It’s a rare day when consumers don’t read about another cybersecurity breach afflicting a U.S. business. For example, last year Anthem, a large health insurer, announced that hackers stole sensitive personal information from 80 million of its customers. Not surprisingly, consumers are on edge about future attacks, as are financial-services regulators. In fact, the North American Securities Administrators Association (NASAA), went so far as to publish an alert encouraging consumers to discuss cybersecurity with their investment advisors.

 “The increasing reliance on technology in our daily lives could leave our sensitive financial information more vulnerable to unwanted viewing or theft without proper safeguards in place,” said William Beatty, NASAA President and Washington Securities Director.

In September 2014, NASAA reported that 62 percent of state-registered investment adviser firms participating in a NASAA pilot survey had undergone a cybersecurity risk assessment, and 77 percent had established policies and procedures related to technology or cybersecurity. “Investors should think about the safety of their financial information, and talk with their investment professionals about what steps firms are taking to safeguard client information,” Beatty said.

To help investors with that discussion, Beatty suggests asking the following questions:

  • Has the firm addressed which cybersecurity threats and vulnerabilities may impact its business?
  • Does the firm have written policies, procedures, or training programs in place regarding safeguarding client information?
  • Does the firm maintain insurance coverage for cybersecurity?
  • Has the firm engaged an outside consultant to provide cybersecurity services?
  • Does the firm have confidentiality agreements with any third-party service providers with access to the firm’s information technology systems?
  • Has the firm ever experienced a cybersecurity incident where, directly or indirectly, theft, loss, unauthorized exposure, use of, or access to customer information occurred? If so, has the firm taken steps to close any gaps in its cybersecurity infrastructure?
  • Does the firm use safeguards such as encryption, antivirus, and anti-malware programs?
  • Does the firm contact clients via email or other electronic messaging, and if so, does the firm use secure email and/or any procedures to authenticate client instructions received via email or electronic messaging, to work against the possibility of a client being impersonated?

Guidance from the National Ethics Association: Make sure you have completed a cybersecurity assessment and that you have comprehensive policies and procedures in place to prevent a cyber attack. This is important not only to protect customer information, but also to prevent data thefts that could spawn client complaints and E&O insurance claims. If you haven’t done this yet, tap into resources or referrals available from your FMO, RIA, or Broker-Dealer. Most importantly, do not assume that a cyber attack will never happen to you. It can, and if it does, your response plan must be ready to go.

For information on affordable E&O insurance for low-risk insurance agents, investment advisors, and real estate broker/owners, please visit For information on ethical sales practices, please visit the National Ethics Association’s Ethics Center.