
Cyber Defense: Private Funds & Banks
An interview with Michelle A. Reed
Banks, private funds, and other financial firms hold exactly what cybercriminals want: money, investor data, and market-moving information. As firms rely more on technology and outside vendors, regulators have moved from general expectations to specific rules on security programs, vendor oversight, breach notification, and data retention.
In this TalksOnLaw interview, Joel Cohen sits down with Michelle Reed, then a partner leading Akin Gump's cybersecurity, privacy, and data protection practice and now co-chair of the Data Privacy & Cybersecurity group at Paul Hastings, to walk through the threats facing the financial sector and the regulatory regime that has grown up around them.
From Stolen Numbers to Stolen Millions
The stakes, Reed explains, have moved from stolen Social Security numbers to millions of dollars in wire fraud and stolen market-moving information. In a typical business email compromise, criminals get into a mailbox through a phishing link, often a fake "mailbox full" login page, and then sit quietly for weeks, studying who approves payments and how. When they strike, the payment instructions come from the real account, so the bank's verification call goes to the criminals. The money hops quickly from London to the Caribbean and beyond, often through accounts opened by unwitting money mules recruited through online dating sites. Reed describes a client that lost tens of millions of dollars over a series of transfers. Her first and easiest fix is two-factor authentication on email, which takes away the low-hanging fruit even if it can be beaten.
Advanced Persistent Threats
Nation-state and other sophisticated actors play a longer game. They hide in a network without leaving obvious tracks, so firms must bring in specialized threat hunters, who work without tipping off the intruder. Private equity firms with seats on portfolio-company boards are attractive targets for industrial espionage, and groups such as FIN4 have stolen deal information to trade on the markets. The richer a firm's information, Reed says, the bigger the target.
Ransomware and the Ransom Decision
Ransomware encrypts every machine it can reach and demands payment in cryptocurrency, sometimes well over a million dollars. Companies once refused to pay on principle, but after seeing the business losses many bought cyber insurance that covers ransom payments. Reed's first question is always whether the firm can restore from a backup kept safely apart from its systems. If it cannot, paying may be the only option, but firms must make sure the attackers are not on a U.S. sanctions list, and they must consider whether the attackers left a way back in.
Cloud Mistakes and the SEC's Exam Approach
Misconfigured cloud storage is another common source of exposure, often discovered by security researchers who scan for it, and every such incident raises the question of whether notification is required. For investment advisers, the SEC first signaled its expectations through examination requests, asking about cybersecurity preparedness, wire-fraud controls, and disaster recovery, alongside long-standing rules such as Regulation S-P for safeguarding customer information and Regulation S-ID for identity-theft red flags.
Principles-Based Rules and the NIST Framework
Longstanding federal rules for investment firms require administrative, technical, and physical safeguards for customer information but never define them in detail. Reed calls that vagueness a strength, because the rules evolve with technology, and a challenge, because clients must decide what "technical safeguards" mean. Regulators hoped industry would regulate itself using the NIST Cybersecurity Framework developed after a presidential executive order. When that moved too slowly, states stepped in.
New York DFS and Vendor Oversight
The New York Department of Financial Services' cybersecurity regulation set detailed requirements, such as encrypting sensitive data at rest and in transit or documenting in a risk assessment why it is unnecessary. Reed notes that security and convenience are inversely related, which is why encryption at rest is often resisted. The regulation's vendor provisions matter especially for investment funds, which often outsource cybersecurity and fund administration. Firms need both diligence on vendors and contract terms requiring protection of data and prompt notice of breaches.
Breach Notification: Fifty-Plus Standards
Federal law largely governs investment funds, but notification is an exception: without a federal notice requirement, state breach laws apply. Every state, plus U.S. territories, has its own standard. New York's SHIELD Act, for example, moved to an access-based trigger, so notice may be required when information was accessed even if theft cannot be shown. Europe's GDPR requires notifying regulators within 72 hours. Firms must quickly decide whether an incident is a "capital-B Breach" requiring notice. Notification and credit monitoring are costly, and consumers now experience "data breach fatigue."
Incident Response and Tabletop Exercises
The SEC wants to see governance: an incident response plan, a pre-identified response team, and practice through tabletop exercises that simulate a breach. Reed says many investment funds have not practiced, so their first real breach becomes a stressful tabletop. A small, quickly contained "baby breach" can be a blessing because it forces governance changes. What worries her most is data integrity: attackers quietly altering positions or records in ways a firm might never detect without proper logging.
People, Phishing, and Detection
Every breach Reed has handled involved a human mistake, so the key is preparing to respond. Employees are highly trainable. Initial phishing exercises often see half of employees click, and training can bring that down to a few percent. Even careful people can be compromised through a hacked third-party site they visit every day. Newer tools learn normal user behavior and flag anomalies, such as a login at 4 a.m. from another country, and logging software helps reconstruct an attack.
Questions Every Firm Should Ask
Reed's checklist: Have we done a risk assessment and a gap analysis, and fixed the gaps? Do we penetration-test at least annually? Is our budget aligned with our biggest risks? Who owns cybersecurity internally, especially when it is outsourced? She also warns against discussing a breach over compromised email. Attackers watch the response and stay ahead of investigators, so firms need out-of-band communication channels and secure conference lines.
Regulators and Enforcement
Notice may be owed to affected individuals and to regulators, which for funds means the SEC and, for futures activity, the CFTC and National Futures Association. The SEC relies on principles such as Regulation S-P and Regulation S-ID and enforces through individual cases. The CFTC and NFA have more detailed rules. Reed describes a CFTC case in which a firm refunded a customer $1 million lost to wire fraud but was fined $500,000 for failing to tell other customers. Internal emails urging staff to keep the breach confidential showed that the firm itself considered the information important.
Delete Data You Don't Need
After turning on two-factor authentication, the easiest way to reduce risk, Reed says, is to delete data. That means adopting a retention and destruction policy consistent with recordkeeping rules and following it. The Sony hack became a lasting embarrassment largely because of old emails. In an SEC case she describes, a small company's breach became a big one because it had kept years of job applicants' data. California's new consumer privacy law, and similar proposals in other states, were making data mapping and retention central to compliance.
What to Know Now
The regime Reed described has become far more detailed. In 2024 the SEC amended Regulation S-P to require broker-dealers, investment advisers, and funds to maintain incident response programs, notify affected individuals within 30 days of a qualifying breach, and oversee service providers, with compliance phased in over 2025 and 2026. Public companies must now disclose material cybersecurity incidents within four business days of determining materiality and describe their cyber risk management and governance annually. New York DFS substantially amended its cybersecurity regulation in 2023, adding requirements for governance, universal multifactor authentication, asset inventories, and prompt reporting of ransom payments. New York also shortened its consumer notification deadline to 30 days. The SEC's examination office, then known as OCIE, was renamed the Division of Examinations in 2020. NIST's Cybersecurity Framework 2.0 added a new "Govern" function that echoes Reed's emphasis on ownership and oversight.
The patchwork she predicted has grown. About two dozen states have enacted comprehensive consumer privacy laws, and there is still no federal privacy statute. The SEC's 2022 proposal for detailed cybersecurity rules for advisers and funds was withdrawn in 2025, and enforcement priorities have shifted under new leadership. A federal court dismissed most of the SEC's high-profile case against SolarWinds and its security chief in 2024, and the SEC voluntarily dropped the remaining claims in November 2025. Ransomware remains a leading threat, and the Treasury Department's Office of Foreign Assets Control has warned that paying ransoms to sanctioned actors can itself create liability. California's privacy law, which Reed described as coming down the line, took effect in 2020 and was later expanded and placed under a dedicated state privacy agency. SEC recordkeeping enforcement against firms whose staff used unapproved messaging apps has also underscored her point that retention and communication policies must be enforced in practice. Her bottom line holds: regulators focus less on whether a firm was breached than on whether it prepared and responded well.
About Michelle A. Reed
“Convenience and security are inversely related. The more secure [a cybersecurity system] is, the more inconvenient it is.”


