Posted on Google Google
Alan Markfeld profile picture
Alan Markfeld
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Dharmi is an excellent securities lawyer who understands the law as it pertains to these cases. She is extremely proactive and represents her clients well. I highly recommend Jacko and Dharmi.
Posted on Google Google
Danielle Martin profile picture
Danielle Martin
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I’ve had the privilege of working closely with this firm in my role as Chief Compliance Officer and I can confidently say they are an exceptional compliance partner. Their depth of experience is immediately evidentand they bring a level of practical knowledge. What I truly enjoy is their ability to translate complex regulatory requirements into plain English, often using real, everyday examples that make implementation far more manageable. They are also incredibly responsive and reliable. In a field where timing matters, their prompt communication and thoughtful guidance have been invaluable. If you’re looking for a compliance attorney who combines expertise, clarity, and professionalism, I highly recommend them.
Posted on Google Google
Curt Rocca profile picture
Curt Rocca
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Michelle and the team at Jacko Law Group have helped guide through a variety of critical circumstances as we ventured through the uncharted and unfamiliar territory of becoming and successfully operating as an RIA. I have particularly appreciated Michelle's personal involvement and genuine caring about us and our organization. She has been responsive and her counsel has been consistently on-point and helpful. She artfully guided us through our initial filing process and first SEC exam process - which went very well. Very grateful to Michelle and her team.
Posted on Google Google
Nicholas Di Paolo profile picture
Nicholas Di Paolo
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Michelle and her team were excellent to work with, front to back. They helped me to understand the challenges ahead and were always proactive in their consultation through every step of my transition. JLG truly know the wealth management industry very well and did a great job of understanding the challenges unique to my business. Without them, I can confidently say I would not have felt as comfortable through the transition as I did. Fortunately, that's not something that stops there - Michelle and her team have kept in touch to ensure that I'm on top of certain administrative issues, trends, and simply showing me that they care about my business and success. I look forward to continuing to work with them for many years to come.
Posted on Google Google
Margery Neis profile picture
Margery Neis
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Dharmi Mehta was extremely helpful when my business partner and I transitioned to a new RIA firm. She and her staff were all very professional. Her guidance during our transition was invaluable. I highly recommend Dharmi and Jacko Law Group.
Posted on Google Google
Joseph Burwell profile picture
Joseph Burwell
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Dharmi and Amandeep were a delight to work with. They assisted me with a claim and stuck with me the entire way through. Dharmi's advice was invaluable, and I was most impressed by her clear and professional communication. From beginning-to-end, both Dharmi and Amandeep kept me well informed. Their entire team are proud of their work and rightfully so. Thank you!
Posted on Google Google
Faruk Jaffer profile picture
Faruk Jaffer
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
My mentor once told me that a good attorney is worth their weight in gold — and that couldn't be more true of Michelle and Amanda. Their expertise, professionalism, and responsiveness were top notch every step of the way. It's rare to find legal partners who are not only sharp and thorough, but also genuinely invested in your success. I’m grateful for their guidance and highly recommend them to anyone seeking trusted legal counsel.
Posted on Google Google
everistus etafo profile picture
everistus etafo
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
It is my great Privilege to share my Review of what Atty Dharmi Mehta of Jacko Law Group did for me and by extension for my family. From the first time complimentary conversation we had having spoken to several other Lawyers ,l knew she was the right person for the Job .Because of her background as a former RR ,she was professional,kind, Empathetic,listened and was focused on fighting for me. From a potential of been terminated with cause ,l was able to walk away with a clean U5 with a validation that l did nothing wrong except what was in the best Interest of my clients. I hope nobody ever has to go through what l have Experienced, but if you do ,you want Dharmi Mehta beside you .Rest assured your service Deserve 10 stars but this forum only allows 5. Me and my family are forever grateful and will make sure that any RR who needs an advocate will know about you . Everistus Etafo
Posted on Google Google
Karen Althaus profile picture
Karen Althaus
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I have worked with Jacko Law Group for 2 different business situations that necessitated an attorney. In both cases, the team was very thorough & competent. Their attention to our situation and the extra effort they put into our case(s) was very much appreciated. I would highly recommend Jacko Law Group!
  • Home
  • Insights
  • Cybersecurity: Attacks, Risk Mitigation, and Regulatory Compliance

BD

Cybersecurity: Attacks, Risk Mitigation, and Regulatory Compliance

Cybersecurity: Attacks, Risk Mitigation, and Regulatory Compliance| Jacko Law Group, PC

In an increasingly digital world, where financial transactions and sensitive information are often stored and transmitted electronically, investment advisers face a growing threat from cyber-attacks. These attacks can range from data breaches and phishing scams to ransomware and insider threats, posing significant risks to both the advisers themselves and their clients.

2023 saw a concerning increase in cyber-attacks. Statista.Com reported 3,203 data compromises in 2023, which put the data of over 352 million individuals at risk, compared to 1802 data incidents in 2022.

In addition, about 744 companies in the financial sector experienced a cyberattack making it the second most affected sector in the US. Globally, the Manufacturing sector was the hardest hit last year, and accounted for about 25% of the total cyber-attacks. The Financial sector was a close second, accounting for 18% of attacks.

In the United States, the Healthcare industry remains one of the most targeted since the COVID-19 Pandemic followed, again, by the Finance sector. Both globally and in the US, cybercriminals continue to target the financial sector, including advisory firms and banking institutions. According to an article by the International Monetary Fund (IMF), the industry suffered from over 20,000 cyber-attacks over the last 20-years, losing approximately $12 billion.

The question remains:

Why is the Financial Sector such a target for cyber criminals?
The financial sector is a hot bed of sensitive personal and financial data. As an economic epicenter, money flows through banking institutions, insurance companies, investment advisory firms and others along with the associated data sought after by cyber criminals. There is an assumption that only large financial institutions are at risk. This is false. According to a report by Accenture, cyber-attacks on smaller businesses continue to rise.

Interestingly, Private Equity firms are also highly appealing to cyber criminals. A report by Accenture titled, “Private Equity: The Rising Cost of Cyber-attacks,” offer that cyber criminals target Private Equity firms because they have a wealth of personal and financial data, access to capital and are considered High Cyber Risk takers because most PE firms are focused most on growth and speed, often relegating cyber security as a non-priority.

However, even more important, is the question,

Why is the Financial Sector so vulnerable to cyber-attacks?

Cyber-attacks have become more sophisticated and harder to detect for longer. Not only have cyber criminals become more advanced in their methods but also in their strategies.

Third Party Vendors

In the financial industry, there is a heavy reliance on third-party service providers such as IT security vendors. Oftentimes, these vendors serve several firms in the industry exposing many companies to attack from one vulnerable spot – the vendor.

For example, in February 2024, a data breach exposed personal and financial data of over 57,000 Bank of America customers. However, the breach did not come through Bank of America, it came through third-party vendor, “Infosys McCamish”, a software provider for the finance industry. In December 2023, sixty credit unions experienced outages as a result of a Ransomware that infiltrated the network system of cloud computing provider, “Ongoing Operation.” With heavier reliance on third-party service providers, and/or failure to perform thorough due diligence on the service providers, the risk of cyber-attacks remains a constant threat.

Lack of Adequate Cyber Security Measures

Cyber preparedness and internal data protections is concerningly lackluster for many businesses in the finance sector. In July 2023, the new SEC Cybersecurity rules went into effect. The amended rules were in response to a widespread lack of cyber preparedness by investment advisers and others in the field and were implemented to protect investors and promote cyber diligence and transparency.

The new cyber security rules were primarily implemented for Public Companies, but, there has been a slew of SEC enforcement actions against smaller private companies for failure to meet cyber compliance requirements.

However, with proper risk mitigation strategies and compliance measures in place, investment advisers can better protect themselves and their clients from cyber threats, and meet compliance requirements.

Understanding the Risks

Cyber-attacks on investment advisers can have severe consequences, including financial losses, reputational damage, and regulatory penalties. Here are some common types of cyber threats that investment advisers may encounter:

  1. Data Breaches: Unauthorized access to sensitive client information, such as personal and financial data, can lead to identity theft and financial fraud.
  2. Phishing Scams: Cyber criminals may use deceptive emails or messages to trick employees into disclosing sensitive information or downloading malware.
  3. Ransomware: Malicious software that encrypts data and demands a ransom for its release can disrupt operations and cause financial losses.
  4. Insider Threats: Employees or contractors with access to sensitive information may intentionally or unintentionally misuse or disclose it.

Risk Mitigation Strategies

To mitigate the risk of cyber-attacks, investment advisers should implement robust cybersecurity measures tailored to their specific needs and risk profile. Here are some key strategies to consider:

  1. Risk Assessment: Conduct regular risk assessments to identify potential vulnerabilities and prioritize cybersecurity investments and actions.
  2. Employee Training: Provide comprehensive training to employees on cybersecurity best practices, including how to recognize and respond to phishing attempts and other security threats.
  3. Access Controls: Implement strong authentication mechanisms, such as multi-factor authentication, to control access to sensitive data and systems.
  4. Data Encryption: Encrypt sensitive data both in transit and at rest to protect it from unauthorized access.
  5. Patch Management: Keep software and systems up to date with the latest security patches and updates to address known vulnerabilities.
  6. Incident Response Plan: Develop and regularly test an incident response plan to ensure a timely and effective response to cyber security incidents.
  7. Vendor Management: Assess the cybersecurity practices of third-party vendors and service providers to ensure they meet appropriate security standards.

Compliance Requirements

Investment advisers are subject to various regulatory requirements related to cybersecurity and data protection. Compliance with these requirements is essential for protecting client assets and maintaining trust in the financial markets. Here are some key compliance considerations:

  1. SEC Regulations: The U.S. Securities and Exchange Commission (SEC) provides guidance and requirements for cybersecurity risk management, including the Safeguard Rule and Regulation S-P (Privacy of Consumer Financial Information).
  2. GDPR Compliance: Investment advisers that operate in the European Union or handle the personal data of EU residents must comply with the General Data Protection Regulation (GDPR), which sets strict requirements for the protection of personal data.
  3. Cybersecurity Examinations: The SEC conducts examinations of registered investment advisers to assess their cybersecurity preparedness and compliance with relevant regulations.
  4. Reporting Requirements: Investment advisers may be required to report cybersecurity incidents to regulatory authorities and affected clients in accordance with applicable laws and regulations.

Conclusion

Cyber-attacks pose significant risks to investment advisers, but with proactive risk mitigation strategies and compliance measures, they can better protect themselves and their clients from cyber threats. By staying vigilant, investing in cybersecurity measures, and adhering to regulatory requirements, investment advisers can enhance their resilience to cyber-attacks and safeguard the integrity of the financial markets.

Author: Kathryn Konzen, Esq. is the Director of Operations and Counsel, at Jacko Law Group, PC (“JLG). With over 15 years of experience in the legal profession, she brings a diverse range of expertise in areas such as operations, eDiscovery consulting, business development, recruiting, and more. Her practice focuses on working closely with clients, assisting them with their Cybersecurity and AI legal needs. 

JLG works extensively with investment advisers, broker-dealers, investment companies, private equity and hedge funds, banks and corporate clients on securities and corporate counsel matters. For more information, please visit https://www.jackolg.com/.

The information contained in this article may contain information that is confidential and/or protected by the attorney-client privilege and attorney work product doctrine. This email is not intended for transmission to, or receipt by, any unauthorized persons. Inadvertent disclosure of the contents of this article to unintended recipients is not intended to and does not constitute a waiver of attorney-client privilege or attorney work product protections.

The Risk Management Tip is published solely based off the interests and relationship between the clients and friends of the Jacko Law Group P.C. (“JLG”) and should in no way be construed as legal advice. The opinions shared in the publication reflect those of the authors, and not necessarily the views of JLG. For more specific information or recent industry developments or particular situations, you should seek legal opinion or counsel.

You hereby are notified that any review, dissemination or copying of this message and its attachments, if any, is strictly prohibited. These materials may be considered ATTORNEY ADVERTISING in some jurisdictions.

[1] Service of process refers to the delivery of the legal documents that gives a defendant notice of the legal action filed against it and the opportunity to respond. Valid service of process on a defendant is required by the U.S. Constitution. Service of process must be accomplished by the plaintiff pursuant to the rules or statutes of the appropriate jurisdiction. These rules include how process documents can be delivered (such as in-hand delivery or certified or registered mail) and to whom that delivery can be made.

About the author

Jacko Law Group provides tailored legal services and effective strategies for success, delivering exemplary solutions to complex legal and regulatory challenges to ensure that both business efforts and compliance obligations are satisfied.

Related Insights