Connect with us
European Gaming Congress 2024

Fintech

SEC Announces Three Actions Charging Deficient Cybersecurity Procedures

Published

on

Washington, D.C.–(Newsfile Corp. – August 30, 2021) – The Securities and Exchange Commission today sanctioned eight firms in three actions for failures in their cybersecurity policies and procedures that resulted in email account takeovers exposing the personal information of thousands of customers and clients at each firm. The eight firms, which have agreed to settle the charges, are: Cetera Advisor Networks LLC, Cetera Investment Services LLC, Cetera Financial Specialists LLC, Cetera Advisors LLC, and Cetera Investment Advisers LLC (collectively, the Cetera Entities); Cambridge Investment Research Inc. and Cambridge Investment Research Advisors Inc. (collectively, Cambridge); and KMS Financial Services Inc. (KMS). All were Commission-registered as broker dealers, investment advisory firms, or both.

According to the SEC’s order against the Cetera Entities, between November 2017 and June 2020, cloud-based email accounts of over 60 Cetera Entities’ personnel were taken over by unauthorized third parties, resulting in the exposure of personally identifying information (PII) of at least 4,388 customers and clients. None of the taken over accounts were protected in a manner consistent with the Cetera Entities’ policies. The SEC’s order also finds that Cetera Advisors LLC and Cetera Investment Advisers LLC sent breach notifications to the firms’ clients that included misleading language suggesting that the notifications were issued much sooner than they actually were after discovery of the incidents.

According to the SEC’s order against Cambridge, between January 2018 and July 2021, cloud-based email accounts of over 121 Cambridge representatives were taken over by unauthorized third parties, resulting in the PII exposure of at least 2,177 Cambridge customers and clients. The SEC’s order finds that although Cambridge discovered the first email account takeover in January 2018, it failed to adopt and implement firm-wide enhanced security measures for cloud-based email accounts of its representatives until 2021, resulting in the exposure and potential exposure of additional customer and client records and information.

According to the SEC’s order against KMS, between September 2018 and December 2019, cloud-based email accounts of 15 KMS financial advisers or their assistants were taken over by unauthorized third parties, resulting in the PII exposure of approximately 4,900 KMS customers and clients. The SEC’s order further finds that KMS failed to adopt written policies and procedures requiring additional firm-wide security measures until May 2020, and did not fully implement those additional security measures firm-wide until August 2020, placing additional customer and client records and information at risk.

“Investment advisers and broker dealers must fulfill their obligations concerning the protection of customer information,” said Kristina Littman, Chief of the SEC Enforcement Division’s Cyber Unit. “It is not enough to write a policy requiring enhanced security measures if those requirements are not implemented or are only partially implemented, especially in the face of known attacks.”

The SEC’s orders against each of the firms finds that they violated Rule 30(a) of Regulation S-P, also known as the Safeguards Rule, which is designed to protect confidential customer information. The SEC’s order against the Cetera Entities also finds that Cetera Advisors LLC and Cetera Investment Advisers LLC violated Section 206(4) of the Advisers Act and Rule 206(4)-7 in connection with their breach notifications to clients. Without admitting or denying the SEC’s findings, each firm agreed to cease and desist from future violations of the charged provisions, to be censured and to pay a penalty. The Cetera Entities will pay a $300,000 penalty, Cambridge will pay a $250,000 penalty, and KMS will pay a $200,000 penalty.

The SEC’s investigations were conducted by Arsen Ablaev, Christine Jeon, and Peter Senechalle of the Cyber Unit and Stephanie Reinhart of the Complex Financial Instruments Unit in the Chicago Regional Office, and supervised by Amy Flaherty Hartman and Ms. Littman of the Cyber Unit. The examinations that led to the investigations were conducted by the Chicago Regional Office and the New York Regional Office with the assistance of the National Examination Program. The examination teams included Joseph Atatsi, Kristine Baker, Daniel Dewaal, Mark Fearer, Richard Hannibal, Donald Hirata, Bradley Kartholl, Steve Lika, Thomas Meier, Paul Mensheha, Salvatore Montemarano, David Mueller, Edward Schmidt, Atif Shameem, Jennifer Spicher, Molly Thompson, Timothy Trainor, Mathew Varghese, and Michael Wells.

Fintech

CARD91 Launches Revolutionary 3-in-1 Card Platform at Global Fintech Fest 2024: Pioneering ID and Payment Integration

Published

on

card91-launches-revolutionary-3-in-1-card-platform-at-global-fintech-fest-2024:-pioneering-id-and-payment-integration

 

CARD91 proudly announces the launch of its 3-in-1 card platform at the prestigious Global Fintech Fest 2024. This innovative solution merges an ID Card, Access, and Prepaid Card functionalities, including NCMC, into one streamlined product, tailored for the modern needs of Corporate Employees and Students alike. Apart from these use cases, this card can be used in multiple scenarios like proper management of large-scale events, in medical institutions, shopping malls, and many more.

Unlock the Future with a Single Tap

This 3-in-1 card platform is set to redefine how organisations and their employees handle professional and financial transactions. By integrating multiple services into one card, users can now enjoy unparalleled convenience, improved security, and increased flexibility.

Platform Capabilities:

  • Mobile-First Design: Optimised for mobile access, ensuring a seamless experience for both users and issuers.
  • User-Friendly Interface: Intuitive portals and customisable dashboards simplify management, enhancing operational efficiency for corporates.
  • Regulatory Compliance: Fully aligned with RBI guidelines, ensuring secure, compliant transactions.
  • Enhanced Security: Equipped with numberless EMV cards, multi-factor authentication, and PCI DSS-compliant data storage for robust fraud protection.
  • Configurable Integration: Open APIs allow easy adaptation and integration with various business systems.
  • End-Use Control: Customisable settings for transaction limits, whitelisting/blacklisting MCCs/MIDs for enhanced expenditure control.

Card Benefits:

  • Multipurpose Functionality: A unified solution for both business and personal use, simplifying everyday interactions.
  • Convenient Mobility: NCMC-enabled, allowing users to skip metro queues and streamline daily commutes.
  • Environmentally Friendly: Reduces carbon footprint by consolidating multiple functions into one eco-friendly card.

A New Era of Integration and Convenience

“We are thrilled to introduce this pioneering 3-in-1 card platform. This product represents our vision of the future, where technology seamlessly integrates into our everyday lives, from unlocking office doors to making secure online purchases and tapping to pay at the store. This launch also signifies our preparedness to enable APAAR Cards for students,” said CARD91 CEO, Ajay Pandey.

He added, “This launch marks a significant step forward in digital convenience, and we extend our sincere thanks to NSDL Payments Bank and NPCI for their support in making this possible.”

The post CARD91 Launches Revolutionary 3-in-1 Card Platform at Global Fintech Fest 2024: Pioneering ID and Payment Integration appeared first on HIPTHER Alerts.

Advertisement
Continue Reading

Fintech

Ibanera Teams Up with Visa to Drive Digital Payment Solutions

Published

on

ibanera-teams-up-with-visa-to-drive-digital-payment-solutions

Leading digital banking platform Ibanera, spearheaded by CEO Michael Carbonara, announced today its collaboration with Visa, a world leader in digital payments. This opportunity will enable Ibanera to leverage Visa’s card issuing capabilities to support its clientele’s banking and finance needs.

Ibanera’s integration with Visa’s payment network will enhance accessibility to domestic and cross-border payments for businesses and their customers. The collaboration provides Ibanera with the scalability to grow its fintech enablement services to meet growing customer demand.

Michael Carbonara, CEO of Ibanera, emphasized the significance of this collaboration for the growth of the payment ecosystem: “Navigating the complexities of regulation and payments can be challenging. This is why we are excited about our strong collaboration with Visa, which will drive innovation and provide simplified solutions as we focus on the digital and creator economies.”

Ibanera’s collaboration with Visa provides an ecosystem not only for global payments but also leverages Visa’s advanced security and fraud protection systems, such as Visa’s zero liability policy for unauthorized transactions, giving cardholders peace of mind through trust in the cards utilized.

Visa Senior Vice President of Digital Partnerships, James Schinella says, “Our alliance with Ibanera underscores our shared commitment to enhancing the payments ecosystem. Our joint efforts will provide advanced security and fraud protection, ensuring peace of mind for cardholders.”

The post Ibanera Teams Up with Visa to Drive Digital Payment Solutions appeared first on HIPTHER Alerts.

Continue Reading

Fintech

Gaia-X Introduces the Compliance Document to Enable and Increase Trust, Security, and European Sovereignty in Digital Ecosystems

Published

on

gaia-x-introduces-the-compliance-document-to-enable-and-increase-trust,-security,-and-european-sovereignty-in-digital-ecosystems

 

Gaia-X, a leading European initiative aimed at establishing a secure, transparent, and interoperable digital infrastructure, has unveiled its Compliance Document. This essential framework defines the standards that data providers, data consumers, data exchanges, and digital infrastructures must follow to participate in the Gaia-X ecosystem. Aligned with the core European values of transparency, data protection, and cybersecurity, the document promotes innovation and competitiveness while ensuring that organisations operate globally under clear, standardised rules.

Why Gaia-X Compliance Matters

The Gaia-X Compliance Document is not just a set of rules but a foundational guide for creating trust in the evolving digital marketplace. It focuses on three key areas:

  1. Openness and Transparency: Gaia-X supports global efforts to create interoperable data spaces built on federated cloud infrastructures. By ensuring transparency in operations, data handling, and service processes, Gaia-X fosters trust across the entire ecosystem, ensuring stakeholders have clear insight into the services they use.
  2. Security and Data Protection: In compliance with GDPR and other European regulations, such as the Data Act and Data Governance Act, Gaia-X ensures that personal and non-personal data are handled securely. Service providers are required to implement strong privacy protections and technical safeguards, offering businesses and users peace of mind.
  3. European Sovereignty: At its core and especially with its Label Level 3, Gaia-X guarantees European control over digital infrastructure, ensuring that services comply with European laws and standards. However, Gaia-X is designed with global interoperability in mind, providing tools and frameworks that can be adapted to meet the regulations of other regions worldwide.

Key Components of Gaia-X Compliance

1. Standards-Based Approach: The Gaia-X compliance framework builds on globally recognised standards, ensuring a high level of security and compliance across industries.

2. Label System for Differentiation: Gaia-X has introduced a clear labelling system to categorise services based on their level of compliance:

  • Gaia-X Standard Compliance: A universal set of standards designed to apply to all types of providers worldwide.
  • Gaia-X Label Level 1: Entry-level compliance with standard data protection and security following European laws.
  • Gaia-X Label Level 2: Higher-level data protection and security standards following European laws and widely based on certifications.
  • Gaia-X Label Level 3:  The highest compliance level for services requiring exceptional data handling, security, and legal control for European providers only.

These labels provide clarity for both providers and users, ensuring transparency in service offerings.

3. Trust Anchors and Continuous Validation: Gaia-X ensures ongoing trust and compliance through its Trust Framework, powered by the Gaia-X Digital Clearing House (GXDCH). This system continuously validates verifiable credentials, allowing automated trust assessments across the ecosystem.

Benefits for Ecosystem Participants

The Gaia-X Compliance offers significant advantages to both service providers and users:

Advertisement
  • For Users: Businesses and governments benefit from greater choice, transparency, and control over the digital services they utilise. With Gaia-X’s clear compliance standards, users can confidently select services that meet their specific security, privacy, compliance or sovereignty needs, allowing them to select their preferred Label Level while maintaining flexibility and avoiding vendor lock-in.
  • For Providers: Gaia-X offers a clear path to certification and compliance, enabling companies to demonstrate adherence to top-tier security and privacy standards. By aligning with European regulations, providers enhance their credibility, position themselves as digital market leaders, and answer to market demand. The standardised use of the Gaia-X Ontology ensures that cloud providers can achieve true interoperability across ecosystems.

The Gaia-X Compliance Document highlights Europe’s commitment to digital sovereignty, security, and trust, providing a foundation for a trusted digital marketplace aligned with European values and laws. It serves as a blueprint for global organisations to operate securely, transparently, and interoperably.

 

The post Gaia-X Introduces the Compliance Document to Enable and Increase Trust, Security, and European Sovereignty in Digital Ecosystems appeared first on HIPTHER Alerts.

Continue Reading

Trending