This week I enabled two-step authentication on my @Vanguard_Group account. Once per day, someone tries to hack my password.
— Aaron Welsh (@heywelshie) December 12, 2014
In December, the firm rolled out an optional security feature, two-factor authentication. Clients who opt in receive a text message to his or her phone with a code to be entered into the login portal.
It has received mixed feedback on Twitter.
I'm looking at you, @Vanguard_Group. https://t.co/btD8IdH6c1
— Code Fairy (@zigdon) May 18, 2015
@vanguard_group You're supposed to send the text *after* the password is entered. Every 2 factor site I've ever seen works that way
— jared (@jaredmoody) January 30, 2015
Also, @Vanguard_Group asks way too much information to reset a password, then sends the temp password as plain text over e-mail. #facepalm
— Greg (@NemesisVex) December 21, 2014
Sid Yenamandra, the co-founder and chief executive of Entreda, a financial services cybersecurity consulting firm, said that this is a classic balance of sacrificing security for convenience, or vice versa.
"Do you force customers to enter two passwords and still let them enter [even if they make a typo] because it's more convenient?" Mr. Yenamandra said. "That was the mistake Vanguard made."
Vanguard is certainly not the only firm to grapple with this issue — other firms have also gotten heat for their allegedly lax sign-on requirements.
For example, Schwab and Fidelity were both called out on Twitter for having a weak login system.
seriously schwab - password must b 6-8 char, no symbls and you don't check the case? Moving to vanguard w/2factor auth.
— Jim Siegl (@jsiegl) March 5, 2015
Schwab financial services has messed up 2FA. http://t.co/eom4lCHNsT Vanguard and Fidelity have had horrid security for all the years I'...
— John Gordon (@jgordonshare) December 25, 2014
Fidelity spokesman Adam Banker said that the firm offers multi-factor authentication as part of its ongoing effort to protect customer accounts and information.
Sarah Bulgatz, director of public relations at Charles Schwab & Co., which has also received criticism for their allegedly weak password requirements, said that the firm is rolling out enhancements to their password protocols, which will make login and identity-verification processes to be much more complex.
Both Schwab and Vanguard offer a guarantee that they will reimburse any losses in compromised online accounts that stemmed from incidents of fraud.
Mr. Yenamandra suggested advisers take note of the types of security measures that the firms they work with are taking and alert management if they seem weak.
"If you're using Schwab or Fidelity and custodying assets and find really weak cybersecurity practices, inform management teams — this is a cause of concern for your clients," Mr. Yenamandra said. "The second thing is they need to audit all of the different vendors."
That's because any third-party service providers, especially those that are integrated with one another and share sensitive data, could be a backdoor way for hackers to enter a system.
Chris Pogue, senior vice president of cyber threat analysis at Nuix, a cybersecurity service provider specializing in financial services firms, said it's usually a question of what the data and the security measures both cost, and which outweighs the other.
"If it costs me more to protect the data than the actual data, what am I doing this for?" he said. "Then there's the concept of usability, as in, if I make it so difficult for my users to use this thing that it defeats the purpose."
Orion Advisor Services also has the two-factor authentication feature. Joe Leyboldt, director of technology support at Orion, said that it provides an extra layer of safety.
"I don't think that's common in the industry," Mr. Leyboldt said. "The chances of potential harm to your account, to have access to all three entry points, is very slim."
There are many other options advisers can take to improve their cybersecurity measures, including knowing their firm's policies and procedures, getting security measures in writing, hiring staff specifically tasked with ensuring firm-wide security and protecting websites, apps and networks with added security features.
But logging in always comes down to a password, which was the crux of Vanguard's issue. Mr. Pogue said that passwords should not be made or kept simply for convenience. He said that they should meet basic requirements, with capitalization, special characters and numbers, and should be rotated every 90 days. They also shouldn't be recycled or duplicated across platforms.
"This is a $3 trillion industry for organized crime. It is not going anywhere any time soon," Mr. Pogue said. "They all say the same thing: 'I never thought it would happen to me.'
"Not only is it going to happen to you, more than likely, it already has and you may not know it," he added.
Canadian stocks are on a roll in 2025 as the country prepares to name a new Prime Minister.
Two C-level leaders reveal the new time-saving tools they've implemented and what advisors are doing with their newly freed-up hours.
The RIA led by Merrill Lynch veteran John Thiel is helping its advisors take part in the growing trend toward fee-based annuities.
Driven by robust transaction activity amid market turbulence and increased focus on billion-dollar plus targets, Echelon Partners expects another all-time high in 2025.
The looming threat of federal funding cuts to state and local governments has lawmakers weighing a levy that was phased out in 1981.
RIAs face rising regulatory pressure in 2025. Forward-looking firms are responding with embedded technology, not more paperwork.
As inheritances are set to reshape client portfolios and next-gen heirs demand digital-first experiences, firms are retooling their wealth tech stacks and succession models in real time.