Now that you have a handle on the nightmare scenario and understand the importance of fostering a culture of security across your investment firm, here are four steps to guide you through the creation of that culture.
1. Create a computer incident response team
Start by creating a “Computer Incident Response Team” who will oversee your information-security policies. Although IT professionals are responsible for overseeing and maintaining your computing infrastructure, you also need business users to play a central role in your security initiatives. After all, they’re the ones who use these resources – and the ones who can represent the biggest vulnerabilities and risks. While the team’s responsibilities can vary, many CIRTs are active in several key areas:
2. Define your terms
Confidential Information
Before you can secure your confidential information, it’s important to define exactly what you mean – and ensure everyone in your organization is literally and figuratively on the same page.
Many firms create a 10 or 20-page written information security plan that formalizes the definitions and policies that govern the creation, access, and deletion of confidential information and computing services. That can be everything from a definition of personally identifiable information (PII), a description of user access privileges and roles, or policies regarding USB thumb-drives. What matters is that you’ve explicitly and unambiguously documented all aspects of your company’s at-risk assets and services. A multi-disciplinary cross-functional team often works best in these efforts.
Technical Safeguards and Responses
With a business perspective, the CIRT team can help IT define the technical restrictions that should be in place – everything from encryption for mobile devices to screen-lock policies, USB usage, antivirus scanning, spam filtering, password policies, penetration tests, audits, and much more. These are matters that should not be in the sole jurisdiction of technical experts.
In the event of a breach, your CIRT can manage and facilitate the response that’s needed after assessing the impact of an incident. That can encompass working with internal stakeholders and notifying regulators and government officials as required by law. Your business people – not the IT team – know the value of that data, and they’re in the best position to define the response.
3. Deliver comprehensive training
All of the documents, committees, and meetings won’t have any meaningful impact if the proper security practices don’t spread quickly and uniformly across the organization. And the way that starts to happen is through systemic and comprehensive training practices.
4. Remember the internal culture reaches out externally
Even when you have locked down your internal systems, implemented best-practices policies and procedures, and trained your employees to think “security first,” there’s still more work to do, culture-wise.
Conclusion
Having proper perimeter defenses and rigid security controls are, of course, non-negotiable requirements for any hedge fund or private equity firm. But the new front lines in corporate IT security aren’t technical – they’re people. By developing an internal culture of security, the organization does far more than deploy and configure bits and bytes. It commits to defining and following thoughtful, far-ranging policies to eliminate the needless internal vulnerabilities that often go unrecognized.
From a properly trained and staffed computer incident response team to carefully defined policies and procedures to complete training, financial services firms can take simple but important steps to prevent breaches, strengthen security, improve regulatory compliance, and increase customer confidence.
Yen carry trade risks mount
Hedge funds and other leveraged investors face renewed risks from the yen carry trade as Japan moves further away from decades of…
More
Valour launches first crypto hedge fund using Neuronomics AI strategy
Valour, the digital asset investment products subsidiary of DeFi Technologies, has launched its first hedge fund as it expands beyond…
More
SocGen targets strong prime brokerage growth
Societe Generale is planning to significantly expand its prime brokerage business as part of Chief Executive Officer Slawomir Krupa's…
More