
- Sign up to free AFI briefing emails for exclusive industry updates and get ahead with AFI Intelligence membership
- Abacus buys Chicago MSSP Entara to drive US growth
“Total vigilance” is a must for hedge funds and other alternative fund managers targeted by ever-more sophisticated hackers, says Travis DeForge, director of offensive cybersecurity at Abacus Group.
“The risk level has never been higher so there’s a need to really have total vigilance,” he says during a trip to London from the US. “It’s never been easier to break into companies.”
Social engineering
New York-based Abacus, a managed IT and cybersecurity service provider, performs penetration testing/social engineering and will probably do 500 to test client defences this year, says DeForge.
Clients, having given their consent, are tricked into permitting access to the systems using things like phishing emails, or even deep fake videos and live voice using AI tools.
“A couple of years ago you had to have a pretty expensive computer to pull those things off, and you had to really know your stuff,” says DeForge. “Now, you can do it with a minute of audio, chatGPT and YouTube.”
That type of risk can be acuter for private equity firms, whose various portfolio companies will be geographically spread and there may be less familiarity. Often times it is the portfolio companies which provide a larger attack surface for the initial access, before a malicious actor pivots to attacking the PE firm directly.
Regulatory impact
While social engineering testing isn’t explicitly required by most regulators, sophisticated LPs are requesting firms to conduct this testing much commonly than in years past.
Indeed, some clients are now applying the standards put in place by the EU’s new DORA regulation on a global basis, as a risk mitigation on the assumption that other regulators may go down the same route in future.
While the industry has been adapting to DORA, the next question will be how it is enforced. “I’d be really curious to see how the market reacts once there’s a little bit more insight into what the audit and examinations actually look like,” says DeForge.
Risk assessments
His key message is that hackers are becoming a lot more sophisticated. What can hedge fund managers do to ensure best practices in this area?
“We generally recommend to everybody to start off your year with a really thorough risk assessment — get a third-party in there to look at the configurations from every angle. This should set the roadmap for the next 6-18 months of security initiatives for the firm.”
He adds: “Make sure everything is aligning, not only to your written policies/procedures and your incidence response plan, but make sure that what’s written in those policies is actually the what’s implemented on the technical side.”
Abacus may go through the audit and find policies which state that all workstations are encrypted at rest. Yet during the technical evidence stage find that out of 40 workstations only 35 of them encrypted are actually encrypted.
“The FCA doesn’t think 95% is 100% and the cyber insurance won’t either,” says DeForge. “So, from just from that kind of a risk mitigation standpoint, make sure there’s alignment. And then from there, it becomes a matter of using that output as your roadmap for the rest of the year to identify where it makes sense to make further investments into your security posture.”
Sometimes it will make sense to bring in a technically sophisticated strategy, like network micro segmentation, other times, it’s just a matter of changing some configurations in a firm’s Microsoft environment.
AI’s role in the fightback
“A lot of security products are implementing AI in really interesting ways. There are tools out there using AI to help flag if the person you are interacting with online is real or not,” says DeForge, highlighting Netarx for deepfake prevention and Conduit Security for wirefraud prevention.
In the hedge fund and private credit space, the goal can often “just” be wire fraud. “Hackers use the same kind of techniques with voice cloning, spoofing phone numbers, deep fakes etc.” It’s a different endpoint, but equally threatening to a business.


