21 December 2023 marked a key milestone in the AMF’s ongoing commitment to strengthening cybersecurity within asset management companies. Through the publication of the summary of its third thematic inspection campaign, the authority highlighted its determination to assess and improve managers’ ability to effectively prevent and manage any malicious compromise of information systems.
These compromises, which can potentially harm data security and the integrity of operations, jeopardise not only investment funds and managed mandates, but also compliance with regulatory obligations and client protection.
As part of this initiative, the AMF highlighted two essential levels of vigilance:
First, the need to protect sensitive data, which is often handled by key IT service providers, including those offering cloud services.
Second, the importance of securing all electronic interactions involving sensitive data that asset management companies maintain with other partners vital to their business.
The review of five asset management companies revealed notable shortcomings in their cybersecurity frameworks, particularly with regard to monitoring employees’ use of IT channels to exchange sensitive data with partners.
This finding highlights the crucial importance of raising employee awareness of cybersecurity, underlining that protective measures are not limited to technology but also include the informed management of human behaviour.
The AMF also stressed the importance of considering the cybersecurity resilience, incident management and business continuity capabilities of IT service providers and partners when selecting, contracting with and monitoring them. These criteria are fundamental to building solid digital trust and avoiding vulnerabilities that could expose asset management companies to significant risks.
The proactive approach recommended by the AMF, in preparation for the application of the European DORA regulation from 17 January 2025, requires asset management companies to adopt a robust and balanced risk management strategy. This involves allocating the necessary human and financial resources, using appropriate technical tools, accurately mapping risks, establishing internal procedures, carrying out regular checks and implementing a business continuity plan.
By emphasising employee cybersecurity awareness, the AMF points towards an integrated security culture in which every member of the organisation plays a crucial role in preventing and managing cybersecurity incidents. This approach aims not only to prevent incidents, but also to anticipate them, thereby strengthening the operational resilience of asset management companies in a rapidly evolving digital landscape.



