ARTICLE
16 July 2020

OCIE Warns Of Heightened Ransomware Risks

HL
Hogan Lovells Cadwalader

Contributor

Hogan Lovells Cadwalader is a global law firm trusted by clients to deliver on complex, high-stakes matters.

Operating at the intersection of business, finance, and government, we bring an unwavering commitment to client service and the decisive counsel that helps clients achieve exceptional results.

Consistently recognized for innovation across legal services, we combine sharp judgment with deep commercial perspective and intellectual rigor to address critical, cutting-edge challenges.

With 3,100 lawyers worldwide, we offer global scale with strong local insight in the markets that matter most. Our commitment extends beyond client work through pro bono activities, community investment, and responsible business practices.

The Office of Compliance Inspections and Examinations ("OCIE") alerted market participants to reports of sophisticated ransomware attacks targeting SEC registrants and their service providers.
United States Technology

The Office of Compliance Inspections and Examinations ("OCIE") alerted market participants to reports of sophisticated ransomware attacks targeting SEC registrants and their service providers.

In a Risk Alert, OCIE defined ransomware as a "type of malware designed to provide an unauthorized actor access to institutions' systems and to deny the institutions use of those systems until a ransom is paid." Ransomware perpetrators typically demand ransom to "maintain the integrity and/or confidentiality of customer data or for the return of control over registrant systems," OCIE said.

OCIE recommended that registrants and other market participants monitor the cybersecurity alerts released by the Department of Homeland Security Cybersecurity and Infrastructure Security Agency. OCIE also outlined the following measures that registrants may take to reduce ransomware risks:

  • periodically assess and test policies for responding to ransomware attacks;
  • evaluate the firm's ability to maintain operations and restore systems after an attack;
  • provide employee training, including on how to identify phishing emails;
  • implement programs that scan for and patch vulnerabilities;
  • manage user access to systems; and
  • establish "perimeter security" capabilities that can surveil network traffic to detect unauthorized activity.

OCIE also reminded registrants that it manages a "Cybersecurity Spotlight" webpage, which contains related guidance and resources.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More