
Security & Compliance
Secure Email Solutions
Defense from man-in-the-middle attacks
Control intentional & unintentional information leakage
In today's global financial landscape, the enforcement of security and compliance is no longer a localized requirement but a global regulatory norm. From the Hong Kong Monetary Authority (HKMA) and Securities and Future Commission (SFC) in Hong Kong to Markets in Financial Instruments Directive (MiFID) II in Europe and the SEC in the United States, regulators are increasingly mandating strict information barriers (ethical walls) and conflict-of-interest controls. These mandates are designed to achieve three core objectives: preventing the misuse of inside information, managing organizational conflicts, and ensuring the fair treatment of clients.

What is TSECM? Why is TSECM
Corporate Finance Adviser Code of Conduct
Corporate Finance Adviser Code of Conduct ("CFA Code") Paragraph 4.3 - Chinese Walls
The Corporate Finance Division prepares this FAQ and aims to clarify the meaning of paragraph 4.3 of the CFA Code.
Chinese Wall
Where a Corporate Finance Adviser is part of a professional firm or group of companies undertaking other activities, e.g. auditing, banking, research, stock broking, and fund management, the Corporate Finance Adviser should ensure that there is an effective system of functional barriers (Chinese Walls) to prevent the flow of information that may be confidential or price sensitive between the corporate finance activities and the other business activities. This system should include a physical separation between different staff employed for the various business activities.
Business Email Compromise
21%
increase in reported data breaches
from the data of PCPD
>$70 million
FBI Data identifies
over $70 billion in exposed losses due to
Business Email Compromise (BEC)
Data breach incidents involving
-
Hacking
-
Employee misconduct
-
System misconfiguration
-
Loss of documents on portable devices
-
Inadvertent disclosure of personal data by email, post or fax.
The Challenge: The Human Factor and the "Control vs. Efficiency" Paradox
Despite these rigorous frameworks, the industry recognizes that most information leaks are the result of human factors and careless mistakes. While regulators like the Financial Conduct Authority (FCA) UK and Australian Securities & Investments Commission (ASIC) require "effective organizational arrangements" and "confidentiality controls", manual oversight often falls short of preventing accidental data exposure.
Furthermore, as firms implement the "segregation of functions" and "independent reporting lines" required by bodies like the Monetary Authority of Singapore (MAS) and Securities and Exchange Board of India (SEBI), they face a growing dilemma: more control often leads to more manual work, which inevitably reduces operational efficiency. The administrative burden of maintaining restricted lists, monitoring insider activities, and managing "deal rooms" can slow down the very business functions these controls are meant to protect.

Information Barrier Compliance
Prevent the flow of information that may be confidential or price sensitive between
the corporate finance activities and the other business activities.
Price sensitive
Advises on corp. finance or mergers & acquisitions
Inside information Insider dealing prohibitions
01
Protect against the misuse of and wrongful disclosure of sensitive information
02
Avoid Conflict of interest
03
Law duty of confidentiality to the client
04
Act fairly and in the best interests of their clients
05
Corporate finance information should generally be restricted to those people who "need to know
The Solution:
How TSECM Achieves Balance Through Automation
TSECM is designed to resolve this paradox by balancing stringent security measures with work efficiency through process automation. It transforms compliance from a manual hurdle into a streamlined, automated workflow.
TSECM achieves these results by:
-
Automating Information Barriers: Instead of relying on human memory or manual permissions, TSECM automates the "organizational and administrative arrangements" required by MiFID II, ensuring that sensitive data is restricted to authorized personnel by default.
-
Streamlining Compliance Monitoring: By adopting the "compliance monitoring" expectations of the SEC, TSECM uses automated triggers to identify and prevent potential breaches in real-time, reducing the need for constant manual audits.
.png)
By replacing high-risk manual processes with automated functional segregation, TSECM ensures that firms remain compliant with global standards like the INTERNATIONAL ORGANIZATION OF SECURITIES COMMISSIONS (IOSCO) principles (Principles for Financial Benchmarks, Principle 3 Conflicts of Interest for Administrators and 4 Control Framework for Administrators.) without sacrificing the speed and efficiency required in modern finance.
Key Components of an Effective Email Compliance Program
A robust email compliance program combines policy, people, and technology to ensure secure and accountable communication across the organization.
Below are the essential components:
✅
Policy Development
Establishing clear, comprehensive email policies is the foundation of compliance. These policies should define acceptable use, outline data handling rules, and specify retention periods in accordance with both industry regulations and internal governance standards. They must also cover procedures for handling confidential information, email classification, external communication protocols, and escalation paths for reporting incidents.
.jpg)

📘
Training and Awareness
Establishing clear, comprehensive email policies is the foundation of compliance. These policies should define acceptable use, outline data handling rules, and specify retention periods in accordance with both industry regulations and internal governance standards. They must also cover procedures for handling confidential information, email classification, external communication protocols, and escalation paths for reporting incidents.
💻
Technology Solutions
A. Monitoring and Automation
Implement automated systems that monitor email flow in real-time, flag policy violations, and enforce actions like rerouting, blocking, or archiving. Automation reduces manual errors and ensures consistent policy application across the board.

B. Secure Email Infrastructure
Deploy secure email gateways that offer advanced threat protection, content filtering, and encryption to prevent data leakage and ensure message confidentiality. Use Data Loss Prevention (DLP) tools to detect and block unauthorized sharing of sensitive data.
C. Archiving and Retention
Implement compliant email archiving solutions that store communications in a tamper-proof manner for legally mandated periods. These tools ensure emails are easily retrievable for audits, legal holds, or internal investigations, preserving data integrity and transparency.
Together, these components help organizations mitigate risk, improve accountability, and maintain trust—both internally and with external stakeholders.
An effective email compliance program isn’t just a checkbox—it’s a proactive defense against legal, financial, and reputational harm.

71-75, Shelton Street, Covent Garden, London, WC2H 9JQ, UNITED KINGDOM
© TrustSafe | Privacy Statement | Terms of Use
