Skip to content
English
  • There are no suggestions because the search field is empty.

Why is it important that my financial website comply with NFA requirements?

If your firm is a member of the National Futures Association (NFA), such as a futures commission merchant (FCM), introducing broker (IB), commodity pool operator (CPO) or commodity trading advisor (CTA), your website and the systems behind it are part of your regulatory obligations. NFA rules cover both how you protect your systems and customer data and what your website says.

Please note: this article is general information, not legal or compliance advice. Always confirm your firm's obligations with your compliance officer or legal counsel.

1. You need a written cybersecurity program

NFA requires members to adopt and enforce a written information systems security program (ISSP) under Interpretive Notice 9070. The ISSP must address the risk of unauthorized access to, or attacks on, your technology systems and how you'll respond if an attack happens. Your website, email, CRM and hosting are all part of those systems.

NFA doesn't mandate specific technologies. Instead, each firm tailors its program to its own risks. Key requirements include:

  • Risk assessment: identify your systems, the data you hold and the threats you face.
  • Safeguards: put protections in place, such as access controls, software updates, backups and monitoring.
  • Incident response plan: know how you'll detect, respond to and recover from an attack, and who you'll notify.
  • Employee training: train staff on your ISSP when they're hired and at least once a year.
  • Senior approval: your CEO, or another senior officer responsible for information security, must approve the program.
  • Regular review: review and update the program to keep up with new risks.

2. You may need to report cyber incidents to NFA

You must notify NFA, through its Cyber Notice Filing System, of a cybersecurity incident related to your commodity interest business that results in:

  • A loss of customer or counterparty funds.
  • A loss of your firm's own capital.
  • Your firm notifying customers or counterparties under state or federal law.

A hacked website that exposes customer data could trigger these obligations, which is why prevention matters.

3. Oversee the vendors you rely on

If you outsource functions needed to meet NFA or CFTC requirements to a third party, NFA Interpretive Notice 9079 requires a written framework for overseeing that vendor. This includes risk assessment, due diligence, ongoing monitoring, termination planning and recordkeeping.

Your compliance team can determine whether your web hosting, website management or other technology vendors fall under this requirement. Gate 39 can provide information about our security practices to support your due diligence.

4. Your website is promotional material

Under NFA Compliance Rule 2-29, promotional material is defined broadly. It generally includes any communication with the public, including your website, that relates to soliciting accounts or transactions in your commodity interest business. Your website content must meet NFA standards: for example, it must be accurate and balanced and include required risk disclosures. Your compliance team should review new pages and content before they go live.

Why websites get hacked, even small ones

Many firms assume their website is too small or unimportant to be a target. In reality, most attacks are carried out by automated bots that scan the internet for any site with a known weakness, regardless of size. Common reasons websites are attacked include:

  • Stealing data: customer names, email addresses, logins or financial information.
  • Ransomware: locking your site or systems until a ransom is paid.
  • Spreading malware to your website visitors.
  • Sending spam or phishing emails from your server, often impersonating your firm.
  • Hijacking search rankings by hiding spam links in your site's code.
  • Hosting illegal content or running scams on your site.
  • Fake sign-ups and card testing through your forms or checkout.
  • Vandalism: replacing your pages with the attacker's message.

A hacked site can damage your reputation, be blocked or flagged by Google, and be difficult to restore without good backups. For an NFA member, it may also trigger regulatory reporting.

How Gate 39 helps protect your website

  • Updates: keeping WordPress, plugins and themes updated to close known security holes.
  • Backups: regular backups so your site can be restored quickly.
  • A firewall and bot protection to block attacks, spam and fake sign-ups.
  • Secure logins: strong passwords and multi-factor authentication for site administrators.
  • Monitoring for malware, downtime and suspicious activity.
  • Documentation of our security practices to support your ISSP and vendor due diligence.

Have questions about your website's security or compliance? Contact the Gate 39 team through the Customer portal.

 

 References
[1] NFA – Amends Interpretive Notice Regarding Information Systems Security Programs
[2] NFA Rulebook – Interpretive Notice 9070: Information Systems Security Programs
[3] NFA – Cybersecurity (Introducing Brokers)
[4] NFA – Notice to Members (CPO/CTA cybersecurity)
[5] Proskauer – NFA Issues Guidance on Information Systems Security Programs
[6] Ropes & Gray – NFA to Require Written Supervisory Framework for Third-Party Service Providers (Apr 2021)
[7] Hedge Fund Law Report – NFA Issues New Rules on Use of Third Parties (May 27, 2021)
[8] NFA Rulebook – Compliance Rule 2-29 Interpretive Notice
[9] Mayer Brown – NFA Advertising Rules and Related Enforcement Actions (Feb 2020)