{"id":19665,"date":"2025-07-07T13:54:27","date_gmt":"2025-07-07T17:54:27","guid":{"rendered":"https:\/\/www.elteni.com\/?p=19665"},"modified":"2025-07-07T13:54:27","modified_gmt":"2025-07-07T17:54:27","slug":"2025-july-newsletter","status":"publish","type":"post","link":"https:\/\/www.elteni.com\/insights\/?p=19665","title":{"rendered":"2025 July Newsletter"},"content":{"rendered":"<h1>ELTENI&#8217;S CYBER SCOOP<\/h1>\n<h3>Latest News<\/h3>\n<p>In this newsletter, we focus on retraction of the proposed cybersecurity rules for investment advisers, the continued requirement for disclosure and transparency of cyber incidents and building trust through effective cybersecurity.<\/p>\n<h1>REGULATORY CORNER<\/h1>\n<p><strong>SEC withdraws cyber rules for investment companies, advisers<\/strong><\/p>\n<p><em>The Securities and Exchange Commission is pulling back cybersecurity regulations for investment companies and investment advisers proposed under the Biden administration.<\/em><\/p>\n<p><em>In a notice in early June 2025, the SEC said it was withdrawing pending rules requiring those companies and advisers to develop written policies to address cybersecurity risks and report significant cybersecurity incidents to the commission. It also would have required them to report on the last two fiscal years\u2019 cyber incidents and risks in a publicly available registration form.\u00a0 <\/em><\/p>\n<p><em>In 2023, the commission re-opened the public comment period on the rule, saying that it \u201cwill allow interested persons additional time to analyze the issues and prepare comments in light of other regulatory developments, including whether there would be any effects of other Commission proposals related to cybersecurity risk management and disclosure that the Commission should consider. \u201c<\/em><\/p>\n<h3>Notes<\/h3>\n<p>The SEC\u2019s quiet retreat from its proposed cybersecurity rule for investment advisers and funds is a step backward. While other industries have baseline standards\u2014PCI-DSS for payments, HIPAA for healthcare, CMMC for federal contractors\u2014finance remains exposed. Financial professionals handle sensitive investor data and assets; as such, cybersecurity should not be optional\u2014it should be a core part of fiduciary duty. Without minimum controls like MFA, vendor risk assessments, or incident reporting, firms are left vulnerable to phishing, ransomware, and supply chain attacks.<\/p>\n<p>The SEC is falling out of sync with regulators like The New York Department of Financial Services (NYDFS) and global efforts like the EU\u2019s Digital Operational Resilience Act (DORA), which promote proactive risk-based approaches to cyber governance. This lack of standardization increases investor risk and drives up breach-related costs that ultimately fall on clients. The SEC\u2019s decision sends the wrong message: that cybersecurity is a \u201cnice to have.\u201d It\u2019s not. It\u2019s essential.<\/p>\n<p><a href=\"https:\/\/cyberscoop.com\/sec-withdrawals-cyber-rules-for-investment-companies-advisers\/\">SEC Withdraws cyber rules for investment companies, advisers | CyberScoop<\/a><\/p>\n<p>&nbsp;<\/p>\n<h1>ENFORCEMENT NEWS<\/h1>\n<p><strong>Hotel asset manager settles with SEC over cyber breach misreporting<\/strong><\/p>\n<p><em>The SEC stated in its complaint that Ashford, a Dallas based investment adviser, was the victim of a cyberattack in September 2024, instigated by an unnamed \u201cforeign threat actor.\u201d That attack exfiltrated 12 terabytes of data from Ashford\u2019s servers, and locked servers containing data for at least 22 of its hotel clients.<\/em><\/p>\n<p><em>\u00a0<\/em><em>The SEC accused Ashford of negligence in its failure to perceive the customer information leak, stating that it knew, or should have known, that the data had been compromised. The agency based that determination on a finding that Ashford could have easily verified that customer information was stolen had it reviewed the file trees for the compromised data<\/em><\/p>\n<h3>Notes<\/h3>\n<p>The SEC\u2019s enforcement action against asset manager Ashford for misrepresenting the scope of a ransomware breach affecting over 46,000 individuals was, on the surface, a necessary step. However, the mere $115,231 penalty feels incongruent with the severity of the infraction. Given the persistence of cybersecurity incidents and the heightened sensitivity to data protection, the Commission has made it clear that timeliness and transparency in breach notification are not optional. Ashford\u2019s delayed and incomplete disclosure violated that mandate, potentially depriving clients, investors, and regulators of critical information needed to assess risk. While the enforcement action reaffirms the SEC\u2019s commitment to cyber transparency, the nominal fine sends a conflicting message: that underreporting a cyber event might be met with a regulatory slap on the wrist rather than a meaningful deterrent. For alternative investment firms\u2014often lean on compliance staff and heavy on sensitive client data\u2014this is the wrong incentive structure.<\/p>\n<p>Real deterrence requires real consequence. The SEC should pair regulatory clarity with enforcement teeth. Otherwise, firms may see breach disclosure as a cost-benefit calculation rather than a fiduciary obligation.<\/p>\n<p><a href=\"https:\/\/www.grip.globalrelay.com\/hotel-asset-manager-settles-with-sec-over-cyber-breach-misreporting\/\">Hotel asset manager settles with SEC over cyber breach misreporting | Grip<\/a><\/p>\n<p>&nbsp;<\/p>\n<h1>CYBER NEWS<\/h1>\n<p><a href=\"https:\/\/www.reuters.com\/business\/coinbase-says-cyber-criminals-stole-account-data-some-customers-2025-05-15\/\">Coinbase warns of up to $400 million hit from cyberattack | Reuters.com<\/a><\/p>\n<p>The company received an email from an unknown threat actor on May 11, claiming to have information about certain customer accounts as well as internal documents. Hackers had paid multiple contractors and employees working in support roles outside the U.S. to collect information. The company had fired those involved, it said. While some data \u2014 including names, addresses and emails \u2014 was stolen, the hackers did not get access to login credentials or passwords, Coinbase said. It would, however, reimburse customers who were tricked into sending funds to the attackers.<\/p>\n<p><a href=\"https:\/\/www.forbes.com\/councils\/forbestechcouncil\/2025\/05\/08\/building-trust-through-effective-cybersecurity\/\">Building Trust Through Effective Cybersecurity | Forbes.com<\/a><\/p>\n<p>When cybersecurity measures are correctly implemented, they mitigate risks like data breaches, ransomware and unauthorized access. This protection creates confidence among users, partners and stakeholders, trusting that their private and sensitive information is safe and systems will function securely. Cybersecurity is not just about protection; it&#8217;s about empowerment. It transforms risk from a source of fear and uncertainty into a foundation for trust and resilience.<\/p>\n<p><a href=\"https:\/\/cyberscoop.com\/financial-deepfake-scams-targeted-in-bipartisan-senate-bill\/\">Financial deepfake scams targeted in bipartisan Senate bill | CyberScoop<\/a><\/p>\n<p>According to Federal Trade Commission data, fraudsters stole more than $12.5 billion from consumers last year, a 25% jump from 2023. AI tools are increasingly being used by scam artists to craft emails, text messages and phone calls that trick people into thinking their loved ones are in danger and that payment is the only way to guarantee their safety.<\/p>\n<p><a href=\"https:\/\/cyberscoop.com\/citrix-zero-day-netscaler\/\">Citrix users hit by actively exploited zero-day vulnerability | CyberScoop<\/a><\/p>\n<p>Citrix has disclosed an actively exploited zero-day vulnerability affecting multiple versions of NetScaler products, an alarming development from a vendor that\u2019s been widely targeted in previous attack sprees. The zero-day (CVE-2025-6543) was disclosed by Citrix nine days after it issued a security bulletin for a pair of defects (CVE-2025-5777 and CVE-2025-5349) in the same products. All three vulnerabilities affect the company\u2019s networking security appliance NetScaler ADC and its virtual private network NetScaler Gateway.<\/p>\n<h1>DECODE THE TERMS<\/h1>\n<p><strong>C2 (Command and Control) \u2013 <\/strong>Infrastructure used by attackers to remotely control compromised systems.<\/p>\n<p><strong>DLL Injection \u2013 <\/strong>A technique for executing malicious code within another process by injecting a Dynamic Link Library (DLL).<\/p>\n<p><strong>Sinkhole \u2013 <\/strong>A security mechanism to redirect malicious traffic away from a targeted system.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ELTENI&#8217;S CYBER SCOOP Latest News In this newsletter, we focus on retraction of the proposed cybersecurity rules for investment advisers, the continued requirement for disclosure and transparency of [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":19667,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[114,67,134,113,68,3,133,135,101,102,103,18,140,136,47,17,25,106,137,89,138,90,127,19],"tags":[],"class_list":["post-19665","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-alternative-asset-management","category-awareness","category-breaches","category-business-email-compromise","category-cloud","category-cyber","category-finra","category-ftc","category-hackers","category-hedge-fund","category-investment-adviser","category-microsoft","category-newsletter","category-nydfs","category-ocie","category-password","category-pii","category-private-equity","category-private-funds","category-regulatory","category-rules","category-sec","category-technology","category-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>2025 July Newsletter - Insights<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.elteni.com\/insights\/?p=19665\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"2025 July Newsletter - Insights\" \/>\n<meta property=\"og:description\" content=\"ELTENI&#8217;S CYBER SCOOP Latest News In this newsletter, we focus on retraction of the proposed cybersecurity rules for investment advisers, the continued requirement for disclosure and transparency of [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.elteni.com\/insights\/?p=19665\" \/>\n<meta property=\"og:site_name\" content=\"Insights\" \/>\n<meta property=\"article:published_time\" content=\"2025-07-07T17:54:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2025\/07\/July-2025-Cover-Image.png\" \/>\n\t<meta property=\"og:image:width\" content=\"818\" \/>\n\t<meta property=\"og:image:height\" content=\"1059\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"dtuck\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"dtuck\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19665#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19665\"},\"author\":{\"name\":\"dtuck\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\"},\"headline\":\"2025 July Newsletter\",\"datePublished\":\"2025-07-07T17:54:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19665\"},\"wordCount\":1043,\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19665#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/July-2025-Cover-Image.png\",\"articleSection\":[\"Alternative Asset Management\",\"Awareness\",\"Breaches\",\"Business Email Compromise\",\"Cloud\",\"Cyber\",\"FINRA\",\"FTC\",\"Hackers\",\"Hedge Fund\",\"Investment Adviser\",\"Microsoft\",\"Newsletter\",\"NYDFS\",\"OCIE\",\"Password\",\"PII\",\"Private Equity\",\"Private Funds\",\"Regulatory\",\"Rules\",\"SEC\",\"Technology\",\"Vulnerability\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19665\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19665\",\"name\":\"2025 July Newsletter - Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19665#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19665#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/July-2025-Cover-Image.png\",\"datePublished\":\"2025-07-07T17:54:27+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19665#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19665\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19665#primaryimage\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/July-2025-Cover-Image.png\",\"contentUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/July-2025-Cover-Image.png\",\"width\":818,\"height\":1059},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19665#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.elteni.com\\\/insights\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"2025 July Newsletter\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/\",\"name\":\"Insights\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\",\"name\":\"dtuck\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"caption\":\"dtuck\"},\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?author=3\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"2025 July Newsletter - Insights","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.elteni.com\/insights\/?p=19665","og_locale":"en_US","og_type":"article","og_title":"2025 July Newsletter - Insights","og_description":"ELTENI&#8217;S CYBER SCOOP Latest News In this newsletter, we focus on retraction of the proposed cybersecurity rules for investment advisers, the continued requirement for disclosure and transparency of [&hellip;]","og_url":"https:\/\/www.elteni.com\/insights\/?p=19665","og_site_name":"Insights","article_published_time":"2025-07-07T17:54:27+00:00","og_image":[{"width":818,"height":1059,"url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2025\/07\/July-2025-Cover-Image.png","type":"image\/png"}],"author":"dtuck","twitter_card":"summary_large_image","twitter_misc":{"Written by":"dtuck","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.elteni.com\/insights\/?p=19665#article","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19665"},"author":{"name":"dtuck","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b"},"headline":"2025 July Newsletter","datePublished":"2025-07-07T17:54:27+00:00","mainEntityOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19665"},"wordCount":1043,"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19665#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2025\/07\/July-2025-Cover-Image.png","articleSection":["Alternative Asset Management","Awareness","Breaches","Business Email Compromise","Cloud","Cyber","FINRA","FTC","Hackers","Hedge Fund","Investment Adviser","Microsoft","Newsletter","NYDFS","OCIE","Password","PII","Private Equity","Private Funds","Regulatory","Rules","SEC","Technology","Vulnerability"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.elteni.com\/insights\/?p=19665","url":"https:\/\/www.elteni.com\/insights\/?p=19665","name":"2025 July Newsletter - Insights","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19665#primaryimage"},"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19665#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2025\/07\/July-2025-Cover-Image.png","datePublished":"2025-07-07T17:54:27+00:00","author":{"@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b"},"breadcrumb":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19665#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.elteni.com\/insights\/?p=19665"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.elteni.com\/insights\/?p=19665#primaryimage","url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2025\/07\/July-2025-Cover-Image.png","contentUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2025\/07\/July-2025-Cover-Image.png","width":818,"height":1059},{"@type":"BreadcrumbList","@id":"https:\/\/www.elteni.com\/insights\/?p=19665#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.elteni.com\/insights"},{"@type":"ListItem","position":2,"name":"2025 July Newsletter"}]},{"@type":"WebSite","@id":"https:\/\/www.elteni.com\/insights\/#website","url":"https:\/\/www.elteni.com\/insights\/","name":"Insights","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.elteni.com\/insights\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b","name":"dtuck","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","caption":"dtuck"},"url":"https:\/\/www.elteni.com\/insights\/?author=3"}]}},"_links":{"self":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19665","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19665"}],"version-history":[{"count":0,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19665\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/media\/19667"}],"wp:attachment":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19665"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19665"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19665"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}