Cybersecurity Policy Report, Implementing baseline best practices is key to improving cybersecurity, says PCAOB Member Hamm, (Oct 9, 2019)
Hamm also urges world’s regulators to engage in extensive information sharing and to push entities to prepare effective response and recovery plans.
PCAOB Member Kathleen Hamm believes that financial industry regulators around the world should use their leverage to encourage regulated entities to improve their cybersecurity preparedness. In remarks at a capital market regulation conference in Tokyo, Hamm said that the key elements to effective cybersecurity and resiliency includes identifying and implementing baseline protections and best practices, engaging in information sharing, and preparing an effective response and recovery plan.
Hamm acknowledged that the way that global regulators oversee and protect regulated entities necessarily varies by jurisdiction. However, she believes all regulators share the responsibility of using the tools at their disposal to try to ensure that the regulated entities have the technology, processes, and other controls to protect against cyber-incidents. Regulators should press the entities they regulate to prepare for significant cyber-incidents, she added.
PCAOB approach. The leverage that can be applied depends on the specific regulatory system, she noted. At the PCAOB, auditors and auditing standards play an important but limited role related to cybersecurity, Hamm said. Auditors are required to assess the use of IT to prepare financial statements and the automated controls associated with financial reporting, she noted, but PCAOB standards do not require auditors to assess companies’ overall business or operating risks as they relate to cybersecurity.
PCAOB standards also do not specifically address the cybersecurity of auditors themselves or even explicitly require auditors to maintain the security of their clients' information or systems, according to Hamm. However, the PCAOB does require audit professionals to exercise their skill with "reasonable care and diligence." Whether reasonable care and diligence encompasses protecting confidential client information and systems from compromise has not been tested, she said.
Hamm noted that the PCAOB has not applied its standards to any cyber-incident that may have occurred at a registered audit firm. If a significant cyber-incident occurred at a registered audit firm, Hamm said she would press for a careful assessment of whether PCAOB standards or rules had been violated, including whether the auditor had acted with reasonable care and diligence.
Auditors recognize threat. Without specific standards in place, Hamm said that she has been asking audit firms about what more they could be doing around cybersecurity to secure their clients’ data and systems. She has been pleased to find that many auditors, at least at the largest firms, recognize cybersecurity as a threat and are acutely aware of the reputational harm that could ensue if they experienced a significant cyber-event.
Consequently, some auditors are addressing cybersecurity concerns as part of their systems of quality control, Hamm said. Some have implemented cybersecurity strategies and control frameworks tailored to the firm’s specific risks, she noted, and are monitoring to ensure that those strategies and controls are being followed.
Best practices. At the PCAOB and around the globe, the proper approach starts with baseline protections and best practices, according to Hamm. The basics include multi-step identity checks before allowing access to an entity’s networks, systems, and data, and limiting special, high-level data and system access to as few people as possible. Those IT professionals with administrative rights to install software, configure systems, and grant access to other users should be subject to controls to keep their access limited, she added.
Other basic best practices include patching software in a timely and systematic manner, and instituting regular system scans for malicious activity, Hamm said. She also recommended that entities segregate their critical systems and data. This is critical, she noted, because once a breach occurs, a hacker will have unfettered access if systems are not appropriately segmented.
Information sharing. In her address, Hamm also emphasized the importance of information in trying to combat cyber attacks. Malicious cyber actors often use the same or similar methods to target multiple institutions, she noted, which is why sharing information about cyber vulnerabilities, threats, and incidents is critical.
Regulators should encourage entities to share timely, actionable information with each other, she said. Depending on the jurisdiction, sharing can be bilateral or multilateral, Hamm added. She pointed out that the financial services sector has global hubs for sharing cyber intelligence, including the Financial Services Information Sharing and Analysis Center. Other industries have specialized information sharing and analysis centers, she noted. In her current role at the PCAOB, Hamm said that she has advocating for auditors to consider establishing a mechanism to share actionable threat intelligence and vulnerability information across their profession.
Response and recovery. Even with the best protection in place, regulators should still urge entities to prepare for the likelihood of significant cyber-incidents, Hamm advised. She recommended a cyber-incident playbook that would describe who does what, when, and to whom they report when a cyber-incident happens. She said that a playbook also should cover when to get executive management and the board involved, when to call regulators and law enforcement, and when and how to notify shareholders, customers, and counterparties.
RegulatoryActivity: AccountingAuditing PCAOBNews CyberPrivacyFeed LegislativeRegulatoryActivity DataPrivacy DataSecurity