Learn from the past.
Prepare for the future.
Tracking the global digital assets ecosystem

Trading Firms Urged to Strengthen Vendor Oversight

From left to right: Kym Weiland, Scott Hennon, Emily Verlinde, Dawn Calonge

At the 2026 FINRA Annual Conference panel “Building Resilient Technology Stacks Through Vendor Management”, on Wednesday, May 13, speakers warned that third-party vendor risk is becoming increasingly difficult to manage.

Much of the conversation, moderated by Kym Weiland, Senior Vice President, Delivery Services Technology at FINRA, focused on how financial institutions are adapting their vendor oversight and incident response strategies.

Scott Hennon, Chief Information Security Officer and Head of Security Services at Cetera Financial Group, described how artificial intelligence has lowered the barriers for cybercriminals to launch sophisticated scams.

“You don’t really have to be that technical to commit a lot of these scams now, and they’re very effective,” Hennon said.

“If you’re having struggles conducting your scam or your campaign, they do have ‘bad guy’ support. So you can call in and get help with conducting your campaign,” he said.

Hennon said the growing accessibility of AI tools is changing how firms think about cybersecurity risks.

“AI inherently is not good or bad. There are good people and bad people who use AI. And so the bad people are definitely using AI. And so the good – we have to counter that,” he said.

Hennon said firms are increasingly relying on AI-powered defenses and looking to security vendors and technology partners for additional support. At the same time, he noted that many security professionals are still learning how to manage and secure AI-related systems.

“A lot of the security folks are expected to protect us, and people want to use AI, but we have to be able to be skilled and able to govern and protect and deploy our own tools in a thoughtful way,” he said.

He added that firms are investing more heavily in training and certifications to help close those gaps.

“This AI thing is an ongoing challenge. It’s not going to end anytime soon,” he commented.

Source: Cetera Financial Group presentation by Scott Hennon, Chief Information Security Officer and Head of Security Services

AI-driven fraud raises pressure on vendor oversight

Emily Verlinde, Chief Compliance Officer at Open to the Public Investing, Inc., said AI-enabled fraud and social engineering have become some of the biggest emerging concerns for vendor oversight teams.

“AI can help fraudsters and the bad guys just as fast as us,” Verlinde said.

She pointed to the growing sophistication of phishing emails, impersonation attempts and fraudulent websites, which she said have become far harder to distinguish from legitimate communications.

“Ten years ago, if you got a phishing email, it would be quite obvious,” she said. “Now when you get them, they’re almost indistinguishable from regular emails,” she stressed.

Verlinde said attackers are increasingly targeting firms of all sizes, including smaller vendors with fewer resources.

“They’re not just going after big firms and big vendors,” she said. “They’re also going after really small firms and really small vendors,” she added.

That shift has made vendor oversight more important because third parties often hold sensitive customer information and may present vulnerabilities comparable to direct attacks on firms themselves, she said.

“A vendor who has access to my firm’s information, in my mind, is the same as a direct attack on my firm,” Verlinde said.

She encouraged firms to ask vendors detailed questions about phishing awareness, fraud monitoring and AI governance practices, while also maintaining regular communication and oversight.

Verlinde also highlighted simple monitoring tools that smaller firms can implement without significant cost, including Google Alerts tied to vendor names and keywords such as ‘fraud’ or ‘lawsuits’.

“We trust our vendors to be doing everything they need to be doing, but Google Alerts can work really well as a backup,” she said.

Dawn Calonge, Senior Director, Risk Monitoring: Retail Firms at FINRA, said firms often perform strong due diligence during vendor onboarding but become less rigorous with ongoing reviews.

“Where we see firms sometimes slip up is on that ongoing assessment,” Calonge said.

She stressed the importance of governance structures that involve compliance, finance, business and technology teams, as well as maintaining comprehensive vendor inventories and tiered risk frameworks.

“Not everything can be the most critical,” Calonge said.

The panelists also discussed how firms are shifting away from trying to prevent every possible disruption and instead focusing more heavily on resilience and recovery planning.

“I think in the old days, we tried to prevent everything. But inevitably, what we’re finding these days is something’s going to happen,” Hennon said.

He added that firms should assume incidents and outages will occur and ensure that incident response plans include vendor-related scenarios, recovery procedures and direct lines of communication with vendor security teams.

“You don’t want to be scrambling to figure out what to do or who to get involved,” Hennon said.

Hennon also described how firms use business impact analyses to determine which systems and vendors require the highest levels of resiliency investment.

“If you’re trying to make everything highly resilient, that’s a lot to afford,” he said.

“Most people can’t afford to make their entire environment highly resilient,” he added.

Verlinde said smaller firms can sometimes benefit from being able to respond quickly during incidents. “We can work really quickly. We can get the right people in the room really fast,” she said.

She encouraged firms not to become overwhelmed by the scale of cyber and vendor-management challenges and instead focus on “building resilience incrementally over time”.

“Resilience really compounds. If you schedule a tabletop exercise next month, or you document a fallback next week, those are all small things on their own, but they compound over time,” she said.

 

MOST READ

PODCAST