Investment Funds Update
URGENT: CFTC Warns Registrants of Cyber Threats and Requests Information by January 10 and/or January 20.
One DSIO cyber threat alert was directed to swap dealers (SDs) and futures commission merchants (FCMs). Another was directed to commodity pool operators (CPOs), commodity trading advisors (CTAs), introducing brokers (IBs) and retail foreign exchange dealers (RFEDs). The National Futures Association (NFA) then sent a blast email to all NFA members in these registration categories (on behalf of the CFTC), with the DSIO alerts attached, further emphasizing to NFA members the information requested by DSIO and the deadlines for providing such information.
Each SD, FCM, CPO, CTA, IB and RFED should determine whether any of its cloud service providers has been affected by the cyber attack described in the WSJ article, or if it has received communications or is communicating with cloud service providers or others regarding the attack or any related potential cyber event, and respond as follows:
- SDs and FCMs should respond by January 10, 2020, whether any of their cloud service providers were affected by the attack. DSIO has requested that SDs and FCMs respond even if their cloud service providers were not affected by the attack.
- CPOs, CTAs, IBs and RFEDs should respond by January 10, 2020, if any of their cloud service providers were affected by the attack. Registrants in these categories whose cloud service providers were not affected by the attack do not need to respond to DSIO pursuant to the cyber threat alerts.
- Any CFTC registrant whose cloud service provider or providers were affected by the attack should include information regarding whether and when the provider(s) informed it about the attack, a summary of any steps it has taken to protect its systems and data in response to the attack and its plans to notify market participants whose data may have been affected.
- In addition, each registered IB and RFED should respond by January 20, 2020, advising whether it has received any communications from, or is communicating with, cloud service providers, customers, clients, counterparties, business partners or industry-related parties regarding the attack described in the WSJ article or a related potential cyber event. This request is much broader than those described above, as it covers “related potential cyber events” and not merely the attack described in the WSJ article, and it is not limited to events related to cloud service providers. Also, given the phrasing of these sections of the cyber threat alerts, it appears DSIO is requesting responses from all registered IBs and RFEDs, regardless of whether they have any affirmative information to report.
- DSIO has requested that registrants notify the staff promptly with updated information as their evaluation of the situation evolves.
Any information submitted to DSIO pursuant to the cyber threat alerts should be sent via email to DSIOAlerts@CFTC.gov.
律师广告—Sidley Austin LLP 是一家全球性律师事务所。我们的地址及联系方式可在 www.sidley.com/en/locations/offices 查阅。
Sidley 提供本信息仅作为向客户及其他友好人士提供的服务,且仅供教育目的使用。本信息不应被解释或依赖为法律意见,亦不构成律师与客户关系。读者在未寻求专业顾问意见之前,不应依据本信息采取任何行动。Sidley 和 Sidley Austin 指 Sidley Austin LLP 及其关联合伙实体,详见 www.sidley.com/disclaimer。
© Sidley Austin LLP
联系我们
如果您对本次 Sidley 更新有任何疑问,请联系您平时合作的 Sidley 律师,或
Offices
Capabilities
Suggested News & Insights
- Stay Up To DateSubscribe to Sidley Publications
- Follow Sidley on Social MediaSocial Media Directory
