Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.
Cybersecurity and an'increase in data breaches'isn't merely a U.S. problem. On Dec. 21, the Investment Industry Regulatory Organization of Canada (IIROC), a self-regulatory organization that helps oversee the country's trading industry, released two guides to help investment dealers protect themselves and their clients against cyber attack.
The first guide, titled 'Cybersecurity Best Practices Guide,' is intended as a living document that can be updated to give dealers the latest practices concerning governance and risk management, network security, and more. The 53-page guide also features a cybersecurity incident checklist and a sample vendor assessment.
'For smaller dealer members, this can help in understanding how to provide basic security for computer systems and networks,' this guide noted in an executive summary.' For larger dealer members, this provides a cost-effective approach to securing computer systems based on business needs, without placing additional regulatory requirements on business.'
The second guide, titled 'Cyber Incident Management Planning Guide,' focuses more narrowly on actions these investment dealers should take if a breach actually occurs. The 29 page guide examines the five stages of cybersecurity incident management ' plan and prepare, detect and report, assess and decide, respond, and post-incident activity ' as well as the current state of information sharing and breach reporting requirements.
The IIROC wrote that this guide, despite laying a framework from which to develop a plan, should not be 'intended to function as a working response plan. Rather, each dealer member should develop internal plans as part of their cybersecurity strategy that prepares them in advance for the risks they are most likely to face.'
The IIROC said that these two resources were produced by a 'leading security consulting firm' with which the organization has worked with in the past. The resources follow other initiatives from the organization, including a cybersecurity survey and a table-top exercise. The IIROC also separately noted that it is currently developing a cybersecurity program to help dealers increase their cybersecurity preparedness.
'Active management of cyber risk is critical to the stability of IIROC-regulated firms, the integrity of Canadian capital markets and the protection of investors,' said Andrew Kriegler, IIROC President and CEO, in a statement accompanying the guides' release. 'That is why we consulted with the industry, engaged security experts and developed concrete resources to help firms better manage their cyber risks.'
The focus on cybersecurity within Canada's securities sector follows an initiative from the government at large to focus on cybersecurity. Earlier in December, the country's government announced plans to launch the Canadian Cyber Threat Exchange in 2016, an independent, not-for-profit organization that will help corporations guard against attacks through information sharing. Its founding members are Air Canada, Bell Canada, Canadian National Railway Company, HydroOne, Manulife, Royal Bank of Canada, TELUS, TD Bank Group and TransCanada Corporation.
'One of our best defenses is our ability to work together and share information on existing and emerging cyber security threats, defensive techniques and other best practices,' said Ralph Goodale, Canada's Minister of Public Safety and Emergency Preparedness, in a statement at the time. 'For this reason, the Government of Canada welcomes the private sector initiative to create the CCTX. It will facilitate collaboration amongst public and private sectors in Canada and will help us to identify, prevent and mitigate cyber risks more effectively.'
'
With each successive large-scale cyber attack, it is slowly becoming clear that ransomware attacks are targeting the critical infrastructure of the most powerful country on the planet. Understanding the strategy, and tactics of our opponents, as well as the strategy and the tactics we implement as a response are vital to victory.
In June 2024, the First Department decided Huguenot LLC v. Megalith Capital Group Fund I, L.P., which resolved a question of liability for a group of condominium apartment buyers and in so doing, touched on a wide range of issues about how contracts can obligate purchasers of real property.
The Article 8 opt-in election adds an additional layer of complexity to the already labyrinthine rules governing perfection of security interests under the UCC. A lender that is unaware of the nuances created by the opt in (may find its security interest vulnerable to being primed by another party that has taken steps to perfect in a superior manner under the circumstances.
This article highlights how copyright law in the United Kingdom differs from U.S. copyright law, and points out differences that may be crucial to entertainment and media businesses familiar with U.S law that are interested in operating in the United Kingdom or under UK law. The article also briefly addresses contrasts in UK and U.S. trademark law.