Alert:
For more information on the cybersecurity incident, please visit the cybersecurity incident page.
This Notice is for IIROC Dealer Members who use remote access services (e.g. Virtual Private Network – VPN, remote desktop, etc.) to support work from home arrangements.
Over the last couple of months, IIROC has issued Notices to firms and to advisors and employees to alert them to increased cybersecurity threats related to the pandemic.
We continue to see evolving cybersecurity threats, this time related to the use of remote access services with attackers increasingly targeting and exploiting its vulnerabilities.
Background
Remote access service vendors have advised that potential vulnerabilities are being leveraged to gain access to internal networks of various organizations. Attackers have been observed actively scanning for vulnerable configurations. Once access is gained, attackers can remain undetected and will look to obtain additional privileges to launch future attacks such as ransomware or data exfiltration.
What to do?
Firms must continue to apply general security precautions and actions to all computing resources with vigilance to external facing components such as remote access services.
We strongly recommend that your Information Technology department or services provider does the following:
Other resources
Further information and resources on managing cybersecurity threats, including guides and webinars, are available on IIROC’s cybersecurity site.
Welcome to CIRO.ca!
You can find the Canadian Investment Regulatory Organization (CIRO) at CIRO.ca with our fresh look and feel.