{"id":15315,"date":"2026-09-15T19:12:45","date_gmt":"2026-09-15T13:42:45","guid":{"rendered":"https:\/\/threatcop.com\/blog\/?p=15315"},"modified":"2026-09-15T19:12:47","modified_gmt":"2026-09-15T13:42:47","slug":"information-barriers-financial-services","status":"publish","type":"post","link":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/","title":{"rendered":"Information Barriers in Financial Services: The Control That Runs on People"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Information barriers, also called ethical walls, are the policies and procedures financial firms use to stop material non-public information from moving between business units that must stay separated. Surveillance detects a breach after it happens. The controls that prevent one, including wall crossings and need-to-know discipline, are executed by employees in the moment.<\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_87 ez-toc-wrap-center counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #414141;color:#414141\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #414141;color:#414141\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#What_Information_Barriers_Are_and_Which_Rules_Require_Them\" >What Information Barriers Are and Which Rules Require Them<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#What_the_SEC_Found_When_It_Examined_Barrier_Programmes\" >What the SEC Found When It Examined Barrier Programmes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#Book_a_Free_Demo_Call_with_Our_Expert\" >Book a Free Demo Call with Our Expert<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#How_a_Wall_Crossing_Actually_Works\" >How a Wall Crossing Actually Works<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#Are_Most_Barrier_Breaches_Deliberate_or_Accidental\" >Are Most Barrier Breaches Deliberate or Accidental?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#Why_Channel_Proliferation_Broke_the_Old_Model\" >Why Channel Proliferation Broke the Old Model<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#What_to_Train_by_Role\" >What to Train, by Role<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#Why_Self-Reporting_Is_the_Control_Nobody_Budgets_For\" >Why Self-Reporting Is the Control Nobody Budgets For<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#What_to_Measure_Beyond_Surveillance_Alerts\" >What to Measure Beyond Surveillance Alerts<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#Start_With_the_Crossings_You_Are_Not_Recording\" >Start With the Crossings You Are Not Recording<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Information_Barriers_Are_and_Which_Rules_Require_Them\"><\/span>What Information Barriers Are and Which Rules Require Them<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Information barriers separate parts of a firm that hold material non-public information from parts that trade, advise, or publish research. The classic separations are investment banking from research, and advisory desks from proprietary trading, with the goal of preventing insider dealing, front running, and conflicts of interest.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The requirement is statutory rather than advisory. Section 15(g) of the Securities Exchange Act of 1934 requires registered broker-dealers to establish, maintain, and enforce written policies and procedures reasonably designed, taking into account the nature of their business, to prevent the misuse of material non-public information. Section 204A of the Investment Advisers Act of 1940 imposes a parallel duty on registered investment advisers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Specific conduct rules sit on top of that general duty. FINRA Rules 2241 and 2242 govern conflicts around equity and debt research, Rule 5280 addresses trading ahead of research reports, and <a href=\"https:\/\/www.finra.org\/rules-guidance\/rulebooks\/finra-rules\/5270\" target=\"_blank\" rel=\"nofollow noopener\">Rule 5270<\/a> on front running of block transactions carves out firms that have established information barriers to prevent internal disclosure. In the United Kingdom, the FCA addresses the same ground through SYSC 10.2.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">How these obligations sit inside a wider control framework is covered in this guide to <a href=\"https:\/\/threatcop.com\/blog\/cybersecurity-governance-risk-and-compliance-guide\/\">governance, risk, and compliance<\/a>. The word &#8220;enforce&#8221; in Section 15(g) is the one that does the work. A written barrier that exists on paper and is routinely crossed without record does not satisfy a duty phrased that way, which is the gap most enforcement actions turn on.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_the_SEC_Found_When_It_Examined_Barrier_Programmes\"><\/span>What the SEC Found When It Examined Barrier Programmes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The SEC&#8217;s Office of Compliance Inspections and Examinations published a <a href=\"https:\/\/www.sec.gov\/about\/offices\/ocie\/informationbarriers.pdf\" target=\"_blank\" rel=\"nofollow noopener\">staff summary report on examinations of information barriers<\/a> after reviewing brokerage firms&#8217; programmes for protecting against the misuse of MNPI. It remains the most specific published description of what examiners expect, and it identified four components of an effective programme.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\"><strong>Component<\/strong><\/th><th class=\"has-text-align-left\" data-align=\"left\"><strong>What it means in practice<\/strong><\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\">Removing decision-making authority from the business unit<\/td><td class=\"has-text-align-left\" data-align=\"left\">The judgment about whether information may cross is made by a control group in compliance, not by the desk that wants the information<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">Formal procedures and documentation<\/td><td class=\"has-text-align-left\" data-align=\"left\">Wall crossings, restricted lists, and watch lists are recorded contemporaneously rather than reconstructed later<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">Limiting the sharing of information<\/td><td class=\"has-text-align-left\" data-align=\"left\">Need-to-know is applied at the level of individual people, not departments<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">Surveillance techniques<\/td><td class=\"has-text-align-left\" data-align=\"left\">Communications and trading are monitored for patterns indicating leakage<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Three of those four are procedural controls carried out by people. Only the fourth is a monitoring technology, and it is the one that operates after information has already moved. Vendors selling detection tend to present the fourth component as the programme, which inverts the SEC&#8217;s own emphasis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The report also cautioned firms about classifying individuals or groups as &#8220;above the wall&#8221; where physical barriers, documentation, or other controls are limited or absent, and noted that examiners found gaps in oversight coverage at most firms reviewed. Broader control context is set out in <a href=\"https:\/\/threatcop.com\/blog\/cybersecurity-in-banking\/\">cybersecurity controls in banking<\/a>.<\/p>\n\n\n\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>Threatcop \u2013 Book a Free Demo<\/title>\n<link href=\"https:\/\/fonts.googleapis.com\/css2?family=Outfit:wght@300;400;500;600;700&#038;display=swap\" rel=\"stylesheet\">\n<style>\n  .tc-wrap , .tc-wrap ::before, .tc-wrap ::after { box-sizing: border-box; margin: 0; padding: 0; }\n  .tc-wrap { font-family: 'Outfit', sans-serif; width: 100%; display: flex; justify-content: center; padding: 20px 10px; }\n  .tc-card { width: 100%; max-width: 820px; background: #fff; border-radius: 20px; overflow: hidden; box-shadow: 0 20px 60px rgba(24,57,148,0.13), 0 4px 16px rgba(24,57,148,0.07); display: flex; flex-direction: row; }\n  .tc-left { background: linear-gradient(160deg, #1e44b0 0%, #183994 40%, #0e2570 100%); width: 320px; flex-shrink: 0; padding: 40px 32px; display: flex; flex-direction: column; justify-content: center; position: relative; overflow: hidden; }\n  .tc-left::before { content: ''; position: absolute; inset: 0; background-image: radial-gradient(rgba(255,255,255,0.08) 1.5px, transparent 1.5px); background-size: 22px 22px; }\n  .tc-left::after { content: ''; position: absolute; bottom: -60px; right: -60px; width: 220px; height: 220px; background: radial-gradient(circle, rgba(99,179,255,0.22) 0%, transparent 65%); border-radius: 50%; pointer-events: none; }\n  .tc-panel-inner { position: relative; z-index: 1; }\n  .tc-badge { display: inline-flex !important; align-items: center !important; gap: 6px; background: rgba(255,255,255,0.1) !important; border: 1px solid rgba(255,255,255,0.18) !important; border-radius: 20px !important; padding: 4px 14px 4px 10px !important; font-size: 12.5px !important; font-weight: 600 !important; letter-spacing: .09em !important; text-transform: uppercase !important; color: rgba(255,255,255,0.85) !important; margin-bottom: 18px !important; font-family: 'Outfit', sans-serif !important; line-height: 1.4 !important; }\n  .tc-badge-dot { width: 6px; height: 6px; background: #5cd9a0; border-radius: 50%; box-shadow: 0 0 6px #5cd9a0; flex-shrink: 0; display: inline-block; }\n  .tc-left h1, .tc-left h2, .tc-left h3, .tc-left h4, .tc-left h5, .tc-left h6 { color: #ffffff !important; font-family: 'Outfit', sans-serif !important; font-size: 28px !important; font-weight: 700 !important; line-height: 1.35 !important; letter-spacing: -0.3px !important; margin: 0 !important; padding: 0 !important; background: none !important; -webkit-text-fill-color: #ffffff !important; }\n  .tc-left h2 em { font-style: normal !important; color: #7ec8ff !important; -webkit-text-fill-color: #7ec8ff !important; }\n  .tc-left p, .tc-left .tc-sub { color: rgba(255,255,255,0.78) !important; -webkit-text-fill-color: rgba(255,255,255,0.78) !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 300 !important; line-height: 1.65 !important; margin-top: 12px !important; background: none !important; }\n  .tc-right { flex: 1; padding: 32px 32px 28px; display: flex; flex-direction: column; justify-content: center; }\n  .tc-form-title { font-size: 13px !important; font-weight: 600 !important; letter-spacing: .12em; text-transform: uppercase; color: #8fa4cc !important; margin-bottom: 20px !important; display: flex !important; align-items: center !important; gap: 10px; font-family: 'Outfit', sans-serif !important; }\n  .tc-form-title::after { content: ''; flex: 1; height: 1px; background: #eef1fa; }\n  .tc-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 14px; }\n  .tc-field { display: flex; flex-direction: column; gap: 5px; }\n  .tc-field.full { grid-column: 1 \/ -1; }\n  .tc-field label { font-size: 13px !important; font-weight: 600 !important; color: #3a4f7a !important; letter-spacing: .04em; text-transform: uppercase; font-family: 'Outfit', sans-serif !important; display: block !important; }\n  .tc-input-wrap { position: relative; display: flex; align-items: center; }\n  .tc-input-wrap .tc-fi { position: absolute; right: 12px; width: 15px; height: 15px; stroke: #c0ccdf; stroke-width: 1.8; pointer-events: none; fill: none; }\n  .tc-wrap input[type=\"text\"], .tc-wrap input[type=\"email\"], .tc-wrap input[type=\"number\"] { width: 100% !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 34px 9px 13px !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 400 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; transition: border-color .2s, background .2s, box-shadow .2s; -moz-appearance: textfield; box-shadow: none !important; -webkit-text-fill-color: #1e2d50 !important; }\n  .tc-wrap input[type=\"number\"]::-webkit-inner-spin-button, .tc-wrap input[type=\"number\"]::-webkit-outer-spin-button { -webkit-appearance: none; }\n  .tc-wrap input::placeholder { color: #c0ccdf !important; -webkit-text-fill-color: #c0ccdf !important; opacity: 1; }\n  .tc-wrap input:focus { border-color: #183994 !important; background: #fff !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-phone-row { display: flex; gap: 8px; }\n  .tc-flag-select { position: relative; flex-shrink: 0; }\n  .tc-flag-select select { appearance: none !important; -webkit-appearance: none !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 26px 9px 12px !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 500 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; cursor: pointer; width: 100px !important; transition: border-color .2s, box-shadow .2s; }\n  .tc-flag-select select:focus { border-color: #183994 !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-flag-select::after { content: ''; position: absolute; right: 10px; top: 50%; transform: translateY(-50%); width: 0; height: 0; border-left: 4px solid transparent; border-right: 4px solid transparent; border-top: 5px solid #a0b0cc; pointer-events: none; }\n  .tc-phone-row .tc-input-wrap { flex: 1; }\n  .tc-btn-submit { width: 100% !important; margin-top: 18px !important; padding: 11px !important; background: #183994 !important; border: none !important; border-radius: 10px !important; color: #fff !important; -webkit-text-fill-color: #fff !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 600 !important; letter-spacing: .05em; cursor: pointer; display: flex !important; align-items: center !important; justify-content: center !important; gap: 9px; transition: background .2s, transform .15s, box-shadow .2s; box-shadow: 0 6px 24px rgba(24,57,148,0.28) !important; text-decoration: none !important; }\n  .tc-btn-submit:hover { background: #1d46b5 !important; transform: translateY(-1px); box-shadow: 0 10px 32px rgba(24,57,148,0.35) !important; color: #fff !important; }\n  .tc-btn-submit:active { transform: translateY(0); }\n  .tc-btn-submit svg { width: 16px; height: 16px; stroke: #fff; stroke-width: 2.2; fill: none; flex-shrink: 0; }\n  .tc-trust { margin-top: 10px !important; display: flex !important; align-items: center !important; justify-content: center !important; gap: 5px; font-size: 13px !important; color: #a0b0cc !important; font-family: 'Outfit', sans-serif !important; }\n  .tc-trust svg { width: 12px; height: 12px; stroke: #a0b0cc; stroke-width: 2; fill: none; flex-shrink: 0; }\n  @media (max-width: 680px) {\n    .tc-card { flex-direction: column !important; }\n    .tc-left { width: 100% !important; padding: 28px 24px 24px !important; }\n    .tc-right { padding: 24px 20px !important; }\n    .tc-grid { grid-template-columns: 1fr !important; }\n    .tc-field.full { grid-column: 1 !important; }\n  }\n<\/style>\n\n<div class=\"tc-wrap\">\n  <div class=\"tc-card\">\n    <div class=\"tc-left\">\n      <div class=\"tc-panel-inner\">\n        <div class=\"tc-badge\">\n          <span class=\"tc-badge-dot\"><\/span>\n          People Security Management\n        <\/div>\n        <h2><span class=\"ez-toc-section\" id=\"Book_a_Free_Demo_Call_with_Our_Expert\"><\/span>Book a Free<br><em>Demo Call<\/em><br>with Our Expert<span class=\"ez-toc-section-end\"><\/span><\/h2>\n        <p class=\"tc-sub\">Discover how Threatcop protects your workforce from modern cyber threats.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"tc-right\">\n      <div class=\"tc-form-title\">Your Details<\/div>\n      <form action=\"https:\/\/threatcop.com\/thankyou-blog\" method=\"get\" target=\"_blank\">\n        <input type=\"hidden\" name=\"BlogForm\" value=\"BlogForm\">\n        <input type=\"hidden\" name=\"PageSource\" id=\"tc-page-source\" value=\"\">\n        <div class=\"tc-grid\">\n          <div class=\"tc-field\">\n            <label>Full Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"FullName\" placeholder=\"Jane Smith\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><circle cx=\"12\" cy=\"8\" r=\"4\"><\/circle><path d=\"M4 20c0-4 3.58-7 8-7s8 3 8 7\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field\">\n            <label>Company Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"CompanyName\" placeholder=\"Acme Corp\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"3\" width=\"18\" height=\"18\" rx=\"2\"><\/rect><path d=\"M9 3v18M3 9h6M3 15h6\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Corporate Email<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"email\" name=\"email\" placeholder=\"jane@yourcompany.com\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"2\" y=\"4\" width=\"20\" height=\"16\" rx=\"2\"><\/rect><polyline points=\"2,4 12,13 22,4\"><\/polyline><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Phone Number<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"number\" name=\"Phone\" placeholder=\"98765 43210\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 16.92v3a2 2 0 01-2.18 2A19.79 19.79 0 013.09 4.18 2 2 0 015.07 2h3a2 2 0 012 1.72c.13.96.36 1.9.71 2.81a2 2 0 01-.45 2.11L9.09 9.91a16 16 0 006 6l1.27-1.27a2 2 0 012.11-.45c.91.35 1.85.58 2.81.71A2 2 0 0122 16.92z\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n        <\/div>\n        <button type=\"submit\" class=\"tc-btn-submit\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 2L11 13M22 2L15 22l-4-9-9-4 20-7z\"><\/path><\/svg>\n          Book My Free Demo\n        <\/button>\n        <div class=\"tc-trust\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"11\" width=\"18\" height=\"11\" rx=\"2\"><\/rect><path d=\"M7 11V7a5 5 0 0110 0v4\"><\/path><\/svg>\n          Your data is safe &amp; never shared with third parties\n        <\/div>\n      <\/form>\n    <\/div>\n  <\/div>\n<\/div>\n<script>document.getElementById('tc-page-source').value = window.location.href;<\/script>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_a_Wall_Crossing_Actually_Works\"><\/span>How a Wall Crossing Actually Works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The wall crossing, or over-the-wall process, is the procedure by which someone on the public side is deliberately brought into possession of MNPI for a legitimate reason. It is the most human-dependent control in the entire framework, and it is missing from most discussions of information barriers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The sequence is straightforward on paper. A banker identifies a need to consult someone outside the deal team. The request goes to the control group rather than being handled between colleagues. The control group decides whether to permit it, records who was crossed, when, and in respect of which issuer, adds the person to the relevant list, and restricts their activity accordingly. When the information becomes public or the deal dies, the person is brought back.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every step of that depends on the banker recognizing, before the conversation happens, that they are about to cross a wall. No surveillance system can supply that recognition. By the time a monitoring tool observes the communication, the crossing has occurred, the person is contaminated, and the firm&#8217;s options have narrowed to remediation and disclosure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is the structural reason prevention in this domain is a training problem rather than a tooling problem. The moment of control arrives before any system has data to analyze, which is a pattern <a href=\"https:\/\/threatcop.com\/blog\/how-do-insider-threat-programs-defend-against-insider-threats\/\">insider threat programmes<\/a> encounter repeatedly.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Are_Most_Barrier_Breaches_Deliberate_or_Accidental\"><\/span>Are Most Barrier Breaches Deliberate or Accidental?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The archetype of a barrier failure is a trader deliberately exploiting a tip. The common case is far more ordinary, and it is the one training can actually address.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An analyst replies to all on a thread that has quietly grown to include someone on the private side. A banker mentions a client name in a lift or an open-plan area. A shared drive permission survives a reorganization and nobody notices that a folder is now readable by a desk that should not see it. Someone forwards a deck to a personal account to work on it at home. A colleague asks a casual question at lunch and receives a helpful answer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">None of these involves intent to breach, and none of them is stopped by a policy document. What stops them is a person recognizing a situation as a wall-relevant moment and behaving differently because of it, which is a trained reflex rather than a rule lookup. The distinction between deliberate and inadvertent insider risk is developed in <a href=\"https:\/\/threatcop.com\/blog\/insider-threats-malicious-misguided\/\">the difference between careless and deliberate insiders<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The full spectrum, from careless to deliberate, is mapped in <a href=\"https:\/\/threatcop.com\/blog\/insider-threats\/\">insider threats: risks, identification and prevention<\/a>. The practical consequence for programme design is that the population needing the deepest training is not the population most likely to act maliciously. It is the population most likely to be in the room when information moves without anyone deciding that it should.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Channel_Proliferation_Broke_the_Old_Model\"><\/span>Why Channel Proliferation Broke the Old Model<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Barriers were designed for an environment where communication was formal, physically separated, and logged. Hybrid work, messaging platforms, collaboration tools, and personal devices removed all three properties at once.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The scale of the resulting failure is documented in the off-channel communications enforcement campaign, in which regulators penalized firms for business conversations conducted on unapproved messaging apps and not preserved. What makes that campaign relevant to barriers specifically is not the penalty totals but the mechanism: conversations moved to channels where neither preservation nor surveillance applied, which means barrier monitoring was blind to them by construction.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Adding more channels to a surveillance estate is a partial answer at best, because each new platform arrives before the monitoring does, and the interval between adoption and coverage is exactly when the risk concentrates. Visibility limits of this kind are examined in <a href=\"https:\/\/threatcop.com\/blog\/insider-threat-detection\/\">insider threat detection<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The durable answer is that employees need to understand which conversations are wall-relevant regardless of the channel carrying them, because the rule attaches to the information rather than to the application.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_to_Train_by_Role\"><\/span>What to Train, by Role<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Generic compliance training does not equip anyone to handle a wall-crossing moment. The content has to match what each population will actually encounter.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\"><strong>Population<\/strong><\/th><th class=\"has-text-align-left\" data-align=\"left\"><strong>What they need to recognize<\/strong><\/th><th class=\"has-text-align-left\" data-align=\"left\"><strong>The behaviour being built<\/strong><\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\">Investment banking<\/td><td class=\"has-text-align-left\" data-align=\"left\">When a consultation requires a formal crossing rather than an informal question<\/td><td class=\"has-text-align-left\" data-align=\"left\">Route the request to the control group before the conversation<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">Research<\/td><td class=\"has-text-align-left\" data-align=\"left\">When an inbound request is seeking information they should not supply<\/td><td class=\"has-text-align-left\" data-align=\"left\">Decline and report rather than deflect informally<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">Trading and sales<\/td><td class=\"has-text-align-left\" data-align=\"left\">When a piece of information they hold changes what they may trade<\/td><td class=\"has-text-align-left\" data-align=\"left\">Escalate immediately, before acting<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">Control room and compliance<\/td><td class=\"has-text-align-left\" data-align=\"left\">Edge cases, documentation standards, and list hygiene<\/td><td class=\"has-text-align-left\" data-align=\"left\">Consistent decisions and contemporaneous records<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">Support functions<\/td><td class=\"has-text-align-left\" data-align=\"left\">That administrative access can carry MNPI exposure<\/td><td class=\"has-text-align-left\" data-align=\"left\">Apply need-to-know to files and calendars, not only conversations<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">Senior management<\/td><td class=\"has-text-align-left\" data-align=\"left\">That &#8220;above the wall&#8221; status carries documentation duties<\/td><td class=\"has-text-align-left\" data-align=\"left\">Accept the controls that classification requires<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The last two rows are the ones most often skipped. Support staff frequently hold broader systems access than the front office, and senior executives are the population most likely to be classified above the wall and least likely to complete role-specific training on what that entails.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threatcop&#8217;s TLMS delivers this layer as role-based and category-based content across compliance frameworks, with coverage reported by role rather than as a single firm-wide completion figure, so a control room and a trading desk receive different material and the firm can show which population got which. Design considerations are covered in <a href=\"https:\/\/threatcop.com\/blog\/role-based-security-awareness-training\/\">matching training content to job function<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Self-Reporting_Is_the_Control_Nobody_Budgets_For\"><\/span>Why Self-Reporting Is the Control Nobody Budgets For<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A barrier breach that is reported within the hour is a remediation exercise. The same breach discovered six months later by surveillance is an enforcement matter, because the firm cannot show it acted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That difference is created entirely by whether someone chose to speak up, and in financial services the incentives against speaking up are unusually strong. Reporting an accidental crossing means telling compliance you may have contaminated yourself, with consequences for what you can work on and what you can trade. In a blame-oriented culture, the rational individual choice is silence, and the firm then holds a clean compliance record that reflects nothing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Firms that get early reports have usually done three specific things: made self-reporting of accidental crossings explicitly non-punitive in writing, demonstrated it by handling a real case that way visibly, and made the reporting path fast enough to use in the moment rather than at the end of the day. Mechanics are set out in <a href=\"https:\/\/threatcop.com\/blog\/what-is-incident-reporting-culture\/\">why employees stay silent about mistakes<\/a>, and the cost argument in <a href=\"https:\/\/threatcop.com\/blog\/how-psm-reduces-compliance-costs\/\">why weak human controls raise compliance costs<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_to_Measure_Beyond_Surveillance_Alerts\"><\/span>What to Measure Beyond Surveillance Alerts<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Alert volume measures the monitoring system. These measure the programme.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><p><strong>Wall crossings recorded per period<\/strong>, where a suspiciously low number usually means informal crossings, not disciplined separation<\/p><\/li>\n\n\n\n<li><p><strong>Median time from crossing to control group record<\/strong>, which distinguishes a live process from retrospective paperwork<\/p><\/li>\n\n\n\n<li><p><strong>Self-reported accidental crossings<\/strong>, read as a health indicator rather than a failure count<\/p><\/li>\n\n\n\n<li><p><strong>Restricted and watch list accuracy<\/strong>, sampled against actual deal activity<\/p><\/li>\n\n\n\n<li><p><strong>Role coverage of training against the populations the barrier map identifies<\/strong><\/p><\/li>\n\n\n\n<li><p><strong>Time from a new communication channel appearing to a policy decision about it<\/strong><\/p><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The first two are diagnostic in a way alert counts are not. A firm with an active pipeline and almost no recorded crossings is not exercising better discipline than its peers; it is failing to record something that is certainly happening. Metric selection of this kind is discussed in <a href=\"https:\/\/threatcop.com\/blog\/what-is-the-goal-of-an-insider-threat-program\/\">the goal of an insider threat programme<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Start_With_the_Crossings_You_Are_Not_Recording\"><\/span>Start With the Crossings You Are Not Recording<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Pull the count of formally recorded wall crossings for the last two quarters and compare it against the number of live transactions in the same period. If the first number is small relative to the second, the crossings are happening informally, and the firm&#8217;s documentation will not support the word &#8220;enforce&#8221; in Section 15(g) if an examiner asks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then train the populations that map identifies, on the moments they will actually face rather than on the policy in general. <a href=\"https:\/\/threatcop.com\/threatcop-learning-management-system\">Deliver the role-specific version<\/a> to banking, research, trading, and the support functions that quietly hold the broadest access, and report coverage by role so the programme can be evidenced rather than described.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\t\t<div class=\"sp-easy-accordion-block sp-eab-regular-accordion alignwide\"\n\t\t\t\t>\n\t\t\t<div class=\"sp-eab-wrapper sp-eab-vertical-accordion sp-eab-8c42b7e1f905\">\n\t\t\t\t\t\t\t\t<div class='sp-eab-accordion sp-eab-mode-vertical sp-eab-vertical-one sp-d-flex' data-accordion-settings=\"{&quot;mode&quot;:&quot;vertical&quot;,&quot;activeEvent&quot;:&quot;click&quot;,&quot;defaultAccordionOpen&quot;:&quot;first-item&quot;,&quot;selectedItemOpen&quot;:0,&quot;openMultiItemAtaTime&quot;:false,&quot;scrollToTopOnLoad&quot;:false,&quot;scrollToTopOnClick&quot;:false,&quot;accordionItemToUrl&quot;:false,&quot;animationEffect&quot;:false,&quot;applyAccessibility&quot;:true}\">\n        \t    \t\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-4d71a9c3082b\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-e1f905\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-e1f905'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat are information barriers in financial services?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-e1f905'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Information barriers, historically called Chinese walls and now more often ethical walls, are the policies, procedures, and physical or technical separations that prevent material non-public information from moving between parts of a financial firm that must remain independent. Typical separations divide investment banking from research and advisory functions from proprietary trading, preventing insider dealing, front running, and conflicts of interest.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-b0e6534fa71c\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-e1f905\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-e1f905'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhich regulations require information barriers?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-e1f905'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Section 15(g) of the Securities Exchange Act of 1934 requires broker-dealers to establish, maintain, and enforce written policies and procedures reasonably designed to prevent the misuse of MNPI. Section 204A of the Investment Advisers Act of 1940 applies the same duty to registered investment advisers. FINRA Rules 2241, 2242, 5270, and 5280 address specific conduct, and the FCA covers the area through SYSC 10.2.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-7fa2c8016d34\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-e1f905\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-e1f905'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat is a wall crossing?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-e1f905'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">A wall crossing, or over-the-wall process, is the controlled procedure for giving someone on the public side access to MNPI for a legitimate business purpose. A control group within compliance approves the crossing, records who was crossed and in respect of which issuer, adds the person to the relevant restricted or watch list, and brings them back when the information becomes public or the transaction ends.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-1e59d720b8af\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-e1f905\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-e1f905'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tCan technology alone enforce information barriers?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-e1f905'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">No. The SEC&#8217;s examination work identifies four components of an effective programme, of which only surveillance is a monitoring technology; the others concern where decision authority sits, documentation, and need-to-know discipline. Surveillance also operates after information has moved, whereas the decisive moment in a wall crossing occurs before any system has data to analyze.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-93c0ed4b62f7\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-e1f905\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-e1f905'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat is the difference between a restricted list and a watch list?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-e1f905'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">A restricted list is typically visible within the firm and prohibits activity in named securities, such as proprietary trading or research publication. A watch list is confidential to the control group and is used to monitor activity in securities where the firm holds MNPI without signalling that it does. Maintaining the confidentiality distinction is itself part of the barrier.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\n\n<p><script type=\"application\/ld+json\"><br \/>\n{<br \/>\n  \"@context\": \"https:\/\/schema.org\",<br \/>\n  \"@type\": \"FAQPage\",<br \/>\n  \"mainEntity\": [<br \/>\n    {<br \/>\n      \"@type\": \"Question\",<br \/>\n      \"name\": \"What are information barriers in financial services?\",<br \/>\n      \"acceptedAnswer\": {<br \/>\n        \"@type\": \"Answer\",<br \/>\n        \"text\": \"Information barriers, historically called Chinese walls and now more often ethical walls, are the policies, procedures, and physical or technical separations that prevent material non-public information moving between parts of a financial firm that must remain independent. Typical separations divide investment banking from research and advisory functions from proprietary trading, preventing insider dealing, front running, and conflicts of interest.\"<br \/>\n      }<br \/>\n    },<br \/>\n    {<br \/>\n      \"@type\": \"Question\",<br \/>\n      \"name\": \"Which regulations require information barriers?\",<br \/>\n      \"acceptedAnswer\": {<br \/>\n        \"@type\": \"Answer\",<br \/>\n        \"text\": \"Section 15(g) of the Securities Exchange Act of 1934 requires broker-dealers to establish, maintain, and enforce written policies and procedures reasonably designed to prevent the misuse of MNPI. Section 204A of the Investment Advisers Act of 1940 applies the same duty to registered investment advisers. FINRA Rules 2241, 2242, 5270, and 5280 address specific conduct, and the FCA covers the area through SYSC 10.2.\"<br \/>\n      }<br \/>\n    },<br \/>\n    {<br \/>\n      \"@type\": \"Question\",<br \/>\n      \"name\": \"What is a wall crossing?\",<br \/>\n      \"acceptedAnswer\": {<br \/>\n        \"@type\": \"Answer\",<br \/>\n        \"text\": \"A wall crossing, or over-the-wall process, is the controlled procedure for giving someone on the public side access to MNPI for a legitimate business purpose. A control group within compliance approves the crossing, records who was crossed and in respect of which issuer, adds the person to the relevant restricted or watch list, and brings them back when the information becomes public or the transaction ends.\"<br \/>\n      }<br \/>\n    },<br \/>\n    {<br \/>\n      \"@type\": \"Question\",<br \/>\n      \"name\": \"Can technology alone enforce information barriers?\",<br \/>\n      \"acceptedAnswer\": {<br \/>\n        \"@type\": \"Answer\",<br \/>\n        \"text\": \"No. The SEC's examination work identifies four components of an effective programme, of which only surveillance is a monitoring technology; the others concern where decision authority sits, documentation, and need-to-know discipline. Surveillance also operates after information has moved, whereas the decisive moment in a wall crossing occurs before any system has data to analyze.\"<br \/>\n      }<br \/>\n    },<br \/>\n    {<br \/>\n      \"@type\": \"Question\",<br \/>\n      \"name\": \"What is the difference between a restricted list and a watch list?\",<br \/>\n      \"acceptedAnswer\": {<br \/>\n        \"@type\": \"Answer\",<br \/>\n        \"text\": \"A restricted list is typically visible within the firm and prohibits activity in named securities, such as proprietary trading or research publication. A watch list is confidential to the control group and is used to monitor activity in securities where the firm holds MNPI without signalling that it does. Maintaining the confidentiality distinction is itself part of the barrier.\"<br \/>\n      }<br \/>\n    }<br \/>\n  ]<br \/>\n}<br \/>\n<\/script><\/p>","protected":false},"excerpt":{"rendered":"<p>Information barriers fail at the wall crossing, not the firewall. See what the SEC expects, how crossings work, and what to train by role and desk.<\/p>\n","protected":false},"author":29,"featured_media":15324,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[42,329],"tags":[],"class_list":["post-15315","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-awareness","category-human-risk-management"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Information Barriers in Financial Services: What to Train<\/title>\n<meta name=\"description\" content=\"Information barriers fail at the wall crossing, not the firewall. See what the SEC expects, how crossings work, and what to train by role and desk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Information Barriers in Financial Services: What to Train\" \/>\n<meta property=\"og:description\" content=\"Information barriers fail at the wall crossing, not the firewall. See what the SEC expects, how crossings work, and what to train by role and desk.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/\" \/>\n<meta property=\"og:site_name\" content=\"Threatcop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-15T13:42:45+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-15T13:42:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Information-Barriers-in-Financial-Services-blog-banner.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Yogyata Sethi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatcop\" \/>\n<meta name=\"twitter:site\" content=\"@threatcop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Yogyata Sethi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/\"},\"author\":{\"name\":\"Yogyata Sethi\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/8078d9da24781c2e8078d72917df4f6b\"},\"headline\":\"Information Barriers in Financial Services: The Control That Runs on People\",\"datePublished\":\"2026-09-15T13:42:45+00:00\",\"dateModified\":\"2026-09-15T13:42:47+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/\"},\"wordCount\":2197,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Information-Barriers-in-Financial-Services-blog-banner.png\",\"articleSection\":[\"Cybersecurity Awareness\",\"Human Risk Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/\",\"name\":\"Information Barriers in Financial Services: What to Train\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Information-Barriers-in-Financial-Services-blog-banner.png\",\"datePublished\":\"2026-09-15T13:42:45+00:00\",\"dateModified\":\"2026-09-15T13:42:47+00:00\",\"description\":\"Information barriers fail at the wall crossing, not the firewall. See what the SEC expects, how crossings work, and what to train by role and desk.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/#primaryimage\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Information-Barriers-in-Financial-Services-blog-banner.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Information-Barriers-in-Financial-Services-blog-banner.png\",\"width\":1280,\"height\":720,\"caption\":\"Threatcop blog banner reading Information Barriers in Financial Services, The Control That Runs on People, over an abstract network graph on a dark navy background\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/information-barriers-financial-services\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Information Barriers in Financial Services: The Control That Runs on People\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"name\":\"Threatcop\",\"description\":\"Cybersecurity Blogs, News, Updates, and Articles\",\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\",\"name\":\"Threatcop\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"width\":432,\"height\":102,\"caption\":\"Threatcop\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/people\\\/Threatcop\\\/100083109892339\\\/\",\"https:\\\/\\\/x.com\\\/threatcop\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/threatcop\\\/\",\"https:\\\/\\\/www.instagram.com\\\/threatcop_official\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/8078d9da24781c2e8078d72917df4f6b\",\"name\":\"Yogyata Sethi\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_29_1789479711-96x96.png\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_29_1789479711-96x96.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_29_1789479711-96x96.png\",\"caption\":\"Yogyata Sethi\"},\"description\":\"Yogyata Sethi is a finance professional at Kratikal with experience in financial analysis, business operations, and corporate finance. She has contributed to key business initiatives, including strategic growth and the company\u2019s public listing journey. Currently pursuing an MBA in Finance, Yogyata is passionate about financial planning, business strategy, and data-driven decision-making. She focuses on creating insights that support sustainable growth and long-term business value.\",\"sameAs\":[\"https:\\\/\\\/threatcop.com\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Information Barriers in Financial Services: What to Train","description":"Information barriers fail at the wall crossing, not the firewall. See what the SEC expects, how crossings work, and what to train by role and desk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/","og_locale":"en_US","og_type":"article","og_title":"Information Barriers in Financial Services: What to Train","og_description":"Information barriers fail at the wall crossing, not the firewall. See what the SEC expects, how crossings work, and what to train by role and desk.","og_url":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/","og_site_name":"Threatcop","article_publisher":"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","article_published_time":"2026-09-15T13:42:45+00:00","article_modified_time":"2026-09-15T13:42:47+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Information-Barriers-in-Financial-Services-blog-banner.png","type":"image\/png"}],"author":"Yogyata Sethi","twitter_card":"summary_large_image","twitter_creator":"@threatcop","twitter_site":"@threatcop","twitter_misc":{"Written by":"Yogyata Sethi","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#article","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/"},"author":{"name":"Yogyata Sethi","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/8078d9da24781c2e8078d72917df4f6b"},"headline":"Information Barriers in Financial Services: The Control That Runs on People","datePublished":"2026-09-15T13:42:45+00:00","dateModified":"2026-09-15T13:42:47+00:00","mainEntityOfPage":{"@id":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/"},"wordCount":2197,"commentCount":0,"publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"image":{"@id":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Information-Barriers-in-Financial-Services-blog-banner.png","articleSection":["Cybersecurity Awareness","Human Risk Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/","url":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/","name":"Information Barriers in Financial Services: What to Train","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#primaryimage"},"image":{"@id":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Information-Barriers-in-Financial-Services-blog-banner.png","datePublished":"2026-09-15T13:42:45+00:00","dateModified":"2026-09-15T13:42:47+00:00","description":"Information barriers fail at the wall crossing, not the firewall. See what the SEC expects, how crossings work, and what to train by role and desk.","breadcrumb":{"@id":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#primaryimage","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Information-Barriers-in-Financial-Services-blog-banner.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Information-Barriers-in-Financial-Services-blog-banner.png","width":1280,"height":720,"caption":"Threatcop blog banner reading Information Barriers in Financial Services, The Control That Runs on People, over an abstract network graph on a dark navy background"},{"@type":"BreadcrumbList","@id":"https:\/\/threatcop.com\/blog\/information-barriers-financial-services\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/threatcop.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Information Barriers in Financial Services: The Control That Runs on People"}]},{"@type":"WebSite","@id":"https:\/\/threatcop.com\/blog\/#website","url":"https:\/\/threatcop.com\/blog\/","name":"Threatcop","description":"Cybersecurity Blogs, News, Updates, and Articles","publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/threatcop.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/threatcop.com\/blog\/#organization","name":"Threatcop","url":"https:\/\/threatcop.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","width":432,"height":102,"caption":"Threatcop"},"image":{"@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","https:\/\/x.com\/threatcop","https:\/\/www.linkedin.com\/company\/threatcop\/","https:\/\/www.instagram.com\/threatcop_official\/"]},{"@type":"Person","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/8078d9da24781c2e8078d72917df4f6b","name":"Yogyata Sethi","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_29_1789479711-96x96.png","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_29_1789479711-96x96.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_29_1789479711-96x96.png","caption":"Yogyata Sethi"},"description":"Yogyata Sethi is a finance professional at Kratikal with experience in financial analysis, business operations, and corporate finance. She has contributed to key business initiatives, including strategic growth and the company\u2019s public listing journey. Currently pursuing an MBA in Finance, Yogyata is passionate about financial planning, business strategy, and data-driven decision-making. She focuses on creating insights that support sustainable growth and long-term business value.","sameAs":["https:\/\/threatcop.com\/"]}]}},"_links":{"self":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15315","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/comments?post=15315"}],"version-history":[{"count":7,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15315\/revisions"}],"predecessor-version":[{"id":15361,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15315\/revisions\/15361"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media\/15324"}],"wp:attachment":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media?parent=15315"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/categories?post=15315"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/tags?post=15315"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}