Tue, Nov 11, 2025
A A A
Welcome Guest
Free Trial RSS pod
Get FREE trial access to our award winning publications
Industry Updates

French regulator reviews asset management cybersecurity systems

Monday, December 16, 2019
Opalesque Industry Update - The AMF has published a review of its thematic inspections of the cybersecurity systems in place in asset management companies.

In accordance with its supervision priorities for the current year, the Autorité des Marchés Financiers reviewed the cybersecurity systems of five asset management companies. Based on its observations, it highlights the good practices noted.

During these short thematic inspections called "SPOT" (Supervision des Pratiques Opérationnelle et Thématique - operational and thematic supervision of practices), the regulator examined:

- the organisation of cybersecurity systems with regard to human and technical resources; - the governance of these systems;
- the Information System administration and surveillance systems; the cyber incident management process;
- the management of sensitive data;
- the business continuity plan;
- existing internal control of the Information System and the cybersecurity system.

For performing its work, the AMF considered cyber risk as arising from any potential malicious attack, internal or external, on one of the key features of the Information System of an asset management company, namely its availability, its integrity, the confidentiality of the data that it processes or the traceability of the actions performed in the Information system.

In this context, the AMF noted that the firms inspected are starting to address cyber risk by including it in their risk mapping, by compiling the cybersecurity incidents that they sustain and by calling on specialised service providers to verify the robustness of their Information System from time to time. However, the systems analysed do not take into account the potential impacts of the materialisation of cybersecurity risks on the firms' regulatory compliance with regard to (i) ensuring the level of regulatory capital, (ii) retention of sensitive data, (iii) maintenance of an effective business continuity plan, and (iv) maintenance of appropriate (IT) resources.

The AMF also noted the practically universal absence of mapping of (i) sensitive data and (ii) critical systems, and of a data classification policy, leading to a risk of partial coverage of major risks by the control system. Moreover, the formal identification of cyber incidents for continuous assessment of the associated risk level proves problematic in the existing compilation databases. Lastly, the vulnerabilities identified or confirmed by internal control are not corrected with sufficient speed and monitoring.

For asset management companies belonging to a Group (most of the tested sample), inadequate internal supervision of the services (relating to IT, cybersecurity and business continuity) performed by the parent company was identified. But the technical execution of these services by the Group cannot exempt asset management companies from their responsibilities regarding the definition (in priority) of the main risk areas and management of the relevant controls.

Among the best practices observed, the AMF notes, for example, the following:

- Ensuring the independence of the CISO (Chief Information Security Officer) function relative to the IS Department (Information Systems Department) either by (administrative or functional) reporting by the CISO to the Executive Committee, or by establishing a control function independent of the CISO's activities;
- Raising the AMC's employees' awareness of cybersecurity risks by including them in the annual training plan and, at least once a year, performing a test on employees' reaction to attempted phishing by email;
- Including in the AMC's business continuity strategy the regular verification of:(i) the collaborative working capacity of key personnel in a crisis situation, (ii) the ability to restore backup data, and (iii) the level of physical and IT security of the backup systems.

Conversely, the AMF noted the following poor practices:

- Deploying a cybersecurity system in the absence of (i) prior identification, (ii) classification by criticality level (on the basis of the AICT criteria) and (iii) regular review of sensitive data and Information Systems;
- In AMC risk mapping, confining the analysis of cybersecurity risks solely to the impacts of operational risk on the funds and/or portfolios managed;
- Not blocking the USB ports of user workstations;
- Deploying the process of permanent/periodic control of sensitive outside IT service providers on the basis of a non-exhaustive list of said providers.

Apart from the summary published on this day, this series of SPOT inspections gave rise to the sending of follow-up letters to the AMCs in question. Cybersecurity risks will be the subject of other AMF inspections in the coming months. In light of the observations made on completion of these inspections, the AMF plans to work out a specific cybersecurity policy proportional to the size of the players.

Press release
Bg

Read more:
Summary of SPOT inspections on cybersecurity systems of asset management companies:

Article source - Opalesque is not responsible for the content of external internet sites

What do you think?

   Use "anonymous" as my name    |   Alert me via email on new comments   |   
Previous Opalesque Exclusives                                  
Previous Other Voices                                               
Access Alternative Market Briefing

 



  • Top Forwarded
  • Top Tracked
  • Top Searched
  1. Global fintech investment slumps to seven-year low of $95.6bn[more]

    Laxman Pai, Opalesque Asia: Global fintech investment plummeted to $95.6 billion across 4,639 deals in 2024, marking its lowest level since 2017, as investors grappled with persistent macroeconomic challenges and geopolitical tensions, revealed a study. According to the Pulse of Fintech H2'

  2. Opalesque Exclusive: Private capital deal value climbed 19% in 2024[more]

    Bailey McCann, Opalesque New York: Private capital deal value climbed 19% in 2024, according to the latest data from the Global Private Capital Association. Growth was driven by big-ticket investments across Southeast Asia, Latin America and Central & Eastern Europe (CEE). Investor confidence

  3. Opalesque Roundup: Citco: 77% of hedge funds achieved positive returns in January 2025: hedge fund news[more]

    In the week ending February 21st, 2025, a report revealed that hedge funds enjoyed one of their best opening months this decade in January, as Equity and Multi-Strategy funds posted strong returns. Funds administered by the Citco group of companies (Citco) delivered a weighted average return of 4%,

  4. Opalesque exclusive: Permuto's new equity unbundling product to change investment model[more]

    Opalesque Geneva for New Managers: Here is a different way of owning stocks coming to you soon: the option of holding just the dividend portion of a stock, independent of its price movements. Or capturing the stock&

  5. Opalesque Exclusive: Hedge funds outperform mutual funds in managing extreme risk contagion - key insights for investors[more]

    Matthias Knab, Opalesque for New Managers: Hedge funds and mutual funds are among the most prominent vehicles for investors seeking growth and diversification. However, a critical question persists: which fund ty