Month: September 2017

SEC Unmasked: How Safe are Its Investigative Files?

Dennis Stubblefield

Dennis Stubblefield, Esq.
619.696.9500
dstubblefield@shufirm.com

We just posted our overview of the SEC Hack. The agency has thus far specified just EDGAR as being compromised.  However, the SEC should also quickly evaluate what accountability it should demonstrate to the varied constituents who get caught up in its enforcement apparatus, i.e., any and all companies and individuals—extending way beyond regulated entities like broker-dealers and investment advisers—who come within reach of the investigative powers of its Division of Enforcement.

Enforcement can command the production of documents and the furnishing of testimony from any “person,” (including entities) and it does so regularly and aggressively.  Such information reflects and reveals a broad swath of data ranging from documents containing social security, bank, brokerage and telephone numbers to witnesses’ testimony about anything and everything relevant to investigations. Such investigations are “non-public,” and documents are routinely submitted by companies and persons with the clear notation, usually on each and every page, “Confidential Treatment Requested.”

It is true that the Commission has broad discretion to share and release information, even the most valuable and sensitive, and even when clearly flagged as confidential, consistent with its obligations under the Freedom of Information and Privacy Acts. Nonetheless, enforcement defense practitioners have long assumed that the SEC has a reasonably solid system and process underlying the exercise of such discretion.  Perhaps this assumption should be reexamined in light of the hack. After all, what is the worth and sufficiency of an agency determination to release or not release information if the basic integrity of its own system and process surrounding that information is called into question?

It is already daunting enough for individuals and companies to deal with the fact that sensitive information is routinely shared with DOJ, its United States Attorneys, FINRA and other governmental and quasi-governmental agencies. This concern is particularly compelling for “Good Citizen Boy Scouts and Girls” who have done nothing wrong yet have had to discharge their legal obligation when commanded by the government, often at considerable burden to them in terms of lost productive time and significant attorneys’ fees.

But is it too much to ask that such good citizens — and indeed each and every person and company cooperating with the Commission — have some sort of decent comfort level that information furnished by them is at least reasonably safe from the prying eyes of predators ranging from identity thieves to market manipulators?

The answer of course is a resounding “No.”

Anyone who has furnished such information to the Enforcement Staff should consider asking the Staff Attorney assigned to the investigation whether such information has been compromised. You will very likely not get an answer, but, whatever the response, consider documenting it. That way you will have “made a record,” in case you need it later.

As of press time, the SEC’s website had no mention of the hack, much less any guidance on what affected parties may wish to consider doing about it.

Shustak Reynolds & Partners, P.C. regularly represents firms and individuals in SEC, FINRA, securities, investment, and financial services matters, including litigation, arbitration, enforcement and investigation matters. If you or your company require counsel in these areas, contact us today for a confidential, complimentary consultation.

Dennis Stubblefield, our Partner in charge of the firm’s Orange County office, was formerly an enforcement attorney with the SEC, and General Counsel of several AIG/SunAmerica broker-dealers.  His practice focuses on enforcement defense in matters investigated and litigated by the SEC and FINRA.  He also provides expert witness testimony and consultation on broker-dealer compliance and supervision, particularly in the context of customer-firm disputes in FINRA arbitration.

Posted in Blog | Comments Off on SEC Unmasked: How Safe are Its Investigative Files?

SEC Reveals It Was Hacked in 2016

Jonah A. Toleno

Jonah A. Toleno, Esq.
619.696.9500 ex. 104
jtoleno@shufirm.com

On the heels of the recent Equifax hack disclosure, the U.S. Securities and Exchange Commission (SEC), the government agency responsible for regulating the nation’s securities and financial services industry, issued a press release September 20, 2017, announcing a significant security breach. According to a concurrent statement by SEC Chairman Jay Clayton, the SEC detected the breach in 2016. Clayton disclosed, “Specifically a software vulnerability in the test filing component of our EDGAR [Electronic Data Gathering, Analysis and Retrieval] system, which was patched promptly after discovery, was exploited and resulted in access to nonpublic information,” and the incident “may have provided the basis for illicit gain through trading.” While the SEC’s investigation is ongoing, the security invasion and the SEC’s delay in disclosing it are disconcerting to many.The SEC maintains – and transmits – three categories: publicly available disclosure documents filed by issuers and other registrants; nonpublic and personally identifiable information related to the SEC’s supervisory and enforcement functions including data on broker-dealers, investment companies, credit rating agencies and municipal advisors; and nonpublic and personally identifiable information related to the SEC’s internal operations – obviously, an enormous amount of sensitive data requiring the strictest of protections.

According to the July 2017 U.S. Government Accountability Office (GAO) Report to the SEC Chairman, the GAO found that in 2015 and 2016 the “SEC improved control of financial systems but needs to take additional actions.” As of September 30, 2016, the GAO issued 29 information security recommendations to the SEC. In its report, it reported that a staggering 14 of these recommendations had not been implemented as of July 2017. Sounds like the SEC has some ‘splainin’ to do to the broker-dealers and investment advisory firms it regulates and audits for – you guessed it – cybersecurity compliance.

Chairman Clayton assures the public he is focused on maintaining and improving SEC cybersecurity. He initiated an assessment of the SEC’s internal cybersecurity risk profile and its approach to cybersecurity from a regulatory and oversight perspective in May of this year. But Clayton’s and the SEC’s work is cut out for them. “I recognize that even the most diligent cybersecurity efforts will not address all cyber risks that enterprises face. That stark reality makes adequate disclosure no less important….Cybersecurity efforts must include, in addition to assessment, prevention and mitigation, resilience and recovery”, he writes.

Clayton’s sentiment is especially pertinent in light of the recently Equifax hack, potentially affecting over 143 million people and rendering countless others even more fearful of cyberattacks.

Shustak Reynolds & Partners, P.C. regularly represents firms and individuals in SEC, FINRA, securities, investment, and financial services matters, including litigation, arbitration, enforcement and investigation matters. If you or your company require counsel in these areas, contact us today for a confidential, complimentary consultation.

Jonah Toleno is a partner in our San Diego office and has extensive experience representing individuals and firms before the SEC, FINRA, state courts and federal courts. She acts as trial counsel in a range of litigation and arbitration matters and offers outside counsel services to various financial services firms.

Posted in Blog | Comments Off on SEC Reveals It Was Hacked in 2016

FINRA Issues New Guidance on Social Media Communications, Including Rules on Sharing Content and New Types of Advertising

Katherine S. Bowles

Katherine S. Bowles, Esq.
619.696.9500 ex. 124
kbowles@shufirm.com

FINRA has issued new guidance on the use of social media and digital communications for member firms and persons associated with member firms. Regulatory Notice 17-18 provides guidance in the areas of recordkeeping, third-party posts and hyperlinks to third-party sites. This notice builds on prior Regulatory Notices 10-06 and 11-39 that concerned communications with the public to social media sites and the use of personal devices for business communications.

Text Messaging – More frequently, clients want to interact with registered representatives through text messaging and other chat services. Records of these communications related to its business that are made by these means must be retained, and any firm that intends to communicate using these means must first ensure that it can retain records of those communications as required by SEA Rules 17a-3 and 17a-4 and FINRA Rule 4511.

Sharing of Content – This new FINRA guidance makes clear that by sharing or linking to third-party content, the member firm has adopted the content and is responsible for the content to the same extent it is for firm-generated communications. As for personal communications, an associated person who shares or links to content that the member firm made available, which is not related to its products or services (such as the firm’s sponsorship of a charitable event), is not subject to Rule 2210.

The firm is not responsible for links to other content in the third-party content it shares, unless the facts and circumstances indicate the firm has adopted or became entangled with such content. Whether the firm has adopted this content depends on whether the firm has influence or control over it. This analysis changes when the firm shares or links to content that itself serves primarily as a vehicle for links, and in that situation the firm would have adopted the other content accessed through those links. This rule would apply if a firm linked to a webpage made up largely of links to other content.

Additionally, if a firm includes on its website a link to a section of an independent third-party website, whether it has adopted the content of that website depends on two factors: (1) whether the link is “ongoing” and (2) and whether the firm has influence or control over the content of the third party site. The firm has not adopted content if the link is “ongoing”. “Ongoing” means that: (i) the link is continuously available to investors who visit the firm’s site; (ii) investors have access to the linked site whether or not it contains favorable material about the firm; and (iii) the linked site could be updated or changed by the independent third party and investors would still be able to use the link. The language introducing the ongoing link must also conform to the content standards of the communication rules, including not being misleading or inaccurate.

Native Advertising – This is advertising content that matches the form and function of the platform on which it appears, such as content that is similar to a news feature article, product reviews, or other material that surrounds it online. This regulatory notice clarifies that native advertising is not inherently misleading and can be used as long as it complies with Rule 2210, meaning the firm must ensure the communication is fair, balanced and not misleading. Native advertising must prominently disclose the firm’s name, accurately reflect any relationship with the firm and any other entity or individual named in the advertisement, and state whether mentioned products or services are offered by the firm. Also, if a firm or representative has paid for the publication, production or distribution of any communication that appears to be a magazine, article or interview, then the communication must be clearly identified as an advertisement. Any communications that take the form of comments or posts by influencers should be clearly identified as advertisements and include the broker-dealer’s name as well as any other information required for compliance with Rule 2210.

Testimonials and Endorsements – Unsolicited third-party opinions or comments posted on a social network site such as LinkedIn are not communications of the firm or representative for purposes of Rule 2210. However, if the firm or representative likes or shares content, they have adopted the content and become subject to the communication rules, including prohibitions on misleading or incomplete statements or claims, the testimonial requirements, and the supervision and recordkeeping rules. Required testimonial disclosures may be provided in the interactive electronic communication itself in close proximity to the testimonial or the disclosures may be made through a clearly marked hyperlink accompanying the testimonial using language such as “important testimonial information”.

Third-Party Content – If an unaffiliated third-party publisher posts an online directory of business information, contacting the publisher to provide a correction is not considered a communication of the firm or the representative as long as the correction pertains to factual information. The firm or representative may also post a correction by posting a comment on the listing without it being deemed to have adopted the incorrect listing.

BrokerCheck Link – FINRA has clarified that apps created by firms do not need to have a reference and hyperlink to BrokerCheck because Rule 2210(d)(8) specifically references websites. However, if the app displays a webpage of the firm in the app, the firm must ensure that the link is readily apparent when the page is displayed through the app.

Shustak Reynolds & Partners, P.C.’s experienced San Diego FINRA and securities attorneys are well versed in guiding financial advisors through transitions from one firm to another. Our FINRA arbitration practice group routinely represents financial advisors and registered representatives in employment and promissory note disputes before FINRA’s arbitration division.  Contact us today for a confidential, complimentary consultation.

Posted in Blog | Comments Off on FINRA Issues New Guidance on Social Media Communications, Including Rules on Sharing Content and New Types of Advertising