FINRA has created a Checklist for a Small Firm’s Cybersecurity Program (Excel 114 KB) to assist small firms in establishing a cybersecurity program to:
- identify and assess cybersecurity threats, protect assets from cyber intrusions
- detect when their systems and assets have been compromised
- plan for the response when a compromise occurs
- implement a plan to recover lost, stolen or unavailable assets
This checklist is primarily derived from the National Institute of Standards and Technology (NIST) Cybersecurity Framework and FINRA’s Report on Cybersecurity Practices.
Use of this checklist does not create a “safe harbor” with respect to FINRA rules, federal or state securities laws, or other applicable federal or state regulatory requirements.