Breach of Trust

In the 1930s, criminals like John Dillinger and the duo of Bonnie and Clyde captured headlines—and people’s imaginations. Their bank heists were profiled not only on the front pages of newspapers and tabloids but on celluloid. These people were infamous career criminals, who robbed, kidnapped, and killed, ruining the lives of those who got in their way.

Financial heists have evolved in fascinating ways since the good old days of criminals like Dillinger, when criminal identities were much more easily known to authorities. The career criminals dominating today’s digital landscape hide, anonymously, in plain sight. They can steal millions of dollars, pilfer confidential information from miles away with an Internet connection, sell that information to multiple bidders on the dark web, and cash their prize using bitcoins: all without a trace. In most cases, their victims don’t realize that they’ve been compromised until long after the incident has happened.

But, financial institutions continue to attract the attention of criminals, just as they also did in the good old days. While greenbacks in vaults were the targets in the past, privileged information and data repositories are the focus today. Hackers in the 21st century also have a wider choice of victims: asset managers, financial advisors, insurance providers, credit unions, online retailers, to name but a few.

There’s no shortage of information and networks for cybercriminals to prey on—and no shortage of news reports about their activities. In May 2016, hackers used the SWIFT network to transfer $101 million out of the New York Federal Reserve accounts of the Bangladesh Bank (the central bank of that country), leading to the resignation of its central bank governor. In August 2014, a hack at JP Morgan Chase compromised data for 76 million households, but it took over a month for the financial giant to realize it had been breached. And the WannaCry ransomware attack earlier this year wreaked havoc worldwide, including parts of the U.K.’s National Health Service.

These are just the high-profile incidents; unfortunately, many more incidents are never reported. According to a 2014 report from the Center for Strategic and International Studies, cybercrime was estimated to cost the global economy more than US$400 billion annually. And it’s not just the bad guys who are benefiting—the sophistication and frequency of these attacks has spurred an entire ecosystem of service providers and products aimed at this industry. Companies can hire specialized cybersecurity experts, or buy hardware and software, to keep hackers at bay; all the major technology consulting firms now offer consulting in this area, too. Firms can buy cyber liability insurance to protect against losses resulting from cyber incidents. There are even cybersecurity-focused ETFs and stock indices for opportunist investors.

These developments point to the maturing of an industry, with professionals and experts on both sides of the legal fence. Large financial institutions are making significant investments in cybersecurity, and have dedicated departments and budgets for keeping their digital assets and networks secure. Smaller investment management and advisory firms sometimes use a lack of resources as an excuse for not having sufficient safeguards against security breaches, failing to realize that simply throwing money at cybersecurity doesn’t keep the hackers away: institutions with large budgets get attacked, too.

A more fundamental problem, however, is that many advisors and smaller firms still fail to take security seriously. Most of them still perceive cybersecurity as a technology problem, best left to cyber experts who use complex software and code to deter hackers, and believe their responsibility to be limited to going through an annual training exercise with infographics to satisfy their annual compliance certifications. Research bears this out: a 2016 TD Ameritrade Institutional survey indicated that about two-thirds of U.S. financial advisors spend two hours or less annually on cybersecurity training, and one-third actually spend less than an hour.

That kind of attitude towards cybersecurity likely explains why most advisors don’t fully understand the security risks—and reveals the magnitude of the damages that could occur if those risks are realized. According to a 2016 report from the Financial Planning Association’s Research & Practice Institute, only 44% of advisors fully understand the issues and risks around cybersecurity, with only 29% saying they are fully prepared to manage and mitigate cybersecurity risks. Unfortunately, handing over the responsibility to a third party, or buying insurance or specialized software, is no longer considered sufficient to relieve a firm of the responsibility or liability from a security breach.

Regulators are now stepping in to force a behaviour change. In the U.S., the SEC’s Office of Compliance Inspections and Examinations has issued requirements on cybersecurity preparedness and has also started conducting cybersecurity audits of firms under its jurisdiction. FINRA is also reviewing firms’ compliance on cybersecurity practices and rules. Here at home, IIROC has published a detailed cybersecurity best practices guide for dealer firms, and the Bank of Canada has the mandate for overseeing cybersecurity at larger firms.

Complacency, in other words, is no longer an option. Ensuring the security of clients’ confidential information is a basic element of fiduciary responsibility in today’s digital age. According to the Securities and Exchange Commission (SEC), “an adviser’s fiduciary obligation to its clients includes obligations to its clients from being placed at risk as a result of the adviser’s inability to provide advisory services.” Even if there’s no financial damage from such a security breach, the reputational risk in itself can be detrimental. The recent data breach at Equifax is just one example.

A basic Google search will turn up several resources to which advisors and smaller firms can turn for strengthening their security controls, most of which only require an investment of time. Security requirements depend on the nature of the business in question, but the first order of business is for advisors and their firms to understand the risks of, and their potential damage from, a security breach. That, in turn, requires advisors to have a true appreciation of the ubiquity of these attacks, and of the ongoing vigilance that’s necessary.

In reality, no one is fully shielded from a cyberattack. In fact, the SEC itself announced in September a 2016 data breach to its EDGAR database, which leads to another important point: it’s not enough to have the proper controls in place. Contingency plans must also be in place in case those controls fail. We understand what we can do to prevent house fires, and what should be done if they happen: we don’t think about cybercrime like that.

Changing mindsets is neither easy nor instant, but we can start by striving to be better informed and realizing that risk-averse behaviour doesn’t imply or equate to technological sophistication. Guidance from regulators and security experts simply emphasizes the importance of understanding the risks, adopting policies and procedures for dealing with those risks, and providing ongoing training to internalize those policies and procedures. After all, the criminals are always one step ahead; we must strive to be several.