Information Technology

IT is the backbone of the company’s technology infrastructure, ensuring that systems, applications, and data remain secure, reliable, and ready to support your daily work. As an Investment Adviser Representative (IAR), safeguarding client non-public information (NPI) is critical.

  • Important Technology Alerts

    ALERT: Microsoft Phishing Exploit Affecting Email Domains


    Our Technology team has identified a critical Microsoft email exploit, known as a "Direct Send," impacting our @creativeone.com and @creativeonewealth.com email tenants. This phishing vulnerability allows external users to send emails that appear to originate from internal addresses within our domains, bypassing our standard ProofPoint spam filters.


    Issue Details

    • Impact: Emails may appear to come from any individual or shared mailbox within our @creativeone.com or @creativeonewealth.com tenants.
    • Risk: These emails often contain malicious attachments or links designed to compromise security.
    • Why It’s Not Caught: The exploit circumvents our ProofPoint filtering system, allowing phishing emails to reach inboxes undetected.

    Action Required

    To protect yourself and our organization:

    1. Verify Emails: Scrutinize any suspicious email, even if it appears to come from a trusted internal address. Look for unusual language, unexpected requests, or unfamiliar links/attachments.
    2. Do Not Engage: Avoid clicking links or opening attachments in questionable emails.
    3. Report to IT: Forward any suspicious emails to IT Support immediately for review. Do not take further action until IT confirms the email’s safety.
    4. Stay Vigilant: Be cautious of emails requesting urgent action, sensitive information, or financial transactions.

    Example of Suspicious Email

    Phishing emails may resemble the following:

    • From: user@creativeone.com or sharedmailbox@creativeonewealth.com
    • Content: Contains an unexpected attachment (e.g., .pdf, .docx) or a link to an unfamiliar website.
    • Subject: Often urgent or generic, such as “Action Required” or “Document Review.”

    If you have questions or encounter a suspicious email, contact IT Support immediately.


     

    ALERT: General Email Whitelisting Procedures

    To ensure you stay up to date with all CreativeOne and CreativeOne Wealth emails, please review the following email whitelisting procedures. 

    1. Trusted Senders: @creativeonewealth.com, @em.creativeonewealth.com and @creativeone.com
    2. Access Email Settings: Log in to your email client or server admin panel and navigate to the spam filter, junk mail settings, or security rules section. OR contact your hosting administrator to assist.
    3. Add to Whitelist: Input the trusted sender’s email or domain into the appropriate whitelist or “safe senders” list.
    4. Monitor and Update: Regularly review the whitelist to add new trusted senders or remove outdated ones. Check logs if emails are still blocked.
    5. Enable Logging (if applicable): For server-level whitelisting, enable logging to track allowed and blocked emails for troubleshooting.
  • Device Security Setup and Monitoring

    Reliable IT support is essential to keeping operations running smoothly and ensuring employees have the tools they need. Because CreativeOne Wealth does not currently have a dedicated IT team, we’ve outlined recommended solutions below. We also recommend partnering with a local IT support provider to strengthen security and improve operational reliability.


    Minimum Requirements: 

    • PCs: Windows 10+ with automatic updates; Macs: macOS 10.15+ with automatic updates. 
    • Mobile: Latest iOS or Android; enable auto-security updates. 

    Protection Malware Software (Anti-Virus & Spyware): Install malware suite (anti-virus, firewall, browser protection) like Bitdefender, Windows Defeder, Trend Micro. Set for automatic updates


    How do I know if I have antivirus 


    Encryption: Enable full-disk encryption (e.g., BitLocker on Windows) on all devices accessing/storing NPI.

    BitLocker Encryption Overview 


    Access Controls: Password-protect all devices (8+ characters, mix upper/lower case, numbers/symbols; change every 90 days). Use screen saver lock after 5 minutes inactivity. Fingerprint/facial recognition OK on mobiles.


    Networks: Firewalls on all devices/networks. Intra-office networks must be firewalled and not public. Windows Firewall (ensure on automatic updates are turned on) 

    Instructions on how to turn Microsoft Defender Firewall on or off


    Automatic updates, including software patches should be enabled. 

    To change your Automatic Updates settings by using Windows Security Center


    Upgrades/Disposal: Wipe/destroy hard drives before disposing; verify data removal.


    Endpoint Protection: Endpoint protection services provide comprehensive, centralized security for networked devices—including laptops, mobile devices, and servers—against malware, ransomware, and advanced, fileless attacks. 


    Recommended Solutions:  


  • Lost or Stolen Laptop

    Losing or having your work laptop stolen can be stressful, but acting quickly minimizes risks to company data, your personal information, and business operations. Follow these steps immediately—time is critical to prevent unauthorized access.


    1. Assess the Situation: Double-check common spots where you might have left it (e.g., under a seat, in a bag, or at a desk). If you're in a public place like an airport, hotel, or office, contact lost-and-found immediately.


    2. Notifications: Notify Supervisor (if applicable), C1W IT Department and C1W Compliance: Report the incident right away via phone or email. Provide details like the location, time, and any suspicious activity.


    3. Log Out of Cloud Services and Accounts: From another device, sign into company apps (e.g., Google Workspace, Microsoft 365, email) and revoke access for the lost laptop. Look for "active sessions" or "devices" in account settings to log it out remotely. This prevents thieves from accessing cloud-stored files.


    4. Change All Relevant Passwords: Update your company login, email, and any work-related accounts immediately, especially financial accounts. If multi-factor authentication (MFA) is enabled, verify it's still secure. Do the same for personal accounts if the laptop has autofill data.


    5. Enable Remote Features (If Not Already Done): • For Windows laptops: Use Find My Device to locate, lock, or erase the laptop once it connects to the internet. • For MacBooks: Use Find My to mark it as lost, play a sound, or remotely wipe it.


    6. Monitor for Unauthorized Activity: Check your work email and accounts for unusual logins. If personal financial info was on the device, contact your bank/credit card issuers to freeze accounts and monitor for fraud. Consider placing a fraud alert on your credit report.


    7. Document: Note the exact time, location, circumstances, and steps you've taken. Share this with C1W IT Department and C1W Compliance.


    Best Practice • Always use a strong password and enable full-disk encryption (e.g., BitLocker for Windows, FileVault for Mac).


    For additional support email CreativeOne Wealth IT Support

  • Email Program Security

    Email Providers: IARs shall use professional email programs/hosts for advisory services. Ensure providers support MFA, TLS encryption, and integration with Smarsh for archiving. Common top providers include Microsoft 365/Outlook and Google Workspace/Gmail.


    For Microsoft 365/Outlook

    • Enable MFA using the Microsoft Authenticator app.
    • TLS encryption is enabled by default for secure transmission.
    • Configure Smarsh integration to monitor and archive all advisory emails.

    For Google Workspace/Gmail: 

    • Enable 2-Step Verification (2FA) via Google Authenticator or similar.
    • Use Gmail's confidential mode for sensitive emails or password-protect attachments.
    • Set up Smarsh journaling or API integration for compliance archiving.

    General Requirements

    • For sending NPI to external recipients: Encrypt the email (e.g., via S/MIME or provider tools) or password-protect attachments (share password verbally, not in email); add [Secure] in subject line.
    • All advisory emails must be archived via Smarsh for regulatory compliance.
    • No investment discussions via non-archived text unless.
    • If texting clients, use Smarsh Mobile Capture Contact us at  compliance@creativeonewealth.com  
    • Shared Emails: Permissible for efficiency (e.g., info@yourfirm.com); include sender name in signature and track access logs.

  • Electronic Storage of Client Files

    Preferred Methods: Store client NPI in approved cloud-based platforms only. Strongly discourage local storage on hard drives or desktops.


    Approved Vendors: Use vetted systems like CreativeOne Wealth Platform, Redtail,  WealthBox, Google Drive, Dropbox, OneDrive, Egnyte, eMoney, MoneyGuidePro, Microsoft Office and Teams. See Advisor Resource Center for a complete list.


    Prohibitions: No storage on removable media (e.g., USB drives, CDs).


    Best Practice: Limit access to "need-to-know" basis; use principle of least privilege.


  • Common Software and Tools Security

    MFA Mandatory: Enable on all platforms accessing NPI.


    Online Meetings: Use approved encrypted tools with E2EE/AES-256: Zoom,  Microsoft Teams, Cisco Webex. Avoid unapproved like Zoho, Google Hangouts/Meet, GoToMeeting.


    Wireless Internet: Office Wi-Fi must be password-protected (strong password). On public Wi-Fi, use VPN to protect data.


    User Accounts: Unique logins for platforms; no sharing except permitted shared emails. Update inventory/roster in MyCompliance Office (MCO) annually or on changes.


    Phishing Awareness: Verify suspicious emails verbally; don't click unknown links or share info.


  • Data Breach

    Financial services firms continue to face significant data risks, including data breaches, and cyberattacks. Failure to comply with regulations can result in hefty fines and legal penalties. Follow the protocal outlined below if your office experiences a data breach. 


    1. Report suspected breach immediately to C1W Compliance Team
    2. Contain the breach by isolating the affected systems (log out of all sessions, disable accounts
    3. Collect all system login information and change usernames and passwords
    4. Make a pst copy of the email for us to send off for review for PII
    5. Date breach occurred and date discovered
    6. With assist from C1W Compliance and IT teams, determine the number of affected individuals (clients, employees, prospects), and next steps
    7. Review your state specific data security breach guidelines for additional actions that might need to be taken.