Skip to content

Digital Security: Consequences under Law and Strategy for Mitigation

U.S. Securities and Exchange Commission's Examination Division unveils 2025 focus areas ("Report") on October 21, 2024. Investment advisors and brokerage firms must revise their policies, processes, and monitoring strategies to tackle the issues highlighted in the Report.

Cybersecurity Tactics: Examining the Legal Ramifications and Mitigation Strategies
Cybersecurity Tactics: Examining the Legal Ramifications and Mitigation Strategies

Digital Security: Consequences under Law and Strategy for Mitigation

SEC's Examination Division Outlines 2025 Priorities

The US Securities and Exchange Commission (SEC) has released its Examination Priorities Report for 2025, highlighting areas of concern and focus for the coming year.

The report emphasises that the priorities outlined often lead to enforcement actions focused on those same priorities. This year, the SEC's Examination Division will continue to prioritise its review of cybersecurity practices, a focus that has been ongoing for some time.

In 2025, the Division of Examinations will particularly supervise firms dealing with crypto-assets or cryptocurrencies. Although the specific organization responsible for this supervision in 2025 is not explicitly mentioned, it is typically the SEC that oversees crypto exchanges and related entities under its mandate.

One of the key areas of focus for the Division will be scrutinising policies in place for data loss prevention, access controls, and responses to crypto-related incidents. They will also assess registrants' policies and procedures for monitoring controls, fraud prevention, anti-money laundering, and protections against the loss or misuse of client information, especially in relation to Artificial Intelligence (AI).

The report also covers crypto assets as a significant risk area. The Division will review whether registrants are following appropriate standards when recommending crypto assets and will be looking to strengthen compliance practices and risk disclosures relating to these crypto concepts. Protecting investor information, customer records, and assets will also be a priority.

Another priority area in the report is information security and operational resiliency. The Division will assess whether broker-dealers and registered investment companies are complying with rules surrounding tailoring their business model, conducting independent testing, and meeting SAR filing obligations.

The SEC's Examination Division conducts inspections of entities registered with the SEC, including investment advisers and broker-dealers. Building on its 2024 priorities, the Division will remain committed to closely monitoring and examining registrants offering investments involving crypto assets in 2025.

The report also covers perennial priorities of the Examination Division alongside new risk areas. The Division will continue to prioritise anti-money laundering (AML) programs and will assess registrants' compliance with Regulations S-ID and S-P.

Three noteworthy risk areas that are relevant to most capital markets participants include: emerging financial technologies based on artificial intelligence, crypto assets, and information security and operational resiliency. The report emphasises that the Examination Priorities Report is not exhaustive but serves to highlight risk areas of concern.

The Division's focus on AI comes after a year during which the SEC has continued to reiterate its concerns about AI-related risks. The SEC suggests registrants should account for third-party services and products when assessing crypto-related risks and planning for crypto-resiliency for essential business operations.

The Examination Division will begin conducting examinations of registered security-based swap execution facilities in late fiscal year 2025 after it adopted new regulations in late 2023.

The SEC's Examination Division's 2025 Examination Priorities Report underscores the organisation's commitment to maintaining the integrity and security of the financial markets, particularly in the rapidly evolving landscape of crypto assets and AI technologies.

Read also:

Latest