← Broker database 2023-11-03
Bolton Global Capital Fined $75,000 for Cybersecurity Failures
According to FINRA, Bolton Global Capital was fined $75,000 for failing to establish and maintain a supervisory system reasonably designed to safeguard customer records and information in violation of the Safeguards Rule.
The firm had been previously warned by FINRA to strengthen its cybersecurity practices, particularly regarding third-party service provider access. Despite enhancing some security measures like requiring multi-factor authentication for employees, the firm failed to extend these protections to third-party service providers who had administrative access to firm systems and data.
This oversight led to a significant data breach when an unauthorized third party gained access through a device used by a third-party service provider who lacked multi-factor authentication requirements. The breach exposed records and non-public personal information of firm customers. While the firm responded appropriately by self-reporting the incident, engaging cybersecurity consultants, and notifying affected customers, the breach could have been prevented with proper controls.
Investors should understand that brokerage firms have a legal obligation to protect client data through robust cybersecurity measures. Firms must implement comprehensive security protocols not just for their own employees, but also for any third-party vendors with system access. This case demonstrates the critical importance of proper supervision and monitoring of all access points to customer data, as weak security practices can expose investors to identity theft and fraud risks.