Quantifying Cybersecurity Risks

A cybersecurity risk modelling expert discusses the science of planning for an unpredictable data breach.

Cybersecurity breaches continue to ripple through the retirement plan industry, sometimes due to human error, sometimes occurring at third-party vendors.

But retirement providers are not alone. According to a recent report by cybersecurity risk modeling and management firm Kovrr, when considering S&P 500 companies, at least eight could see a 10% annual profit loss due to a cyberattack in the next year.

For more stories like this, sign up for the PLANADVISERdash daily newsletter.

Yakir Golan, Kovrr’s co-founder and CEO, notes that while that may be a relatively small number of firms, those types of financial costs can have a “ripple effect” that can destabilize “investor confidence and the overall economy.”

PLANADVISER spoke to Golan about the risks and safety measures retirement services and financial firms can take.

PLANADVISER: The report shows that financial services firms are generally better protected from cybersecurity issues when compared to others. That said, as retirement plan assets house both money and client data, what are some ways these types of firms can go above and beyond?

Golan: The finance industry, largely due to its attractiveness to malicious cyberactors, is more regulated than other sectors, which is why financial institutions comparatively face some of the lowest financial damages in the wake of an event—both in the long and short term. However, compliance is merely one factor that contributes to the reduction in an organization’s financial exposure due to cyber risk.

Reaching a state of true cyber resilience also requires that all stakeholders, including board members and non-technical C-suite executives, take an active role in cyber risk management and learn how to integrate it into every high-level decisionmaking process. Given cyber risk’s potential to affect every aspect of the organization, from payment processes to supply chain logistics, it should be viewed as a broader business risk, managed with the same rigor and attention as any other.

PLANADVISER: How, specifically, can leaders incorporate a strong cybersecurity process?

Golan: While many of these stakeholders are starting to recognize [the] necessary mindset, they’ve had trouble implementing it due to cybersecurity’s notoriously complex nature. To rectify the situation and effectively elevate cyber resilience efforts to the next level, firms need to quantify cyber risk, translating the complex, technical terms into a language they’re already deeply familiar with, such as event likelihoods and resulting financial impacts.

With the quantified insights, it becomes much easier for decisionmakers to understand the type of loss scenarios their financial company is most exposed to, along with the monetary implications should such scenarios occur, allowing them to prioritize risk mitigation efforts accordingly.

Executives can likewise gain an understanding of the risk drivers that contribute the most to these financial exposure levels, such as their vulnerability to phishing scams or supply chain compromises, giving them an indication of where resources should be allocated.

PLANADVISER: The retirement space has been compromised by popular third-party vendors being hacked. How can companies best guard against that type of vendor risk?

Golan: Supply chain (“vendor”) issues are a growing concern for many organizations, as they should be, especially as cybersecurity leaders consolidate their solutions in the hopes of reducing operational inefficiencies and data-sharing challenges. While this trend undoubtedly has many benefits, the reliance on a single vendor opens up financial companies to a new level of risk that has to be taken into account long before any such consolidations occur.

Measuring this risk cannot be done simply by relying on benchmarks or basic assessments. Institutions need to understand the degree of vulnerability that this aggregated risk introduces specifically to their risk exposure profile. To obtain this information, they can leverage on-demand cyber risk quantification models, which simulate the complexity of an organization’s supply chain and pinpoint the top associated risks. 

By adopting a CRQ solution, financial institutions can gain insights into how much their usage of a specific cloud solution or relationship with a third-party service provider exposes them to financial losses. For example, an organization may discover that utilizing WordPress as a content management system exposes them, on average, to a $5 million loss. Harnessing this data, stakeholders can then make more informed decisions, such as opting for a CMS solution that introduces less financial risk. …

While ‘full defensibility’ against third-party cyber risk is unachievable, cybersecurity leaders … operationalize their findings to reduce these financial exposure levels. Instead of consolidation, for instance, diversification may be the better choice despite the challenges it brings. Cyber risk managers can likewise invest in tailored incident response plans according to the scenario that is most likely to cause substantial financial losses. If the CMS poses the most significant monetary threat, then the most strategic move would be to implement data backup mechanisms.

Wealth Enhancement Group Acquires FinTrust Capital Advisors

The acquisition brings Wealth Enhancement Group’s assets under management to more than $94.7 billion. 

Wealth Enhancement Group, an independent wealth management firm with more than $94.7 billion in client assets, announced a further expansion of its wealth management and workplace plan advisement footprint.

WEG announced Wednesday the acquisition of FinTrust Capital Advisors LLC, which oversees more than $2.39 billion in client assets, including retirement plan advisement and services.

Never miss a story — sign up for PLANADVISER newsletters to keep up on the latest retirement plan adviser news.

Founded in 2007, FinTrust Capital Advisors is a hybrid registered investment advisory headquartered in Greenville, South Carolina, headed by CIO Allen Gillespie and including a team of 14 advisers and 13 support staff. The firm has additional office locations in Anderson, South Carolina, and Athens, Georgia. 

In addition to individual and family wealth management, FinTrust Capital Advisors offers a range of defined contribution and defined benefit plan advisement services, primarily for corporate and institutional clients. The firm provides fiduciary consulting and retirement plan consulting, focusing on helping companies of various sizes manage their employee retirement programs.

The firm’s services include advising on investment strategies, plan design and ongoing compliance to ensure that retirement benefits are optimized for both employers and employees.

“Our firm was built on the premise that the best wealth management advice combines investment management guidance, advanced financial planning, and tax strategies with strong client relationships,” Gillespie said in a statement. “Joining Wealth Enhancement Group allows us to strengthen that promise by tapping into their robust network of central services.” 

FinTrust’s services expand WEG’s institutional client offerings, particularly in retirement planning and fiduciary consulting. The acquisition also enhances WEG’s portfolio by adding expertise in managing complex retirement plans. 

 WEG has been expanding its client base in plan advisement in the last several years, recently reporting about $5 billion in retirement plan assets in retirement plan coverage. Wealth Enhancement Group’s acquisitions in 2024 include Gavin Financial Group in June, Peak Financial Management in July and Levy Wealth Management in September. The firm did not immediately respond to break down how much of its asset base is in retirement plans. 

Park Sutton Advisors, a Waller Helms company, served as the exclusive financial adviser to FinTrust Capital Advisors. 

«