Cybersecurity and Risk Insights and Alerts

Cyber risks and threats continue to evolve, and firms are under pressure to meet SEC and FCA expectations for operational resilience as well as their own internal and client expectations for cybersecurity and privacy. Stay current on the latest cybersecurity, privacy, and risk threat and regulatory alerts, and build your cybersecurity and privacy knowledge with insights from our cybersecurity and technology risk experts.

ACA Aponix Cybersecurity Checklist

Download and review the following cybersecurity safeguards and evaluate your firm’s cybersecurity program.

Cyber alerts and insights

cyber code

Is It Time to Reset Your Password Reset Policy?

Many authorities are questioning whether mandatory password reset policies are worth the hassle. Get ACA's guidance on when, if ever, you can remove or relax your password reset policy.

Article
  • Cybersecurity
tprm vmos

Third-Party Risk Management: Collaborating for Results

Running vendor management or third-party risk management (TPRM) programs can be a complicated process for both consumers and providers of services. Here are some of the current challenges with due diligence and opportunities to improve the process for all parties involved.

Article
  • Cybersecurity
abstract image with a lock and shield

Critical Vulnerability Identified in Windows Servers

The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert identifying a critical vulnerability affecting all versions of Microsoft® Windows Server® configured with the Domain Name System (DNS) role enabled. The vulnerability could potentially allow a remote attacker to gain control of affected systems.

Cyber Alert
  • Cybersecurity
abstract image with a lock and shield

European Union Court Strikes Down Key EU-U.S. Data Sharing Agreement

The Court of Justice of the European Union (CJEU) has determined that the Privacy Shield agreement, a key data sharing agreement that allows signatory U.S. companies to transfer EU resident personal data to the U.S., is no longer valid. Learn what action you may need to take due to this change.

Cyber Alert
  • Cybersecurity
ACA Threat Intelligence Alert Blog Image

CCPA Enforcement leads to Multiple Class-Action Lawsuits

The California Consumer Privacy Act (CCPA) went into effect on 1/1/20 and enforcement began on 7/1/20. There has already been considerable activity on the class action front, much of it even before the enforcement date. Review what you need to do to avoid CCPA penalties.

Article
  • Cybersecurity
  • Privacy
ACA Threat Intelligence Alert Blog Image

OCIE Risk Alert Warns of Increase in Ransomware Attacks

The SEC OCIE has issued a Risk Alert warning of an increase in the sophistication of ransomware attacks against SEC registrants with attackers using advanced phishing and other social engineering tactics to penetrate financial institution networks and install malware that limits company access to data until a ransom is paid.

Cyber Alert
  • Cybersecurity