Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Morgan Stanley Smith Barney Agrees to $35 Million SEC Penalty Over Customer Data Safeguards

The SEC announced a $35 million penalty for Morgan Stanley Smith Barney over failures involving a data-disposal contractor, 42 missing servers and inactive encryption controls.
From TheFinanceBase Team2 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On September 20, 2022, the Securities and Exchange Commission announced that Morgan Stanley Smith Barney LLC (MSSB) agreed to pay a $35 million civil penalty over failures to safeguard personal identifying information connected to approximately 15 million customers. The SEC described two distinct control failures: inadequate oversight of a contractor handling decommissioned equipment, and problems reconciling local servers and activating encryption.

What led to the SEC settlement?

The SEC said MSSB’s safeguarding failures stretched over five years and involved both outsourced equipment disposal and internal controls over local servers. These were separate routes by which customer information could remain exposed.

Contractor handling of decommissioned equipment

Beginning as far back as 2015, MSSB hired a moving and storage company that lacked data-destruction expertise to decommission thousands of hard drives and servers containing customer personal identifying information. The SEC said MSSB did not adequately monitor the contractor’s work over several years. The contractor sold thousands of MSSB devices to a third party; some devices containing customer information were later resold on an internet auction site without that information being removed. MSSB recovered some devices, but the SEC said most had not been recovered. The SEC’s announcement describes the contractor and resale chain.

Missing local servers and inactive encryption

Separately, during a broader hardware refresh and decommissioning of local office and branch servers, a firm reconciliation found 42 servers missing. Each potentially contained unencrypted customer personal information and consumer report information. The SEC also said MSSB learned that local devices had encryption capability, but the encryption software had not been activated for years. The 42 servers were described as potentially containing that information; the announcement does not establish that every missing server held it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

What did MSSB agree to, and what did it admit?

MSSB agreed to pay a $35 million civil penalty and consented to an SEC order finding violations of Regulation S-P’s Safeguards and Disposal Rules. The order states that MSSB consented without admitting or denying the findings, apart from jurisdictional matters specified in the order. The SEC order sets out the legal terms.

What is—and is not—established about customer harm?

The SEC described exposure risks involving information associated with approximately 15 million customers. The announcement and order do not establish confirmed identity theft, customer financial losses, or a separate customer compensation or claims process for this matter. The penalty was an SEC civil penalty; it should not be read as a customer payout program.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the two failures matter

The contractor episode concerned vendor selection, oversight, and the chain of custody for equipment being disposed of. The local-server episode concerned asset reconciliation and encryption controls inside the firm. Treating both as a single lost-device incident obscures the different safeguards implicated: an organization needs to verify what a disposal vendor does with storage media and also track its own equipment and ensure available encryption is actually enabled.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.