As the financial sector continues to be a prime target for hackers and other malicious actors in the cyber domain, the regulators at the Securities and Exchange Commission are getting a new cybersecurity adviser.
Christopher Hetner — formerly the cybersecurity lead for SEC’s Technology Control Program in the Office of Compliance Inspections and Examinations — was named the senior adviser to the chair for cybersecurity policy on June 2.
In this new role, Hetner will work directly with SEC Chair Mary Jo White as an adviser on all cybersecurity issues, including internal SEC policies, as well as “engaging with external stakeholders and further enhancing the SEC’s mechanisms for assessing broad-based market risk,” according to an agency release.
In announcing Hetner’s appointment, White noted that cybersecurity is of the utmost importance to the financial sector, which has seen a steady uptick in attacks over the months and years.
“With the cyber field steadily evolving and expanding, it is imperative we continue to enhance our coordinated approach to cybersecurity policy across the SEC and engage at the highest levels with market participants and governmental bodies concerning the latest developments in this area,” she said. “We are very fortunate that Chris will take on this important role where he will apply his expertise and decades of experience in information security.”
Prior to joining the SEC, Hetner spent a little over two years leading Ernst and Young’s wealth and asset management cybersecurity practice. Over the course of his 20-year career, Hetner has served in top cyber and information security posts at GE and Citigroup and holds a number of certifications.
“Having dedicated my career to information security, I am honored to have the opportunity to advise Chair White on cyber policy issues,” Hetner said. “I look forward to working with staff across the agency to enhance our risk-based approach to cybersecurity policy.”
“To have someone focused specifically on this issue at the SEC will be extremely helpful for investors and public companies alike,” according to Jake Olcott, vice president of BitSight and former legal adviser to the Senate Commerce Committee. “It is critical that the SEC improve the disclosure process from companies to investors [on portfolio cyber risks] – even after the 2011 cyber guidance, both sides still struggle with what to ask for and what to provide.”




