9.2 Business Continuity, Systems Resilience, Cybersecurity, and Vendors

Key Takeaways

  • Rule 4370 requires a written business continuity plan addressing the listed operational areas and reasonably designed for the member's size, business, and customer needs.

  • The plan must be reviewed annually, updated after material changes, and supported by two emergency contacts meeting the rule's conditions.

  • Customer disclosure summarizes how the firm plans to respond to a significant business disruption and must be provided at account opening, posted online, and mailed on request.

  • Cybersecurity and vendor dependency belong in continuity planning because outsourced systems do not transfer the firm's regulatory responsibility.

Last updated: September 2026

1. Business Continuity Planning Framework Under FINRA Rule 4370

Scope and Purpose of Rule 4370

Under FINRA Rule 4370, every member broker-dealer must create, maintain, and update a written Business Continuity Plan (BCP) identifying procedures to be followed in the event of a Significant Business Disruption (SBD). The plan must be engineered to enable the member firm to meet its existing obligations to customers, counterparties, and other broker-dealers, while preserving operational resilience.

Internal vs. External Disruptions

Rule 4370 explicitly requires member firms to formulate contingency responses for two distinct classes of disruptions:

  • Internal SBDs: Disruptions that affect solely the member firm's ability to conduct normal business operations, such as a fire at firm headquarters, localized hardware failure, an internal network cyberattack, or structural building damage.
  • External SBDs: Widespread disruptions that impact an entire financial district, city, region, or capital market infrastructure, such as a regional electrical grid blackout, severe natural disaster (hurricane, earthquake), pandemic lockdown, terrorist attack, or major telecommunications exchange failure.

The BCP must be flexible and scaled to the size, business model, and complexity of the broker-dealer, but cannot omit mandatory core statutory protections.


2. The Ten Mandatory Mission-Critical Components of a BCP

Under FINRA Rule 4370(c), each member firm's business continuity plan must address, at a minimum, the following ten mission-critical elements (or thoroughly document why any specific element is not applicable to the firm's business model):

  1. Data Backup and Recovery: The firm must maintain redundant, geographically dispersed electronic and hard-copy backup records. Backup data must be stored in a facility far enough from the primary site that an external SBD affecting the primary facility will not compromise the backup repository.
  2. All Mission-Critical Systems: Identification of systems essential to prompt order handling, account valuation, trade execution, and regulatory recordkeeping.
  3. Financial and Operational Assessments: Written protocols to immediately determine the firm's net capital status, liquidity reserves, operational solvency, and ability to fund ongoing obligations during an SBD.
  4. Alternate Communications Between Customers and the Firm: Contingency mechanisms for clients to contact the firm (e.g., redundant toll-free phone lines, automated interactive voice response systems, dedicated emergency website banners, mobile alerts) if primary branch offices or call centers fail.
  5. Alternate Communications Between the Firm and Its Employees: Procedures to locate, communicate with, and mobilize essential personnel (e.g., employee crisis hotlines, off-site messaging networks, encrypted group chat systems).
  6. Alternate Physical Location of Employees: Designating pre-established backup operational facilities, secondary data centers, or secure remote-work cloud infrastructure for critical staff.
  7. Critical Business Constituent, Bank, and Counterparty Impact: Procedures to interface with clearing broker-dealers, mutual fund transfer agents, variable insurance issuers, banks, and utility providers, evaluating their BCP preparedness.
  8. Regulatory Reporting: Maintaining the technological and administrative capacity to submit required regulatory filings (such as FOCUS reports, Form U4/U5 amendments, and Rule 4530 filings) without interruption during a disruption.
  9. Communications with Regulators: Establishing direct communication channels with FINRA, the SEC, and state securities divisions during an emergency.
  10. Customer Prompt Access to Funds and Securities: If the broker-dealer determines that an SBD prevents it from continuing its business operations, the firm must execute specific procedures ensuring that customers receive prompt access to their cash and securities (e.g., directing mutual fund clients to execute redemptions directly through the fund's transfer agent or clearing broker-dealer).

Annual Review by a Registered Principal

Under Rule 4370(b), the BCP must be reviewed and evaluated at least annually by a registered principal of the firm to determine whether modifications are required in light of changes to the firm's operations, business structure, address, or technology. Furthermore, whenever the firm undergoes a material operational change, the BCP must be updated promptly.


3. Emergency Contact Persons (ECPs) and Customer Disclosure Protocols

Designation of Emergency Contact Persons

Under FINRA Rule 4370(f), each member firm must designate at least two Emergency Contact Persons (ECPs) through the FINRA Contact System (FCS):

  • Eligibility Standards: Both ECPs must be associated persons of the member firm. At least one ECP must be a member of senior management and a registered principal of the firm.
  • Sole Proprietorship / Small Firm Exception: If a member firm has only one associated person (e.g., a sole proprietorship), the second emergency contact person may be an individual who is not associated with the firm, provided they have knowledge of the firm's business operations (such as the firm's outside legal counsel, independent certified public accountant, or clearing firm contact).
  • Regulatory Update Window: Whenever any information regarding an ECP changes, the firm must update the FINRA Contact System promptly, but in no event later than 30 calendar days following the change.
  • Annual FCS Verification: Within 17 business days following the end of each calendar year, each member firm must review, verify, and re-certify the accuracy of its emergency contact information through the FCS portal.

Mandatory Customer BCP Disclosure

Under Rule 4370(e), member firms must deliver a written summary of their BCP to retail customers:

  • Timing of Delivery: A written BCP disclosure statement must be provided to each customer at account opening.
  • Public Posting: The summary must be prominently posted on the broker-dealer's public website.
  • Mailing on Request: The firm must mail or electronically deliver the BCP disclosure summary promptly to any customer upon written request.

The disclosure summary must explain how the plan addresses disruptions of varying severity, the expected recovery timeframes, and how customers may access their funds and securities if primary communications collapse.


Systems, Cyber Events, and Third Parties

A significant business disruption may be physical, technological, geographic, malicious or vendor caused. Ransomware, telecommunications loss, a transfer-agent outage, cloud-region failure and a building closure can each interrupt books and records, order handling, customer communications and access to funds. The plan should identify dependencies, recovery priorities, manual alternatives and decision authority rather than rely on a vendor's marketing assurance.

Vendor due diligence should address financial and operational resilience, information security, subcontractors, data location, backup, recovery testing, incident notice, access to books and records, termination assistance and concentration risk. Contracts support oversight but do not transfer the firm's duties. The member needs a way to operate or communicate when the vendor itself is unreachable.

Testing should distinguish recovery time objectives—how quickly a process must return—from recovery point objectives—how much data loss can be tolerated. Tabletop exercises validate escalation and communication; technical recovery tests validate that systems and data can actually be restored. Material failures, business changes and lessons from incidents must flow into the annual review and interim updates.

Customer Access and Communications

Communications should state what is known, what customers can do, and where reliable updates will appear without promising a recovery time the firm cannot support. If the firm cannot continue business, its procedures must address prompt customer access to funds and securities through the clearing firm, custodian, transfer agent or another lawful channel. BCP invocation does not suspend privacy, AML, books-and-records, confirmation or regulatory-reporting duties.

Test Your Knowledge

How often must a member conduct the required Rule 4370 review of its business continuity plan?

A

Only after a significant disruption occurs.

B

At least annually, with updates when material operational changes require them.

C

Every five years if systems are outsourced.

D

Monthly, using a form prescribed for every firm.

Test Your Knowledge

A firm outsources its customer platform to a cloud vendor. Who retains responsibility for continuity and regulatory compliance?

A

The vendor assumes all securities-law duties under the service contract.

B

The member firm retains responsibility and must oversee the vendor and maintain workable continuity arrangements.

C

FINRA becomes responsible whenever a cloud service is used.

D

Customers bear the risk because they accepted electronic delivery.

Sections you finish are checked off in the contents.