October 2017

Many hedge fund managers have spent a significant amount of time and resources improving their cyber-security measures in the last few years, and the results have impressed peers and investors alike. Larger managers in the US have been at the forefront of this trend. It would appear, at first, that their efforts have been driven by the guidance and actions of the country’s vigilant regulators. Certainly, the defensive tech of firms in jurisdictions where regulators have been vocal is superior to those in jurisdictions where regulatory expectations appear lower, such as China and mainland Europe. Ultimately, though, the biggest driver of spending has been the cyber-risks themselves; the evolving threats and ongoing vulnerabilities.

Human error remains a key concern. Larger managers have spent big on state-of-the-art firewalls and firewall vendors, but their CTOs are conscious that such measures only go so far in the face of increasingly sophisticated ‘spear phishing’ scams. Most larger managers do not expect to increase their spending on cyber-security going forward having already increased it significantly in recent years. However, our research suggests that more could be done – by managers of all sizes – in terms of educating and testing staff. Many smaller and emerging managers, for whom sophisticated attacks are less of a concern, plan to increase their spending on cyber-security. They would do well to ensure educational initiatives are given equal credence.

In fact, there is room for improvement in cyber-security themed testing more generally. Not just of staff, but systems, processes and protocols. To be fair, the bar is now high. Many emerging managers and quantitative firms have already introduced evolving systems monitoring and deep-dive independent penetration testing. But others, including some established discretionary managers struggling with legacy technology issues, are yet to embrace the full benefits of independent tests. Fear of disruption lingers. Some managers are worried that deep-dive testing is itself a risk, many others are keeping data on attacks and testing in-house to avoid the ire of investors and regulators. Progress on cyber-security has been impressive, but at a time of fierce competition for clients, fear of failure is preventing the industry from achieving the gold standard.


