top of page
TSECM logo
Security and Compliance banner background

Security & Compliance

Secure Email Solutions

Defense from man-in-the-middle attacks
Control intentional & unintentional information leakage

In today's global financial landscape, the enforcement of security and compliance is no longer a localized requirement but a global regulatory norm. From the Hong Kong Monetary Authority (HKMA) and Securities and Future Commission (SFC) in Hong Kong to Markets in Financial Instruments Directive (MiFID) II in Europe and the SEC in the United States, regulators are increasingly mandating strict information barriers (ethical walls) and conflict-of-interest controls. These mandates are designed to achieve three core objectives: preventing the misuse of inside information, managing organizational conflicts, and ensuring the fair treatment of clients.

The Global Architecture of Ethical Walls

What is TSECM? Why is TSECM

Corporate Finance Adviser Code of Conduct

Corporate Finance Adviser Code of Conduct ("CFA Code") Paragraph 4.3 - Chinese Walls

The Corporate Finance Division prepares this FAQ and aims to clarify the meaning of paragraph 4.3 of the CFA Code.

Chinese Wall

Where a Corporate Finance Adviser is part of a professional firm or group of companies undertaking other activities, e.g. auditing, banking, research, stock broking, and fund management, the Corporate Finance Adviser should ensure that there is an effective system of functional barriers (Chinese Walls) to prevent the flow of information that may be confidential or price sensitive between the corporate finance activities and the other business activities. This system should include a physical separation between different staff employed for the various business activities.

Business Email Compromise

21%

increase in reported data breaches
from the data of PCPD

>$70 million

FBI Data identifies
over $70 billion in exposed losses due to
Business Email Compromise (BEC)
Data breach incidents involving
  • Hacking

  • Employee misconduct

  • System misconfiguration

  • Loss of documents on portable devices

  • Inadvertent disclosure of personal data by email, post or fax.

The Challenge: The Human Factor and the "Control vs. Efficiency" Paradox

Despite these rigorous frameworks, the industry recognizes that most information leaks are the result of human factors and careless mistakes. While regulators like the Financial Conduct Authority (FCA) UK and Australian Securities & Investments Commission (ASIC) require "effective organizational arrangements" and "confidentiality controls", manual oversight often falls short of preventing accidental data exposure.

 

Furthermore, as firms implement the "segregation of functions" and "independent reporting lines" required by bodies like the Monetary  Authority of Singapore (MAS) and Securities and Exchange Board of India (SEBI), they face a growing dilemma: more control often leads to more manual work, which inevitably reduces operational efficiency. The administrative burden of maintaining restricted lists, monitoring insider activities, and managing "deal rooms" can slow down the very business functions these controls are meant to protect.

Chinese Wall

Information Barrier Compliance

Prevent the flow of information that may be confidential or price sensitive between
the corporate finance activities and the other business activities.
Price sensitive
Advises on corp. finance or mergers & acquisitions
​Inside information  Insider dealing prohibitions

01

Protect against the misuse of and wrongful disclosure of sensitive information

02

Avoid Conflict of interest

03

Law duty of confidentiality to the client

04

Act fairly and in the best interests of their clients

05

Corporate finance information should generally be restricted to those people who "need to know

The Solution:
How TSECM Achieves Balance Through Automation

TSECM is designed to resolve this paradox by balancing stringent security measures with work efficiency through process automation. It transforms compliance from a manual hurdle into a streamlined, automated workflow.

TSECM achieves these results by:

  • Automating Information Barriers: Instead of relying on human memory or manual permissions, TSECM automates the "organizational and administrative arrangements" required by MiFID II, ensuring that sensitive data is restricted to authorized personnel by default.

  • Streamlining Compliance Monitoring: By adopting the "compliance monitoring" expectations of the SEC, TSECM uses automated triggers to identify and prevent potential breaches in real-time, reducing the need for constant manual audits.

TSECM email flow

By replacing high-risk manual processes with automated functional segregation, TSECM ensures that firms remain compliant with global standards like the INTERNATIONAL ORGANIZATION OF SECURITIES COMMISSIONS (IOSCO) principles (Principles for Financial Benchmarks, Principle 3 Conflicts of Interest for Administrators and 4 Control Framework for Administrators.) without sacrificing the speed and efficiency required in modern finance.

Key Components of an Effective Email Compliance Program

A robust email compliance program combines policy, people, and technology to ensure secure and accountable communication across the organization.

Below are the essential components:

Policy Development

Establishing clear, comprehensive email policies is the foundation of compliance. These policies should define acceptable use, outline data handling rules, and specify retention periods in accordance with both industry regulations and internal governance standards. They must also cover procedures for handling confidential information, email classification, external communication protocols, and escalation paths for reporting incidents.

Policy Development
Training and Awareness
📘
Training and Awareness

Establishing clear, comprehensive email policies is the foundation of compliance. These policies should define acceptable use, outline data handling rules, and specify retention periods in accordance with both industry regulations and internal governance standards. They must also cover procedures for handling confidential information, email classification, external communication protocols, and escalation paths for reporting incidents.

💻
Technology Solutions

A. Monitoring and Automation

Implement automated systems that monitor email flow in real-time, flag policy violations, and enforce actions like rerouting, blocking, or archiving. Automation reduces manual errors and ensures consistent policy application across the board.

Technology Solutions

B. Secure Email Infrastructure

Deploy secure email gateways that offer advanced threat protection, content filtering, and encryption to prevent data leakage and ensure message confidentiality. Use Data Loss Prevention (DLP) tools to detect and block unauthorized sharing of sensitive data.

C. Archiving and Retention

Implement compliant email archiving solutions that store communications in a tamper-proof manner for legally mandated periods. These tools ensure emails are easily retrievable for audits, legal holds, or internal investigations, preserving data integrity and transparency.

Together, these components help organizations mitigate risk, improve accountability, and maintain trust—both internally and with external stakeholders.

An effective email compliance program isn’t just a checkbox—it’s a proactive defense against legal, financial, and reputational harm.

TrustSafe logo small

71-75, Shelton Street, Covent Garden, London, WC2H 9JQ, UNITED KINGDOM

bottom of page