Cybersecurity and Risk Insights and Alerts
Cyber risks and threats continue to evolve, and firms are under pressure to meet SEC and FCA expectations for operational resilience as well as their own internal and client expectations for cybersecurity and privacy. Stay current on the latest cybersecurity, privacy, and risk threat and regulatory alerts, and build your cybersecurity and privacy knowledge with insights from our cybersecurity and technology risk experts.
ACA Aponix Cybersecurity Checklist
Cyber alerts and insights

Apple® Issues Patch to Fix Spyware Vulnerability
A vulnerability has been discovered in Apple products that enables the installation of unauthorized software without the user's permission. The vulnerability is actively used to install Pegasus spyware on devices, allowing user activities to be surveilled by an external party.
- Cybersecurity

Microsoft® Reports “Zero-Day” Attacks Using Tainted Office® Files
Microsoft reports a previously unseen “zero-day” attack that uses Office files tainted with specially crafted Active X controls. Once opened, these controls create a vulnerability that enables perpetrators to perform remote code execution.
- Cybersecurity

China Passes Data Privacy Law That Affects Chinese and Foreign Companies
The Personal Information Protection Law of the People's Republic of China is scheduled to go into effect on November 1, 2021. This new law affects all companies and other entities, both inside and outside of China, engaged with personal information about individuals residing in China.
- Privacy
- Cybersecurity

ACA’s Spring 2021 Virtual Conference: Key Takeaways and Trends
ACA’s Spring 2021 Virtual Conference was an opportunity for the regulatory compliance, performance, and cybersecurity community to come together and discuss the many changes of the past year and what the future of GRC looks like moving forward.
- Compliance
- ComplianceAlpha
- ESG
- GIPS Standards
- RegTech
- Cybersecurity
- Performance
- Privacy

SEC Sanctions Registered Investment Advisers and Broker-Dealers for Cybersecurity Failures
The SEC announced that it sanctioned eight firms for failure to establish and implement cybersecurity policies and procedures. These failures resulted in multiple instances of criminal email account takeovers causing personally identifiable information from thousands of customers and clients to be exposed.
- Cybersecurity
- Compliance

Key Takeaways from 1LoD’s Resilience, Cyber, and 3rd Party Risk Deep Dive Report
Industry analyst 1LoD recently hosted a two-day Deep Dive on operational resilience, cybersecurity, and third-party risk. Attendees represented financial institutions (75%), technology firms (13%), consultancies (11%), and regulators (1%) from around the world. Speakers featured experts in resilience and cybersecurity, including ACA Aponix® Partner Michael Pappacena. We recommend downloading the full report to get a sense for what your peers are doing, how your firm compares, what regulators expect, and what you need to do to build a stronger operational resilience program.
- Cybersecurity