← Broker database 2024-02-14

Ceros Financial Services Fined $75,000 for Email Supervision and Data Security Failures

fined $75,000

According to FINRA, Ceros Financial Services, Inc. was sanctioned for failing to reasonably supervise business-related communications conducted through external email and for failing to safeguard customer information.

Despite being notified that at least one registered representative was using personal email for business communications, the firm implemented an inadequate system that merely sent automated warnings when incoming emails originated from known employee personal email addresses. The firm did not review these communications unless they met other supervisory criteria, nor did it treat them as red flags that other external business communications might not be captured. Because some business-related emails were sent directly between representatives' personal emails and customers without copying the firm, Ceros cannot quantify how many business-related emails were never preserved or reviewed.

The firm also failed to adopt adequate policies and procedures to safeguard customer information. Over 10,000 emails were sent between known employee personal email addresses and firm email addresses, yet the firm had no reasonable process to prevent employees from sending customer information to unsecure locations or to review these emails for customer information. Furthermore, Ceros failed to develop and implement an identity theft prevention program, relying instead on a privacy policy that lacked specific procedures for identifying, detecting, and responding to red flags of identity theft.

This case serves as a critical reminder that broker-dealers must maintain comprehensive systems to capture and review all business communications, regardless of the platform used. For investors, proper email retention and supervision helps ensure accountability and protects their sensitive personal information from unauthorized disclosure or theft.

Source: FINRA disciplinary actions (PDF)