The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →On September 20, 2022, the Securities and Exchange Commission announced that Morgan Stanley Smith Barney LLC (MSSB) agreed to pay a $35 million civil penalty over failures to safeguard personal identifying information connected to approximately 15 million customers. The SEC described two distinct control failures: inadequate oversight of a contractor handling decommissioned equipment, and problems reconciling local servers and activating encryption.
What led to the SEC settlement?
The SEC said MSSB’s safeguarding failures stretched over five years and involved both outsourced equipment disposal and internal controls over local servers. These were separate routes by which customer information could remain exposed.
Contractor handling of decommissioned equipment
Beginning as far back as 2015, MSSB hired a moving and storage company that lacked data-destruction expertise to decommission thousands of hard drives and servers containing customer personal identifying information. The SEC said MSSB did not adequately monitor the contractor’s work over several years. The contractor sold thousands of MSSB devices to a third party; some devices containing customer information were later resold on an internet auction site without that information being removed. MSSB recovered some devices, but the SEC said most had not been recovered. The SEC’s announcement describes the contractor and resale chain.
Missing local servers and inactive encryption
Separately, during a broader hardware refresh and decommissioning of local office and branch servers, a firm reconciliation found 42 servers missing. Each potentially contained unencrypted customer personal information and consumer report information. The SEC also said MSSB learned that local devices had encryption capability, but the encryption software had not been activated for years. The 42 servers were described as potentially containing that information; the announcement does not establish that every missing server held it.
#1 Best Overall
What did MSSB agree to, and what did it admit?
MSSB agreed to pay a $35 million civil penalty and consented to an SEC order finding violations of Regulation S-P’s Safeguards and Disposal Rules. The order states that MSSB consented without admitting or denying the findings, apart from jurisdictional matters specified in the order. The SEC order sets out the legal terms.
What is—and is not—established about customer harm?
The SEC described exposure risks involving information associated with approximately 15 million customers. The announcement and order do not establish confirmed identity theft, customer financial losses, or a separate customer compensation or claims process for this matter. The penalty was an SEC civil penalty; it should not be read as a customer payout program.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why the two failures matter
The contractor episode concerned vendor selection, oversight, and the chain of custody for equipment being disposed of. The local-server episode concerned asset reconciliation and encryption controls inside the firm. Treating both as a single lost-device incident obscures the different safeguards implicated: an organization needs to verify what a disposal vendor does with storage media and also track its own equipment and ensure available encryption is actually enabled.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




