Your Clients’ Data Is a Target. Here’s How LPL Is Helping You Protect It.

In this episode of If You Could, LPL's Renana Friedlich provides insights on how LPL's cybersecurity strategy helps advisors protect client data with defense-in-depth tools and everyday best practices.

Last Edited by: LPL Financial

Last Updated: June 10, 2026

Renana Friedlich-Barsky, Executive Vice President, Chief Information Officer & Information Security Officer, LPL Financial

IN THIS ARTICLE


One morning, one of LPL’s top advisors picked up the phone and called with an urgent problem: ransomware had locked every computer in their practice overnight. Employees arrived to find screens displaying a Bitcoin payment demand. Operations came to a halt.

With support from LPL’s cybersecurity team, the practice was restored in days rather than weeks. But the experience was a stark reminder of something Renana Friedlich, LPL Financial’s chief information security officer, wants every advisor to understand: a cyberattack isn’t an abstract risk. It’s a business continuity event — and it can happen to anyone. Friedlich recently shared these insights on the If You Could with Matt & Taryn podcast.

The cybersecurity threat landscape has fundamentally changed, and financial advisors are increasingly finding themselves on the front lines. What was once considered an issue for large corporations is now a daily business risk for practices of every size. The speed, sophistication, and accessibility of cyberattacks have accelerated dramatically, creating new challenges for advisors entrusted with sensitive client information and financial assets.

For Friedlich, who draws on decades of experience spanning military intelligence, corporate incident response, and enterprise security leadership, the message is clear: cybersecurity is no longer just an IT concern. It’s a business imperative.

“Ultimately, security is going to be one of our top business differentiators, positioning us in a place where we’re not only protecting the business, but we’re helping to better protect our advisors and their clients” says Renana.

Why Financial Advisors Are Increasingly Targeted

Not long ago, organizations often had weeks — or even months — to respond after a new software vulnerability was discovered. Today, cybercriminals can begin exploiting weaknesses in less than 24 hours. As the window between discovery and attack shrinks, businesses have less time than ever to react.

At the same time, attackers are shifting their focus.

Large financial institutions have invested heavily in cybersecurity defenses, making them harder to penetrate. As a result, many cybercriminals are increasingly targeting smaller organizations that maintain valuable financial and personal information but may not have the same level of protection in place. Advisors sit squarely in that category.

Emerging technologies are also lowering the barrier for attackers. Tools powered by artificial intelligence can generate convincing phishing campaigns, impersonations, and deepfakes at a fraction of the cost and effort required just a few years ago.

LPL’s Response: A Defense-in-Depth Strategy

As cyber threats become more sophisticated, relying on a single security control is no longer enough.

That’s why LPL’s Cybersecurity Uplift Program is built around a strategy known as defense in depth — a layered security approach designed to provide multiple safeguards across identities, devices, and data. If one layer is bypassed, additional protections remain in place to help limit risk and prevent a single mistake from becoming a major incident.

The Cybersecurity Uplift Program includes several key components:

  • Enhanced device security
  • Data masking
  • Multi-factor authentication (MFA) for email
  • The LPL Business Browser
  • Cybersecurity insurance planned for launch later this year

Together, these capabilities create multiple lines of defense intended to strengthen security across advisor practices while supporting the day-to-day technology experience advisors rely on.

How the LPL Business Browser Adds Another Layer of Protection

One example of the defense-in-depth approach is the LPL Business Browser, a secure browsing environment designed specifically for advisor business activities.

The concept is similar to separating business and personal devices. Advisors conduct work-related activities within a protected environment that is isolated from personal internet use, helping reduce exposure to common risks.

If a phishing email attempts to direct an advisor to a malicious website or download, the browser can block the threat before it causes harm. Additional security controls at the device level provide another layer of protection if an attack manages to get past the first line of defense.

To date, the LPL Business Browser blocked more than 20,000 attacks without advisors ever knowing they had been targeted. It’s a powerful example of how effective security often works quietly in the background — protecting users without disrupting their workflow.

Cybersecurity Is a Shared Responsibility

Technology plays a critical role in protecting advisor practices, but individual habits remain just as important.

Many successful cyberattacks exploit routine oversights rather than sophisticated technical vulnerabilities. Some of the most effective security measures are also some of the simplest:

  • Apply software and system updates promptly.
  • Enable multi-factor authentication on all accounts containing sensitive information.
  • Encrypt files stored on business devices.
  • Reduce reliance on physical documents, which can create additional fraud and security risks.

Advisors looking for additional support can access cybersecurity resources through branch office security policies, and dedicated cybersecurity support channels. Educational materials are also available for advisors who want to share cybersecurity guidance with clients.

Preparing for What’s Next

While today’s threats demand attention, Friedlich and her team are already focused on what’s coming next.

One area of particular interest is quantum computing, which has the potential to dramatically change how organizations think about encryption and data security. Quantum systems, once mature, could render many of today’s encryption standards obsolete—meaning organizations need to be ready to adapt their security methods rapidly. That adaptability is what Friedlich calls “crypto agility”: the ability to swap out encryption approaches as technology evolves and new risks emerge, without disrupting the business in the process.

For Friedlich, the goal extends beyond simply defending against threats. A stronger cybersecurity foundation creates opportunities for innovation — making it possible to safely introduce new tools, capabilities, and experiences for advisors.

"Once we have the Cybersecurity Uplift enhancements in place, we will be able to unlock the door to new opportunities and new tools that advisors would like to use, giving them even greater experience with the LPL ecosystem."

Renana Friedlich-Barsky

Executive Vice President, Chief Information Officer & Information Security Officer, LPL Financial

Cybersecurity isn’t just about protection. It’s about building the confidence, resilience, and trust that advisors need to serve their clients and grow their practices.

Featured Guest

Renana Friedlich-Barsky, Executive Vice President, Chief Information Officer & Information Security Officer, LPL Financial

Renana's leadership and dedication to the field extend beyond her professional duties, as she actively engages in shaping the future of cybersecurity through speaking at Security conferences and serving on advisory boards at leading universities, tech companies, and startups.

 

 

Renana (00:01):

I remember a case, I get a call from one of our top advisors and he's sharing a story with me about getting hit with ransomware. The panic is high, the practice is down. Yeah, all the computers have a messages on the screen saying You've been ransom. Then here's how you pay us with Bitcoin. The average person never experienced anything like that.

Matt (00:29):

Hey everybody, I'm Matt and Yeti Taryn's here with me too. And you are listening to if you could,

Taryn (00:34):

And I'm so glad you're here.

Matt (00:36):

Now t before we get started, I want to begin today's podcast by traveling back in time all the way back to the year 1997.

Taryn (00:44):

Oh, that was a good year.

Matt (00:45):

Had good year, a kinder, simpler time for sure. And there were some seminal happenings. Our daily behaviors were forever changed by the introduction of a OL. And this all too familiar alert. You've got mail

Taryn (00:58):

Man, I remember those days. And the excitement of hearing those three A OL words felt like a really big deal at the time. It

Matt (01:05):

Was a big deal. 'cause it meant your friends were able to connect with you anytime they wanted to and tell you anything that was going on in their lives. But at some point the email started to become mundane. A little bit annoying and ultimately stressful because now people, including your bosses, had access to you 24 7. Now we've added a whole new adjective. 'cause now they're scary too because today we are facing a vast network of state sponsored terrorists and their AI enabled phishing scams, introducing viruses and ransomware and the ability to take over your network and potentially crippling your business.

Taryn (01:41):

Exactly. And while the headlines focus on outages hitting hyperscalers, hospitals and utilities, the reality is that the risk has shifted as the largest players invest heavily to strengthen their defenses. They're having real success in defending the bad guys. But the bad actors haven't slowed down. They're just adapting. And increasingly they're turning their focus to more accessible targets. All of you, including you, Matt.

Matt (02:07):

Yeah, no, look folks, they're after us, all of us ladies and gentlemen, welcome to the summer of vulnerability where not only do you need sunscreen and a hat, you also need multifactor authentication, endpoint protection, and regular security patching. And while the road ahead is going to require significant change, it's also just the beginning of a whole new normal. Because for every advancement AI brings to our productivity, it further arms the bad guys to wreak havoc.

Taryn (02:34):

But at the same time, we also have more ways to stop those attacks, especially the scaled partners like LPL who have the tools, the talent, and the resources needed to stay ahead of it. So this isn't about doom and gloom is about how we protect our advisors and the clients they serve. Strong infrastructure, evolving tools, clear protocols and the teams behind it all. And today we're joined by Ana Friedli, our chief information Security officer. She's one of the leaders driving this work, sharing what she's seeing across the industry and how we're keeping LPL and our clients safe along the way.

Matt (03:11):

She not only talks the talk, she's walked the walk and she's literally written the book on how to be a security executive.

Taryn (03:17):

Let's get into it.

Matt (03:18):

Let's go. Rena, welcome to if you could. We are pumped to have such a cool conversation with such a cool guest today. Are you pumped?

Taryn (03:28):

So

Renana (03:28):

Pumped. I'm excited to be here. I

Matt (03:29):

Knew you would be. Hey, I wanna get into a lot today. We are gonna go all over the world of cybersecurity or actually I think it's more cyber terrorism is the threat we face today. But I wanted to kind of dive into your background because it's a pretty cool one. And what you bring to LPL is not just a history of kind of corporate cyber protection, but a much more broad view being raised in a small town of Kava, Sava and Israel to moving to the US in 2014 to begin your corporate career working with ENY and then PayPal and then LPL. But I think there's even more compelling and interesting story was your early days of getting into the cybersecurity. We're actually working for the elite Israeli military intelligence unit and that set the groundwork for all that you would bring to corporate America. What a wild ride you've had.

Renana (04:21):

Oh yeah, it's been, it's been a great ride and I'm so, so thankful for it. I mean some people know that in Israel it's actually mandatory to solve in the military how

Taryn (04:30):

Many years? Uh,

Renana (04:31):

It's two years for women. I sell full seven 'cause I thought this was such an amazing experience and I wanted to make the best of it. So I had exposure to the smallest people you can possibly imagine. I've had access to military grade training on cybersecurity. And so when I think about it, it just gave me exposure to the most amazing technology that you can get exposed to if I think about what we did at 18 years old. That's wild. Yeah. Um, and I think it really helped me build a strong sense of ownership and most importantly, adaptability to changing situations, which is something we deal with in corporate America all the time.

Taryn (05:13):

You obviously started there, but then you make this pivot to EY in the us. How did you get there?

Renana (05:19):

So I traveled to the US for the first time on my own. I was doing a project for Fortune 10 company. I was so honored to come from Israel to that company and provide them with consulting services around incident response, computer forensics. And that spiked the light in terms of what else can I do? What else can I become? And so there I was fortunate enough to have a sponsor who helped me take that idea and make it a reality.

Matt (05:52):

Yeah. And the rest is history, right? I mean so many kids grew up being so excited about incident response and computer forensics <laugh>. Yeah, I'm sure it was just they all dream of, I'm sure the dream from day one. Have you

Renana (06:04):

Ever watched like CSI Cyber? No. Have you watched it? No. So the whole concept of as an investigator, you walk into a crime scene and you are looking for signs and evidence of something that happened. But in today's world, the crime isn't always physical. It can be digital. And so it requires people to have training on how to investigate computer crimes. I can actually analyze part of your personality based on your desktop.

Matt (06:33):

Based on our desktop. When you come look at it,

Renana (06:35):

If I can look at your desktop

Matt (06:37):

Ladies and gentlemen, after the podcast, gonna do podcast. We're podcast today. We're gonna go look at our desktops and Renana is gonna tell us all that is wrong and right with us. And I'm nervous.

Renana (06:45):

<laugh>.

Matt (06:45):

Hey Rena, it's cybercrime is hot and it is heavy and it is only getting bigger and and more challenging than ever before. And I think there was a pretty big moment on April 7th of this year and that is when Anthropic launched its latest model mythos. It's 90 times more powerful than the previous release. And it has this autonomous discovery and exploitation capability to find zero day vulnerabilities abilities to affect every operating system and browser on the planet. In fact, it's so powerful folks, that upon review, Andro decides not to release it to the wild because it could have taken down the capital markets as we know them. And so instead they released it to 40 hyperscalers and said, guys and gals take a look and protect yourself. And what we're hearing is they're finding millions of unknown vulnerabilities to their systems. So that's the backdrop of the landscape we're at.

Renana (07:44):

So I think it's pretty amazing if you think about it hackers, well actually the first to adopt ai, they don't have to see it through governance committees. They don't have to get approval to buy extra tokens. So the cybersecurity community has to follow what hackers are doing. And so I would think about it in terms of three waves. The first wave for cyber defenders, everyone was like, no, no thank you. I don't wanna touch it. Let someone else do that. The second wave was, okay, let's start using it. Let's start embracing it, see how it helps scale the cybersecurity programs at companies around the world. And then I think now we're at the third wave where companies understand we have to embrace ai. We cannot respond to myth to everything else that's coming at us unless we embrace AI and use it at scale.

Matt (08:41):

Yeah. But not everyone has the ability to use it at scale. At least not yet.

Renana (08:45):

Well that's where it's actually important to understand what is it that you need to do because the world that we live in with all those vulnerabilities coming at you talk about the concept of self-healing. Full disclosure, I actually spoke with uh, my team at PayPal about self-healing in 2020. And it was a wild idea back then where you can fix your environment, where you can fix your code automatically without human intervention. And we are now at a place where not only that it's feasible, that's where we are ultimately gonna have to go because you cannot fix millions of vulnerabilities without ai.

Taryn (09:29):

So I'm gonna build on all of this 'cause Matt set up mythos and you know, it obviously represents a real inflection point. You know, the pace, the scale and the sophistication is all accelerating. And then you layer on top of that the fact that threats are happening 700 times more often than even just a year ago. And we set this up at the beginning, you know, we called it the summer of vulnerability. And it isn't just a season. It's really becoming our new reality and our new baseline. Is it possible that with all of this going on that we're overreacting at all?

Renana (10:04):

I'll give you the short answer. I don't think we're overreacting. I think we as a company, we as an industry in terms of cybersecurity, recognize that we have to take this seriously. And it's not a question of if but when. And the pace is so much faster that the time to exploit the vulnerability is shorter. Now I recognize exploit sounds like a very technical term. So I'll explain what I mean by that. When you find the vulnerability, it's like finding a potential way to break into your home, right? Yeah. Right. You can break into your home through the window, through the door, but then there needs to be something that actually allows you to do that. Maybe that's because you left your front door open or you left your window open. That's the exploit that we're talking about. Yeah. The opportunity. And so now in today's world the opportunities have expanded 700, 1,000 x. And so now it's about how quickly from the moment that opportunity or exploit is found, you are able to remediate it.

Matt (11:14):

Well what I had read the other day was that it took almost two years from the identification of an exploitation opportunity to the execution of that exploitation. And now it's taking less than 24 hours.

Renana (11:26):

That's right. And and historically you would have people and that would be the exporte, how do you take a vulnerability and write an exploit for it? But now with AI you no longer depend on how long can someone sit at their computer or when you're gonna be delivering pizza to their desk. Now the machine is doing it.

Taryn (11:45):

You mentioned hackers were the first to utilize ai. Do they have a headstart in many ways because they have been sort of incorporating, I'm also curious how they come up with the funding to continue to advance it. It's

Renana (11:57):

Not that expensive. Yeah. When you think about it, um, if you were to go online right now and let's say you wanted it to create an impersonation where you look like rich and you post a video to the entire company. Yeah. You could do that in less than $20.

Taryn (12:14):

Yeah.

Renana (12:15):

And so the thought is the tools are accessible. We're actually lowering the bar in terms of what do you need to get access to these tools? And they don't have to see through committees, they don't have to wait for approvals. They just go ahead and

Taryn (12:30):

Do it. They just go.

Matt (12:31):

Makes sense. And it's getting less and less expensive to be more and more sophisticated. But is that true on the other side is the defense following that same pattern?

Renana (12:39):

The defense is getting better and incorporating AI and the amount of tools and the amount of research that is happening in the industry right now is unbelievable in terms of both the pace that new tools arise to solve problems that didn't even exist like two months ago.

Taryn (12:57):

It's really important to ground the reality of all of this because it

Matt (13:01):

All feels pretty sci-fi, it

Taryn (13:02):

Feels pretty sci-fi and it feels real and it feels personal. So I love if you could share some stories and ways that our clients are being impacted today. Sure. Just to make it feel

Renana (13:13):

More tangible. Remember a case, I get a call from one of our top advisors and he's sharing a story with me about getting hit with ransomware. You never wanna be on that part receiving the call when the panic is high, the practice is down. Yeah. All the computers have messages on the screen saying you've been ransom, then here's how you pay us with Bitcoin. The average person never experienced anything like that. No. Would like to experience anything like that. And so he's reaching out and saying, I need help.

Taryn (13:48):

What did the email look like? Does he recall which email he had clicked on?

Renana (13:53):

Yes. And so he shared a screenshot of what his computer screen looked like with us. And at that point in time he is just saying, I need help. I don't know where to start. I,

Taryn (14:04):

I'm just

Renana (14:05):

Lost. I don't know what they want from me with the Bitcoin requirement. How do I engage with them? This is just too techy for me. And so I jumped on the call and given my experience, you may not know about this about me, but I helped dozens of Fortune 500 companies through cyber crisis just like this one. Yeah. And so I'm bringing that experience and I started a process of setting him up and most importantly calming him down that we're gonna be able to get him back in business. It was something that could have taken weeks because he walked with us. It took days. Yeah. And he was able to get back up and running. And I think ultimately when we had a chance to sit down and debrief after he was recovered from the incident, he talked about how that experience was game changer for him in terms of how he's thinking about cybersecurity and what are the things that he's gonna be doing next.

Matt (15:06):

Well it's a massive wake up call and it shows how vulnerable we all are and how real this is. 'cause effectively we're all one click away from being locked out and shut down. And I could totally feel that panic coming from him. 'cause these are folks who deal all day long with financial markets and, and client concerns, geopolitical crisis. They are not thinking about some sort of state sponsored folk coming at me, shutting down my business and demanding hundreds of thousands if not millions of dollars in Bitcoin in order for you to get back up and running and helping the communities you serve. Which I think is a really good segue to the next part of our conversation because we've been building our back office infrastructure and protection for a long time. We are a scaled player, but what we recognize is we have thousands of clients who aren't necessarily in that same position to make that same type of investment.

Matt (16:00):

And we have a responsibility to partner with them and, and not just solve for when a crisis occurs but prevent it from starting or happening in the first place. And so we've got a broad set of new capabilities and responsibilities that we're putting out to our clients. In addition to making sure folks have multifactor uh, authentication for their emails, we're introducing a new LPL business browser that is secure. We've got more endpoint security, we are doing data masking and we're introducing later this year cybersecurity insurance for folks to take on as well. We call it the security uplift. We're making sure that our clients are protected so that ultimately their businesses and the and the Americans they serve are also protected. Walk us through, 'cause this is kind of the next evolution. We've spent a lot of time protecting this house, but we recognize no house is safe if we aren't helping all

Renana (16:54):

Historically hackers came after the big fish in the ocean. Right. But now the big fish is actually doing better. Yeah. So they're going after other smaller fish and they're going after advisors. And so this is why we're introducing a concept called defense in depth, where we are going to place multiple controls, stack one upon the other so if one control breaks, the next level will kick in. And that gives our advisors something that is new and exciting. Yeah. Not only we're giving them more security, but we're also going to improve their experience, their support model and what they can expect of us as a firm

Taryn (17:37):

From a client experience standpoint. We're taking a multi-layered approach to protection, but at the same time we're spending a lot of time and through all of this we're listening to our clients, we're hearing their feedback and what they're thinking about the security uplift process. Many understand the need and are cited, but then others are asking really fair questions about how far we're going and where is that line. I'm curious how you would respond to that.

Renana (18:06):

So I would divide my answer into two. One, we see what happens to firms who don't take that action and we, we look at the industry, we look at the impact not only to the advisors but also to their investors. And that's a race that we're not willing to take. Yeah. We want our advisors to be safe. And so we're doing it with care, we're doing it with diligence. There are bumps along the way, but we are working very quickly to address them and make sure that not only we're increasing the overall security, but also that we are in touch and making the necessary modifications as things come up.

Taryn (18:47):

And we're in line with what other scale players are doing as well.

Renana (18:50):

The industry is saying what used to be good enough now has to uplift into a new level because we recognize that advisors are now being targeted by cyber hackers. And not only that, they are being targeted with AI empowering them. They're going at them 11 x 20 x more than they used to.

Matt (19:15):

Yeah. And look, it isn't just the industry, it's our regulators as well who are seeing these new risks and they're requiring firms to live into those risks as well. And I was just having this conversation with Rich and he said, Hey look, the threat environment has changed and so we have to change as well. We are not working in quarters or years anymore. This is like real time action that has to be addressed because one layer is never foolproof.

Renana (19:40):

Right. And so to me, ultimately security is gonna be one of our top business differentiators for us as a company positioning us in a place where not only we're protecting the business, but we're protecting our advisors and the end investors.

Matt (19:56):

The multiple layers are necessary. Maybe give an example of something you've seen, you talked about the ransomware, some of those examples where we see the impact and the importance of the multiple layers of protection.

Renana (20:09):

So let's take a hypothetical scenario where someone receives a a phishing email, right? And they want to go and open that phishing email, but they're doing it in the business browser.

Matt (20:22):

So real quick, help us understand what the business browser is.

Renana (20:24):

So the business browser is a browser that has additional protections that we offer to advisors to help reduce the risk of something bad happening rather

Matt (20:34):

Than going into Chrome or Safari. They're going into a new browser just for running client works and other LPL sites.

Renana (20:41):

Correct. The way to think about it is you have your business browser where you do work related items and then you have your personal browser where you do everything else. If that advisor would go into the browser and decide to download something, we will be able to stop that download if we know that it's malicious. Yeah. But wait, let's say that that advisor is particularly naughty.

Taryn (21:04):

They really wanna get it how

Matt (21:04):

You need to know how to solve this problem.

Renana (21:06):

Right? And they are going to their personal browser and trying to download it. That's where the endpoint protection is going to kick in if the file is truly malicious. And so think about that story. This is a case where advisor could have been impacted with ransomware, but instead of being impacted with ransomware, the attack stopped. Yeah. And they can go about their day. To me that's success because you want security there in the background. You don't necessarily want to feel it all the time. And hey, if there are any concerns, they can always reach out to our advisor security team and ask them questions about what happened. And so that's an advisor who will be able to carry on their work, not suffer the consequences of weeks dealing with ransomware and working with loyals and forensics firm and all those things that they really don't want to do. And then ultimately just statistics from the last couple of days, we were able to stop over 90 attacks without advisors even knowing about them.

Taryn (22:08):

Beyond the protections that we have outlined and that we're putting in place. What are some practical steps that our listeners can take to better protect themselves and their clients? It

Renana (22:18):

All comes down to basic hygiene and it's the things that all of us know that we should do, but many don't do. When your operating system says, Hey, there's a new update, it is time for you to reboot your computer. What would many people do? Click next and hope that it won't pop up the next time news. It's actually for your benefit. So that's very important. If you have access to accounts containing sensitive data, set up the multifactor authentication that is required for your bank account, for your healthcare account and so forth. And many will actually enforce that encrypting files that are on your computer so that if someone accidentally gets access to your computer, they cannot actually see what's in those files and then going paperless because mail fraud is rising and we know that relying on mail physical mail is not something that most of us would recommend anymore. Where

Matt (23:26):

Do folks go to get more understanding of how to make sure that they're really in a good place? It's

Renana (23:31):

A combination between the branch office security policy that is available and every advisor attached to on an annual basis as well as the resource center where there's wealth of information about cybersecurity best practices and the do's and the don'ts. And then finally we have a mailbox so that advisors can reach out with questions and receive support on the spot. Should

Taryn (23:55):

Our advisors be talking to their clients so as well about the risks that they could face.

Renana (24:00):

Yes. And we actually have advisors who reach out to us on a regular basis and we arm them with presentations that they can then take to their end investors and continue to educate them.

Matt (24:11):

I wanna take a little bit of a step back in time to 2024 when you talked about how the bad guys were coming after the big dogs and then the big dogs got much better at what they did. And so the bad guys suddenly said, Hey, let's not go to Fort Knox to get the gold. Let's go to these little local community banks and ATMs and take little pieces at a time. 'cause it's easier to get in. Well there was a time where they were coming after us and May of 2024 was a really challenging time as we faced some cyber intruders who wanted to keep people out of our systems. And it kind of knocked us back a little bit and forced us to reimagine what the future of our infrastructure would be, what the future of our investment needed to be, to be one of those scaled players who was rock solid. Take us back. Now what we've had to do since then to make sure we are, 'cause we're talking a lot about our advisors being secure. It starts with us being secure first.

Renana (25:05):

Right? Ultimately, let's think about what happened in 2024 geopolitical conflict happening and there were many groups coming after us financial institutions with denial of service attacks with the ultimate goal of taking the sites down. Yeah. It's important to remember there are certain instances in which the denial of service attack is actually a cover for something else that is happening in the background.

Matt (25:35):

A denial server attack is effectively they send thousands if not millions of login requests to a site in an instant. And what it does is it creates so much of a crowd at the front door that no one can get in. And so what it feels like to the consumer is the site is down, but what's really happening is they have completely clogged the front door so no one can get in.

Renana (25:57):

And so I think it's a good example for many firms across financial services, seeing what happened, then beefing up their protections against it. And so fast forward to 2026, another geopolitical conflict. The number of institutions who are actually impacted by it is minimal because the protections have went up. And so we here at LPL invested in tools, we've invested in people, we've invested in processes that help us increase our resiliency against cyber attacks. And we're always looking for ways to improve.

Matt (26:36):

Rena, you come from working with Fortune 10 companies helping Fortune 500 companies solve for the riddles that cyber attacks present. But I would argue more so than ever, it is the scaled players who are going to survive this current threat landscape because other folks who don't have the ability or willingness to invest in that infrastructure are ultimately going to be a pretty vulnerable target for folks.

Renana (27:04):

Absolutely. And the small companies who are unable to invest in cybersecurity are going to find themselves in a very challenging spot, not only in being able to retain the clients, but also being able to grow with the changes in the threat landscape.

Matt (27:20):

Well, in the threat landscape, we talk about how it's evolving so quickly from the original large language models to some sort of generative AI to agen, which is now allowing folks to kind of attack and solve. And now we're moving into the era of mythos and right around the corner as quantum computing. Can you give a quick understanding or an explanation of quantum computing and and what it actually means and how it's different?

Renana (27:43):

Yeah, absolutely. So think about the enigma during World War II and how many years did it take to crack that code? Yeah. And so we're talking about a world in which if you needed to crack that code with quantum computing, instead of it taking years, it's taking hours or days. And so that's a pretty substantial amount of time that is saved requiring companies to be in a crypto agility world. What that basically means is that in encryption, algorithms need to be rotated at a moment's notice once you can no longer use that encryption. And so that's the next threat on the horizon that companies like us are preparing for.

Matt (28:27):

It is a cat and mouse game played at a level of complexity and sophistication that I don't think any of us ever dreamed of.

Renana (28:35):

The world has drastically changed. And what I love about cybersecurity is the fact that it always keeps me on my feet. There's always something new that I have to learn, that I have to innovate and requires me to stay curious about what should I do and what should we do as a company to protect against the ever changing threat landscape.

Taryn (28:55):

Wild. Talk about a career with purpose. Yes. Taking a step back on this full conversation, it feels like we're heading into a digital battle of good verse evil. Especially when you stack all the threats against the opportunities and at times it can feel a little dark and overwhelming. If you could point us toward the light in all of this, what would it look like?

Renana (29:17):

So here's what I would say. I think ultimately we as a company are investing a lot in security of our home office environment, of our advisors and and investors. And those commitment across the board, not just from the cybersecurity team, but everyone across the company is committed to security. Beyond that, once we have the uplift in place, we will be able to unlock the door to new opportunities and new tools that advisors would like to use, giving them even greater experience with the LPL ecosystem.

Matt (29:53):

You spent 20 years getting ready for this moment and that moment changes in front of you every single day. Cyber CSI seems like it's a real series. I can already see the zeros and ones inside of the chalk outline as we figure out what's been hacked next. And uh, look, I know this, I sleep well at night knowing that you're protecting our back office. And I think our advisors and institutions that we serve sleep a little bit better at night knowing you're there too.

Renana (30:19):

We are lucky to have you. Thank you. I'm so happy to be here.


Disclosures

Securities and advisory services offered through LPL Financial (LPL), a registered investment adviser and brokerdealer (member FINRA/SIPC). Insurance products are offered through LPL Financial or its licensed affiliates. To the extent you are receiving investment advice from a separately registered independent investment advisor that is not an LPL affiliate, please note LPL makes no representation with respect to such entity.

Not Insured by FDIC/NCUA or Any Other Government Agency

Not Bank/Credit Union Guaranteed

Not Bank/Credit Union Deposits or Obligations

May Lose Value

Tracking #1178528