack, up from 17% in 2020, and 50% know another family office that has been attacked. Despite this, less than a third have well-developed cyber risk management processes, and only 29% consider their staff training programs sufficient.<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2024\/05\/google-detects-4th-chrome-zero-day-in.html\">Update Chrome Browser Now: 4th Zero-Day Exploit Discovered in May 2024 | The Hacker News<\/a><\/p>\n<p>Google recently addresses a high-severity security flaw in its Chrome browser, designated CVE-2024-5274, which was actively exploited by many individuals. The vulnerability is a type of confusion bug in the V8 JavaScript and Web Assembly engine. This vulnerability allows threat actors to execute arbitrary code by accessing resources with incompatible types, potentially leading to out-of-bound memory access and system crashes. This marks the fourth zero-day patched by Google in the last month.<\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/scammers-fake-docusign-templates-blackmail-steal-companies\">Scammers Fake DocuSign Templates to Blackmail &amp; Steal from Companies | Dark Reading<\/a><\/p>\n<p>The rise in phishing emails impersonating DocuSign has been attributed to a thriving underground market for fake templates and login credentials. DocuSign\u2019s popularity, along with its generic email format, makes it an easy target for attackers. Attackers can purchase ready-made templates for as low as $10 and buy stolen login credentials. To mitigate these threats, remain vigilant for suspicious email characteristics, such as unfamiliar senders or links, and to verify the legitimacy of unexpected documents with the sender directly.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2024\/05\/is-your-computer-part-of-the-largest-botnet-ever\/\">Is Your Computer Part of \u2018The Largest Botnet Ever?\u2019 | Krebs on Security<\/a><\/p>\n<p>The U.S. Department of Justice (DOJ) was able to arrest the individual behind a service deemed \u201clikely the world\u2019s largest botnet ever\u201d by the FBI. The online anonymity service called 911 S5 exploited compromised computers running various free VPN products to facilitate fraudulent activities. The service allowed cybercriminals to route their internet traffic anonymously through compromised computers. It is advised for internet users to check whether their computers may be part of the 911 s5 botnet since more than 19 million computers were affected.<\/p>\n<h1>DECODE THE TERMS<\/h1>\n<p><strong>Exploit<\/strong>\u2013 a program, or piece of code, designed to find and take advantage of a security flaw or vulnerability in an application or computer system, typically for malicious purposes.<\/p>\n<p><strong>Threat- <\/strong>a malicious act that seeks to damage data, steal data, or disrupt computing systems.<\/p>\n<p><strong>VPN <\/strong>(Virtual Private Network)<strong> \u2013 <\/strong>encrypts internet traffic and routes it through the VPN provider\u2019s server before connecting to a website or another online service.<\/p>\n<p><strong>Botnet<\/strong>&#8211; a network of private computers infected with malware and controlled by hackers remotely.<\/p>\n<p><strong>Incident- <\/strong>a digital or physical breach that threatens the confidentiality, integrity, or availability of an organization\u2019s information systems or sensitive data.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ELTENI&#8217;S CYBER SCOOP Latest News In this newsletter, we highlight the SEC\u2019s rule amendments to Regulation S-P as well as the importance of prompt reporting of cyber incidents. [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":19608,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[114,67,134,113,68,3,133,135,101,102,103,18,140,136,47,17,25,106,137,89,138,90,127,19],"tags":[],"class_list":["post-19606","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-alternative-asset-management","category-awareness","category-breaches","category-business-email-compromise","category-cloud","category-cyber","category-finra","category-ftc","category-hackers","category-hedge-fund","category-investment-adviser","category-microsoft","category-newsletter","category-nydfs","category-ocie","category-password","category-pii","category-private-equity","category-private-funds","category-regulatory","category-rules","category-sec","category-technology","category-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>2024 June Newsletter - Insights<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.elteni.com\/insights\/?p=19606\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"2024 June Newsletter - Insights\" \/>\n<meta property=\"og:description\" content=\"ELTENI&#8217;S CYBER SCOOP Latest News In this newsletter, we highlight the SEC\u2019s rule amendments to Regulation S-P as well as the importance of prompt reporting of cyber incidents. [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.elteni.com\/insights\/?p=19606\" \/>\n<meta property=\"og:site_name\" content=\"Insights\" \/>\n<meta property=\"article:published_time\" content=\"2024-06-07T16:02:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/06\/June-Newsletter-Thumbnail.png\" \/>\n\t<meta property=\"og:image:width\" content=\"816\" \/>\n\t<meta property=\"og:image:height\" content=\"1054\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"dtuck\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"dtuck\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19606#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19606\"},\"author\":{\"name\":\"dtuck\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\"},\"headline\":\"2024 June Newsletter\",\"datePublished\":\"2024-06-07T16:02:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19606\"},\"wordCount\":1007,\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19606#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2024\\\/06\\\/June-Newsletter-Thumbnail.png\",\"articleSection\":[\"Alternative Asset Management\",\"Awareness\",\"Breaches\",\"Business Email Compromise\",\"Cloud\",\"Cyber\",\"FINRA\",\"FTC\",\"Hackers\",\"Hedge Fund\",\"Investment Adviser\",\"Microsoft\",\"Newsletter\",\"NYDFS\",\"OCIE\",\"Password\",\"PII\",\"Private Equity\",\"Private Funds\",\"Regulatory\",\"Rules\",\"SEC\",\"Technology\",\"Vulnerability\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19606\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19606\",\"name\":\"2024 June Newsletter - Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19606#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19606#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2024\\\/06\\\/June-Newsletter-Thumbnail.png\",\"datePublished\":\"2024-06-07T16:02:41+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19606#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19606\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19606#primaryimage\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2024\\\/06\\\/June-Newsletter-Thumbnail.png\",\"contentUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2024\\\/06\\\/June-Newsletter-Thumbnail.png\",\"width\":816,\"height\":1054},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19606#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.elteni.com\\\/insights\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"2024 June Newsletter\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/\",\"name\":\"Insights\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\",\"name\":\"dtuck\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"caption\":\"dtuck\"},\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?author=3\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"2024 June Newsletter - Insights","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.elteni.com\/insights\/?p=19606","og_locale":"en_US","og_type":"article","og_title":"2024 June Newsletter - Insights","og_description":"ELTENI&#8217;S CYBER SCOOP Latest News In this newsletter, we highlight the SEC\u2019s rule amendments to Regulation S-P as well as the importance of prompt reporting of cyber incidents. [&hellip;]","og_url":"https:\/\/www.elteni.com\/insights\/?p=19606","og_site_name":"Insights","article_published_time":"2024-06-07T16:02:41+00:00","og_image":[{"width":816,"height":1054,"url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/06\/June-Newsletter-Thumbnail.png","type":"image\/png"}],"author":"dtuck","twitter_card":"summary_large_image","twitter_misc":{"Written by":"dtuck","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.elteni.com\/insights\/?p=19606#article","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19606"},"author":{"name":"dtuck","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b"},"headline":"2024 June Newsletter","datePublished":"2024-06-07T16:02:41+00:00","mainEntityOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19606"},"wordCount":1007,"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19606#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/06\/June-Newsletter-Thumbnail.png","articleSection":["Alternative Asset Management","Awareness","Breaches","Business Email Compromise","Cloud","Cyber","FINRA","FTC","Hackers","Hedge Fund","Investment Adviser","Microsoft","Newsletter","NYDFS","OCIE","Password","PII","Private Equity","Private Funds","Regulatory","Rules","SEC","Technology","Vulnerability"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.elteni.com\/insights\/?p=19606","url":"https:\/\/www.elteni.com\/insights\/?p=19606","name":"2024 June Newsletter - Insights","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19606#primaryimage"},"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19606#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/06\/June-Newsletter-Thumbnail.png","datePublished":"2024-06-07T16:02:41+00:00","author":{"@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b"},"breadcrumb":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19606#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.elteni.com\/insights\/?p=19606"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.elteni.com\/insights\/?p=19606#primaryimage","url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/06\/June-Newsletter-Thumbnail.png","contentUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/06\/June-Newsletter-Thumbnail.png","width":816,"height":1054},{"@type":"BreadcrumbList","@id":"https:\/\/www.elteni.com\/insights\/?p=19606#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.elteni.com\/insights"},{"@type":"ListItem","position":2,"name":"2024 June Newsletter"}]},{"@type":"WebSite","@id":"https:\/\/www.elteni.com\/insights\/#website","url":"https:\/\/www.elteni.com\/insights\/","name":"Insights","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.elteni.com\/insights\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b","name":"dtuck","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","caption":"dtuck"},"url":"https:\/\/www.elteni.com\/insights\/?author=3"}]}},"_links":{"self":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19606","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19606"}],"version-history":[{"count":0,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19606\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/media\/19608"}],"wp:attachment":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19606"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19606"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19606"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}