• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

SEC Fails to Take Some Basic Cybersecurity Precautions

By
Reuters
Reuters
By
Reuters
Reuters
July 27, 2017, 6:07 PM ET
The U.S. Securities and Exchange Commission (SEC) seal.
The U.S. Securities and Exchange Commission (SEC) seal.Bloomberg via Getty Images

Wall Street’s top U.S. regulator needs to improve the way it protects its own computer networks from cyber attacks, according to a new report by a congressional watchdog office.

The 27-page report by the Government Accountability Office found the Securities and Exchange Commission did not always fully encrypt sensitive information, used unsupported software, failed to fully implement an intrusion detection system and made missteps in how it configured its firewalls, among other things.

“Information security control deficiencies in the SEC computing environment may jeopardize the confidentiality, integrity, and availability of information residing in and processed by its systems,” the GAO said.

“Until SEC mitigates its control deficiencies, its financial and support systems and the information they contain will continue to be at unnecessary risk of compromise.”

The SEC, as Wall Street’s top regulator, houses a tremendous amount of sensitive and confidential information that it must closely safeguard to protect against identity theft or efforts by cyber criminals who might want to use the information for insider-trading or harming U.S. equity markets.

Get Data Sheet, Fortune’s technology newsletter.

The GAO report did give credit to the SEC for making improvements, saying that since September 2016, the agency had resolved 47 of 58 different recommendations previously made by the watchdog office.

However, the GAO noted that 11 recommendations to protect against cyber intrusions remain outstanding, and another 15 new control deficiencies were identified in the GAO’s latest review.

For more about cybersecurity, watch:

Among some of its new recommendations include maintaining up-to-date network diagrams and performing continuous monitoring on its operating systems, databases and network devices.

In a July 14 letter, SEC Chief Information Officer Pamela Dyson said the agency concurs with the recommendations and that it has fixed or plans to fix the problems that were identified.

An SEC spokeswoman did not comment beyond the letter responding to the GAO’s conclusions.

About the Author
By Reuters
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.