19 unchanged sentences
cybersecurity program, with strategic direction aligned to the following core functions:
−Removed: We continuously assess our systems, data, and vulnerabilities to understand our cybersecurity
−Removed: risk profile.
−Removed: We enlist third-party cybersecurity consultants and vendors to support our cybersecurity efforts, tapping into their specialized
−Removed: knowledge and insights to assess and test the effectiveness of our cybersecurity program and to inform decision-making on detection and
−Removed: the deployment of defense measures, commensurate with our risk profile.
−Removed: As part of our Vendor Risk Management program, we periodically
−Removed: examine our third-party providers’ and vendors’ risks by reviewing the content and enforcement of their cybersecurity standards,
−Removed: policies, and procedures.
−Removed: We also employ real-time monitoring to detect suspicious activity in order to minimize risks associated with
−Removed: data breaches or other security incidents that may arise from third-party sources or insider threats.
−Removed: Siebert 2023 Form-10K 16
−Removed: We implement technical safeguards, including access controls, data encryption, network security,
−Removed: endpoint protection, and regular vulnerability patching.
−Removed: Our employee training and awareness programs are designed to improve cybersecurity
−Removed: awareness throughout the organization, and we are committed to educating our employees on security best practices coupled with industry-relevant
−Removed: context such as anti-money laundering, social engineering, and fraud.
−Removed: We employ automated monitoring tools and operational procedures for timely detection of anomalies,
−Removed: cybersecurity events, and potential cybersecurity incidents.
−Removed: We have a Security Incident Response Plan, supported by operational procedures, to help guide
−Removed: response teams to prioritize and execute containment, investigation, eradication, and communication for confirmed cybersecurity incidents
−Removed: Our Business Continuity & Disaster Recovery Plan is in place to enable response to significant
−Removed: business disruptions and timely restoration of systems, data, and business operations following confirmed cybersecurity incidents or disaster
+Added: We continuously assess our systems, data, and vulnerabilities
+Added: to understand our cybersecurity risk profile.
+Added: We enlist third-party cybersecurity consultants and vendors to support our cybersecurity
+Added: efforts, tapping into their specialized knowledge and insights to assess and test the effectiveness of our cybersecurity program and
+Added: to inform decision-making on detection and the deployment of defense measures, commensurate with our risk profile.
+Added: As part of our Vendor
+Added: Risk Management program, we periodically examine our third-party providers’ and vendors’ risks by reviewing the content and
+Added: enforcement of their cybersecurity standards, policies, and procedures.
+Added: We also employ real-time monitoring to detect suspicious activity
+Added: in order to minimize risks associated with data breaches or other security incidents that may arise from third-party sources or insider
+Added: We implement technical safeguards, including access
+Added: controls, data encryption, network security, endpoint protection, and regular vulnerability patching.
+Added: Our employee training and awareness
+Added: programs are designed to improve cybersecurity awareness throughout the organization, and we are committed to educating our employees
+Added: on security best practices in an industry-relevant context, relating to topics such as anti-money laundering, social engineering, and
+Added: fraud prevention.
+Added: We employ automated monitoring tools and operational
+Added: procedures for timely detection of anomalies, cybersecurity events, and potential cybersecurity incidents.
+Added: We have a Security Incident Response Plan, which
+Added: is supported by operational procedures, to help guide response teams to prioritize and execute containment, investigation, eradication,
+Added: and communication for confirmed cybersecurity incidents or breaches.
+Added: Our Business Continuity & Disaster Recovery Plan
+Added: is in place to enable response to significant business disruptions and timely restoration of systems, data, and business operations following
+Added: confirmed cybersecurity incidents or disaster scenarios.
We also incorporate industry-relevant
1 unchanged sentence
● Regulatory Compliance:
−Removed: We integrate cybersecurity controls that address requirements of FINRA, SEC, and
−Removed: other relevant regulatory bodies.
+Added: We integrate cybersecurity controls
+Added: that address requirements of FINRA, SEC, and other relevant regulatory bodies.
● Financial Transaction Security:
−Removed: We employ specific fraud detection and prevention measures to protect
−Removed: client funds and trading operations.
+Added: We employ specific fraud detection
+Added: and prevention measures to protect client funds and trading operations.
● Market Integrity:
−Removed: We strive to safeguard systems and data that contribute to fair and efficient markets.
−Removed: However, this does not mean
−Removed: that we meet any particular technical standards, specifications, or requirements, but only that we use the NIST CSF as a guide to help
−Removed: us identify, assess, and manage cybersecurity risks relevant to our business.
+Added: We strive to safeguard systems and data
+Added: that contribute to fair and efficient markets.
+Added: This does not mean that we
+Added: meet any particular technical standards, specifications, or requirements, but only that we use the NIST CSF as a guide to help us identify,
+Added: assess, and manage cybersecurity risks relevant to our business.
Our cybersecurity program
2 unchanged sentences
As of the filing of this Report,
−Removed: we are not aware of any cybersecurity incidents that have occurred since the beginning of 2023 that have materially affected, or are reasonably
−Removed: likely to materially affect us, including our business strategy, results of operations or financial condition.
−Removed: We acknowledge that we
−Removed: cannot eliminate all security risks within our organization, and we cannot guarantee that any undetected cybersecurity incidents have
+Added: we are not aware of any cybersecurity incidents that occurred during the fiscal year ended December 31, 2024 that have materially affected,
+Added: or are reasonably likely to materially affect us, including with respect to our business strategy, results of operations or financial
+Added: We acknowledge that we cannot eliminate all cybersecurity risks within our organization, and we cannot guarantee that any undetected
+Added: cybersecurity incidents have occurred.
For additional information about these risks, see Part I, Item 1A, - Risk Factors of this Report.
8 unchanged sentences
Our Chief Technology Officer (“CTO”), whose experience includes approximately
−Removed: 25 years of managing technology strategy and programs at public financial services organizations, also has key responsibilities and input
−Removed: into the management of our cybersecurity risks from a technology perspective.
−Removed: In order to monitor the prevention, detection, mitigation
−Removed: and remediation of cybersecurity incidents, our CISO, CTO, and respective technology and operations teams monitor the cybersecurity threat
−Removed: landscape, plan and implement security controls, and detect and respond to cybersecurity threats and incidents using a combination of
−Removed: security tooling, automated systems, and manual processes.
+Added: 25 years of managing technology strategy and programs at public financial services organizations.
+Added: The CTO also has key responsibilities
+Added: and provides input into the management of our cybersecurity risks from a technology perspective.
+Added: In order to monitor the prevention, detection,
+Added: mitigation and remediation of cybersecurity incidents, our CISO, CTO, and respective technology and operations teams monitor the cybersecurity
+Added: threat landscape, plan and implement security controls, and detect and respond to cybersecurity threats and incidents using a combination
+Added: of security tooling, automated systems, and manual processes.
Our Board of Directors, through
5 unchanged sentences
incidents and breaches, and cybersecurity-related matters involving third parties or vendors.
−Removed: Siebert 2023 Form-10K 17
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.