Achievable logoAchievable logo
Series 63
Sign in
Sign up
Purchase
Textbook
Practice exams
Support
How it works
Resources
Exam catalog
Mountain with a flag at the peak
Textbook
Introduction
1. Definitions
2. Registration
3. Enforcement
4. Ethics
4.1 Compensation
4.2 Communications
4.3 Customer funds & securities
4.4 Unethical & criminal actions
4.5 Protecting vulnerable adults
4.6 Cybersecurity
Wrapping up
Achievable logoAchievable logo
4.6 Cybersecurity
Achievable Series 63
4. Ethics

Cybersecurity

7 min read
Font
Discuss
Share
Feedback

As registered persons continue to modernize their businesses, cybersecurity issues are becoming more common. Many firms now store customer records and sensitive documents digitally and in the cloud. Because hackers and other bad actors routinely try to steal identities and confidential information, financial institutions need clear ways to protect clients.

The North American Securities Administrators Association (NASAA) created a cybersecurity checklist to help investment advisers and investment adviser representatives (IARs) ensure the integrity of their systems.

*NASAA provides cybersecurity guidance for advisory firms, but doesn’t have much to say about broker-dealers. This difference comes from how each is regulated. Broker-dealers are regulated by both the Securities and Exchange Commission (SEC) (federal) and the state administrator. Because federal law generally supersedes state law, the SEC primarily provides cybersecurity guidance to broker-dealers. Since this is a state-based exam, that federal cybersecurity guidance for broker-dealers is generally not covered on the Series 63, but rules applicable to state-based advisers are tested - and other federal rules, like Regulation S-P below, are still fair game. The components of this chapter can be thought of as relevant to all registered persons.

Customer privacy under Regulation S-P

Cybersecurity is about keeping data safe from outside attackers. Privacy is a related but separate concern: what the firm itself is allowed to do with that data. The rule that governs it is the SEC’s Regulation S-P (Privacy of Consumer Financial Information), adopted under the Gramm-Leach-Bliley Act. It applies to broker-dealers and investment advisers alike, and it’s fair game on the Series 63 even though it’s a federal rule.

Definitions
Non-public personal information (NPI)
Information a firm learns through its relationship with a customer that isn’t otherwise publicly available. It includes Social Security and taxpayer identification numbers, account numbers, balances, and transaction history, suitability information such as net worth and investment objectives, and less obvious sources, like data a firm collects from visitors to its website.

Regulation S-P requires firms to protect a customer’s NPI in two ways:

  • Privacy notice: the firm must give the customer a notice describing what information it collects, how it uses that information, and with whom it shares it. The notice goes out when the account is opened, and again every year for as long as the relationship continues.
  • Opt-out opportunity: before sharing NPI with an unaffiliated third party, the firm must give the customer a reasonable, easy way to opt out - a check-off box on a form or in an email, for example, rather than requiring a mailed letter. Sharing NPI with the SEC, FINRA, the state administrator, or in response to a court order doesn’t require this opt-out opportunity.

A firm must also adopt written policies to safeguard customer records against unauthorized access - which is where the NASAA checklist below picks up.

We’ll use NASAA’s cybersecurity checklist to organize best practices. The document breaks cybersecurity into five categories:

  • Identify
  • Protect
  • Detect
  • Respond
  • Recover

Identify

The first step is identifying the cybersecurity risks the firm faces. You can’t protect against a threat you haven’t recognized.

NASAA recommends that firms perform risk assessments and designate specific people to handle cybersecurity issues if they arise. The checklist highlights these best practices:

  • Conduct frequent risk assessments (at least annually)
  • Risk assessment should include:
    • Review of data collected
    • Where data is stored
    • Identify if data is encrypted
  • Identify “insider” risks*
  • Identify potential third-party risks**
  • Determine if the firm enforces cybersecurity practices***
  • Identify internal points of contact in event of a cybersecurity event
  • Determine if the firm has proper hardware and software

*An “insider” risk refers to internal threats from disgruntled employees.

**Third parties are persons other than clients that may have access to confidential information. This could include outside vendors (e.g. a company that prints disbursement checks) and authorized parties (e.g. accountants, persons with power of attorney (POA)).

***Best practices involved with cybersecurity include frequent password changes, locking of devices, protocols for reporting stolen information, etc.

Protect

After identifying threats, the firm should protect its digital infrastructure. NASAA organizes this part of the checklist into several areas:

  • Email
  • Devices
  • Cloud storage
  • Firm websites
  • Custodians & third-party vendors
  • Encryption

Email
Firms should identify what information is transmitted via email and avoid sending sensitive information through unverified methods. If sensitive information must be sent, the firm should use an authentication system to verify the client. Employees should also understand whether emails are secured or unsecured.

Devices
Firms should know which devices (e.g. computers, phones) can access sensitive information and whether those devices are properly secured. Backups should be performed routinely and tested. Firms should also conduct routine audits of devices and establish protocols for the destruction of devices.

Use of cloud services
Registered persons should perform due diligence when hiring third-party vendors for cloud services. As part of that due diligence, confirm the vendor has safeguards in place and a documentation system for breaches.

Firm websites
Firms should identify who has access to the firm’s website. They should also determine whether client data is available on the website and, if so, ensure that information is secured.

Custodians & third party vendors
When an investment adviser uses an outside firm (e.g. broker-dealer or bank) to maintain custody of client accounts, due diligence should be performed on that firm’s cybersecurity system. This also applies to outside vendors that have access to sensitive client information (e.g. a company that prints client statements).

Encryption
Encryption is the process of encoding information so it can’t be read by hackers and other bad actors. Firms should use encryption when transmitting sensitive information over the internet.

Detect

Firms should have systems in place to detect cybersecurity issues when they occur. NASAA’s detection recommendations include:

  • The use of antivirus software
  • Antivirus software must be continually updated
  • Employees are trained on how to use cybersecurity software
  • Utilization of firewalls
  • Procedures in place to identify and alert personnel when cybersecurity events occur

Respond

If a cybersecurity event occurs, the firm should have protocols to respond appropriately. NASAA recommends putting these procedures in place:

  • Protocols for notification to the appropriate authorities
  • Protocols for notification to the press
  • Protocols for notification to impacted clients

Recover

After a cybersecurity event, the firm must work to recover and protect its digital infrastructure from further attacks. The following protocols should be implemented:

  • Determination of whether cybersecurity insurance should be obtained
  • Analysis of cybersecurity insurance if purchased
  • Ensure cybersecurity is not voided due to employee misconduct
  • Business continuity plan in place
  • Data retrieval program in place
  • Firm provides training on data recovery

Cybersecurity & Regulatory Framework

  • Broker-dealers regulated by SEC (federal) + state; federal law supersedes, so SEC covers BD cybersecurity (not tested on Series 63)
  • NASAA cybersecurity checklist applies to investment advisers/IARs (state-based, testable)
  • Regulation S-P (federal) applies to both BDs and IAs — fair game on exam

Customer Privacy under Regulation S-P

  • Governs privacy (firm’s use of data), separate from cybersecurity (protection from outside attack)
  • Adopted under Gramm-Leach-Bliley Act
  • Non-public personal information (NPI): SSNs, account numbers/balances, transaction history, suitability info, website visitor data
  • Requirements:
    • Privacy notice at account opening and annually thereafter
    • Opt-out opportunity before sharing NPI with unaffiliated third parties (easy method, e.g. checkbox)
    • No opt-out needed for sharing with SEC/FINRA/state administrator/court order
  • Firms must adopt written safeguard policies for records

NASAA Cybersecurity Checklist — Five Categories

  • Identify, Protect, Detect, Respond, Recover

Identify

  • Conduct risk assessments at least annually (review data collected, storage location, encryption status)
  • Identify insider risks (disgruntled employees) and third-party risks (vendors, POA holders, accountants)
  • Designate internal contacts for cybersecurity events; verify proper hardware/software and enforcement of practices

Protect

  • Email: verify sensitive info transmission, use authentication, know secured vs unsecured channels
  • Devices: know which devices access data, secure them, routine backups/audits, device destruction protocols
  • Cloud services: due diligence on vendor safeguards and breach documentation
  • Firm websites: control access, secure any client data displayed
  • Custodians/third-party vendors: due diligence on their cybersecurity systems
  • Encryption: encode transmitted sensitive info to block unauthorized access

Detect

  • Use continually updated antivirus software
  • Train employees on cybersecurity tools
  • Utilize firewalls
  • Have alert procedures for identifying cybersecurity events

Respond

  • Protocols for notifying authorities
  • Protocols for notifying press
  • Protocols for notifying impacted clients

Recover

  • Assess need for/analyze cybersecurity insurance
  • Ensure coverage isn’t voided by employee misconduct
  • Maintain business continuity plan and data retrieval program
  • Provide employee training on data recovery

Sign up for free to take 4 quiz questions on this topic

Previous
Next  | Wrapping up
All rights reserved ©2016 - 2026 Achievable, Inc.

Cybersecurity

As registered persons continue to modernize their businesses, cybersecurity issues are becoming more common. Many firms now store customer records and sensitive documents digitally and in the cloud. Because hackers and other bad actors routinely try to steal identities and confidential information, financial institutions need clear ways to protect clients.

The North American Securities Administrators Association (NASAA) created a cybersecurity checklist to help investment advisers and investment adviser representatives (IARs) ensure the integrity of their systems.

*NASAA provides cybersecurity guidance for advisory firms, but doesn’t have much to say about broker-dealers. This difference comes from how each is regulated. Broker-dealers are regulated by both the Securities and Exchange Commission (SEC) (federal) and the state administrator. Because federal law generally supersedes state law, the SEC primarily provides cybersecurity guidance to broker-dealers. Since this is a state-based exam, that federal cybersecurity guidance for broker-dealers is generally not covered on the Series 63, but rules applicable to state-based advisers are tested - and other federal rules, like Regulation S-P below, are still fair game. The components of this chapter can be thought of as relevant to all registered persons.

Customer privacy under Regulation S-P

Cybersecurity is about keeping data safe from outside attackers. Privacy is a related but separate concern: what the firm itself is allowed to do with that data. The rule that governs it is the SEC’s Regulation S-P (Privacy of Consumer Financial Information), adopted under the Gramm-Leach-Bliley Act. It applies to broker-dealers and investment advisers alike, and it’s fair game on the Series 63 even though it’s a federal rule.

Definitions
Non-public personal information (NPI)
Information a firm learns through its relationship with a customer that isn’t otherwise publicly available. It includes Social Security and taxpayer identification numbers, account numbers, balances, and transaction history, suitability information such as net worth and investment objectives, and less obvious sources, like data a firm collects from visitors to its website.

Regulation S-P requires firms to protect a customer’s NPI in two ways:

  • Privacy notice: the firm must give the customer a notice describing what information it collects, how it uses that information, and with whom it shares it. The notice goes out when the account is opened, and again every year for as long as the relationship continues.
  • Opt-out opportunity: before sharing NPI with an unaffiliated third party, the firm must give the customer a reasonable, easy way to opt out - a check-off box on a form or in an email, for example, rather than requiring a mailed letter. Sharing NPI with the SEC, FINRA, the state administrator, or in response to a court order doesn’t require this opt-out opportunity.

A firm must also adopt written policies to safeguard customer records against unauthorized access - which is where the NASAA checklist below picks up.

We’ll use NASAA’s cybersecurity checklist to organize best practices. The document breaks cybersecurity into five categories:

  • Identify
  • Protect
  • Detect
  • Respond
  • Recover

Identify

The first step is identifying the cybersecurity risks the firm faces. You can’t protect against a threat you haven’t recognized.

NASAA recommends that firms perform risk assessments and designate specific people to handle cybersecurity issues if they arise. The checklist highlights these best practices:

  • Conduct frequent risk assessments (at least annually)
  • Risk assessment should include:
    • Review of data collected
    • Where data is stored
    • Identify if data is encrypted
  • Identify “insider” risks*
  • Identify potential third-party risks**
  • Determine if the firm enforces cybersecurity practices***
  • Identify internal points of contact in event of a cybersecurity event
  • Determine if the firm has proper hardware and software

*An “insider” risk refers to internal threats from disgruntled employees.

**Third parties are persons other than clients that may have access to confidential information. This could include outside vendors (e.g. a company that prints disbursement checks) and authorized parties (e.g. accountants, persons with power of attorney (POA)).

***Best practices involved with cybersecurity include frequent password changes, locking of devices, protocols for reporting stolen information, etc.

Protect

After identifying threats, the firm should protect its digital infrastructure. NASAA organizes this part of the checklist into several areas:

  • Email
  • Devices
  • Cloud storage
  • Firm websites
  • Custodians & third-party vendors
  • Encryption

Email
Firms should identify what information is transmitted via email and avoid sending sensitive information through unverified methods. If sensitive information must be sent, the firm should use an authentication system to verify the client. Employees should also understand whether emails are secured or unsecured.

Devices
Firms should know which devices (e.g. computers, phones) can access sensitive information and whether those devices are properly secured. Backups should be performed routinely and tested. Firms should also conduct routine audits of devices and establish protocols for the destruction of devices.

Use of cloud services
Registered persons should perform due diligence when hiring third-party vendors for cloud services. As part of that due diligence, confirm the vendor has safeguards in place and a documentation system for breaches.

Firm websites
Firms should identify who has access to the firm’s website. They should also determine whether client data is available on the website and, if so, ensure that information is secured.

Custodians & third party vendors
When an investment adviser uses an outside firm (e.g. broker-dealer or bank) to maintain custody of client accounts, due diligence should be performed on that firm’s cybersecurity system. This also applies to outside vendors that have access to sensitive client information (e.g. a company that prints client statements).

Encryption
Encryption is the process of encoding information so it can’t be read by hackers and other bad actors. Firms should use encryption when transmitting sensitive information over the internet.

Detect

Firms should have systems in place to detect cybersecurity issues when they occur. NASAA’s detection recommendations include:

  • The use of antivirus software
  • Antivirus software must be continually updated
  • Employees are trained on how to use cybersecurity software
  • Utilization of firewalls
  • Procedures in place to identify and alert personnel when cybersecurity events occur

Respond

If a cybersecurity event occurs, the firm should have protocols to respond appropriately. NASAA recommends putting these procedures in place:

  • Protocols for notification to the appropriate authorities
  • Protocols for notification to the press
  • Protocols for notification to impacted clients

Recover

After a cybersecurity event, the firm must work to recover and protect its digital infrastructure from further attacks. The following protocols should be implemented:

  • Determination of whether cybersecurity insurance should be obtained
  • Analysis of cybersecurity insurance if purchased
  • Ensure cybersecurity is not voided due to employee misconduct
  • Business continuity plan in place
  • Data retrieval program in place
  • Firm provides training on data recovery
Key points

Cybersecurity & Regulatory Framework

  • Broker-dealers regulated by SEC (federal) + state; federal law supersedes, so SEC covers BD cybersecurity (not tested on Series 63)
  • NASAA cybersecurity checklist applies to investment advisers/IARs (state-based, testable)
  • Regulation S-P (federal) applies to both BDs and IAs — fair game on exam

Customer Privacy under Regulation S-P

  • Governs privacy (firm’s use of data), separate from cybersecurity (protection from outside attack)
  • Adopted under Gramm-Leach-Bliley Act
  • Non-public personal information (NPI): SSNs, account numbers/balances, transaction history, suitability info, website visitor data
  • Requirements:
    • Privacy notice at account opening and annually thereafter
    • Opt-out opportunity before sharing NPI with unaffiliated third parties (easy method, e.g. checkbox)
    • No opt-out needed for sharing with SEC/FINRA/state administrator/court order
  • Firms must adopt written safeguard policies for records

NASAA Cybersecurity Checklist — Five Categories

  • Identify, Protect, Detect, Respond, Recover

Identify

  • Conduct risk assessments at least annually (review data collected, storage location, encryption status)
  • Identify insider risks (disgruntled employees) and third-party risks (vendors, POA holders, accountants)
  • Designate internal contacts for cybersecurity events; verify proper hardware/software and enforcement of practices

Protect

  • Email: verify sensitive info transmission, use authentication, know secured vs unsecured channels
  • Devices: know which devices access data, secure them, routine backups/audits, device destruction protocols
  • Cloud services: due diligence on vendor safeguards and breach documentation
  • Firm websites: control access, secure any client data displayed
  • Custodians/third-party vendors: due diligence on their cybersecurity systems
  • Encryption: encode transmitted sensitive info to block unauthorized access

Detect

  • Use continually updated antivirus software
  • Train employees on cybersecurity tools
  • Utilize firewalls
  • Have alert procedures for identifying cybersecurity events

Respond

  • Protocols for notifying authorities
  • Protocols for notifying press
  • Protocols for notifying impacted clients

Recover

  • Assess need for/analyze cybersecurity insurance
  • Ensure coverage isn’t voided by employee misconduct
  • Maintain business continuity plan and data retrieval program
  • Provide employee training on data recovery

More from Ethics

  • Compensation
  • Protecting vulnerable adults