WASHINGTON, D.C. — In a regulatory enforcement action underscoring the federal government’s hardline stance on financial market cybersecurity and operational resilience, the Securities and Exchange Commission (SEC) announced a formal censure and a $575,000 civil monetary penalty against New York-based broker-dealer OTC Link LLC.

The penalty concludes a protracted investigation centered on systemic, long-term failures to comply with Regulation Systems Compliance and Integrity (Regulation SCI). According to the SEC’s settled administrative order, OTC Link LLC neglected foundational mandates concerning its alternative trading system (ATS), leaving crucial technological infrastructure vulnerable for nearly nine years.

Without admitting or denying the SEC’s findings, OTC Link LLC has agreed to the censure, a cease-and-desist order, and the financial penalty, signaling a close to this chapter of regulatory scrutiny even as broader questions remain regarding the compliance habits of major over-the-counter (OTC) market operators.


Main Facts of the Enforcement Action

The core of the SEC’s case against OTC Link LLC revolves around the operation of OTC Link ATS, a prominent electronic alternative trading system that facilitates the trading of over-the-counter securities. Because these systems form the technological backbone of substantial portions of the U.S. financial markets, they are subject to stringent oversight designed to reduce the risk of technological glitches, security breaches, and market disruptions.

Specifically, the SEC found that between August 2016 and March 2025, OTC Link LLC repeatedly failed to establish, maintain, and enforce written policies and procedures mandated by Regulation SCI. The violations covered several critical operational pillars:

  • System Security: Inadequate protocols to defend the infrastructure against unauthorized access or malicious cyber threats.
  • Access Control: Flawed mechanisms governing who and what systems could interact with the core trading architecture.
  • Application Vulnerability Management: A chronic inability to properly identify, test, and remediate software and system vulnerabilities.

Regulation SCI was adopted by the SEC to strengthen the technological infrastructure of the U.S. securities markets. It requires key market participants—known as "SCI entities"—to ensure that their systems have adequate capacity, integrity, resiliency, availability, and security. By failing to implement the required minimum policies, failing to periodically review their effectiveness, and failing to take corrective action, OTC Link LLC violated Rules 1001(a)(1), 1001(a)(2), and 1001(a)(3) of Regulation SCI.


Chronology of Non-Compliance

The timeline detailed in the SEC’s order reveals a troubling pattern of repeated warnings followed by inaction. The deficiencies were not hidden; rather, they were repeatedly identified by federal regulators who gave the firm ample opportunity to correct course.

  • August 2016: The statutory timeline of the violations begins. From this point forward, the SEC asserts that OTC Link LLC’s policies regarding its ATS fell short of Regulation SCI mandates. Over the next several years, the alternative trading system continued to operate under sub-par technological governance frameworks.
  • Interim Examination Cycles: During the more than eight-year window, staff members from the SEC’s Division of Examinations conducted routine and targeted compliance examinations of OTC Link ATS. During multiple separate exam cycles throughout this period, examiners flagged specific required policies and procedures that the firm simply had not established.
  • The "Draft" Status Loophole: In many instances, the SEC discovered that required compliance policies existed only as draft documents. Rather than finalizing, operationalizing, and enforcing these policies, OTC Link LLC left them in preliminary states, effectively operating without the formalized safeguards required by federal law.
  • March 2025: The window of active violations formally closes following intensified regulatory pressure, paving the way for the enforcement division to step in and finalize the settled order.
  • September 22, 2026: The SEC officially publicizes the settled administrative order, imposing the censure, cease-and-desist mandates, and the $575,000 penalty.

Supporting Data and Regulatory Framework

To understand the gravity of the SEC’s action against OTC Link LLC, one must examine the regulatory mechanics of Regulation SCI and the financial realities of regulatory penalties in the fintech and broker-dealer sectors.

The Anatomy of Regulation SCI

Promulgated in response to a series of high-profile technological glitches and market outages that shook investor confidence in the early 2010s, Regulation SCI applies to self-regulatory organizations (including stock and options exchanges), certain alternative trading systems (such as OTC Link ATS), registered clearing agencies, and major market data processors.

The rule forces these entities to:

  1. Maintain robust frameworks: Systems must be designed to withstand high volumes and cyber threats.
  2. Conduct mandatory testing: Entities must regularly test their disaster recovery and business continuity plans.
  3. Notify the SEC immediately: Any "SCI events"—ranging from systems intrusions to significant capacity outages—must be reported to the Commission within strict timeframes.

By failing to draft and enforce the baseline policies required under Rule 1001, OTC Link LLC short-circuited the preventative intent of Regulation SCI, leaving the ATS exposed to risks that the regulation was specifically designed to mitigate.

Financial and Operational Breakdown

  • Civil Penalty: $575,000. While modest compared to multi-million-dollar penalties levied against Wall Street giants for massive market manipulation, the fine is significant for administrative non-compliance regarding internal policies, reflecting the duration of the neglect rather than an actual catastrophic market outage.
  • The Duration: The violations spanned an extraordinary 103 months (nearly 8.5 years), highlighting a systemic organizational inertia that persisted across multiple management and compliance cycles within the firm.
  • Resolution Type: A settled administrative proceeding, meaning OTC Link LLC avoided a protracted, public courtroom battle by agreeing to the financial terms and administrative restrictions.

Official Responses and Regulatory Warnings

The enforcement action drew sharp commentary from the leadership of the SEC’s Division of Enforcement, particularly highlighting the agency’s frustration with firms that treat regulatory examinations as suggestions rather than mandates.

Laura D’Allaird, Chief of the Division of Enforcement’s Cyber and Emerging Technologies Unit, did not mince words when addressing the repeat nature of OTC Link LLC’s failures.

"OTC Link’s continual failure to remediate deficiencies even after they were repeatedly flagged by Division of Examinations staff reflects a disregard for their findings and the overall examinations process and justifies a meaningful penalty," D’Allaird stated in the SEC’s official press release.

D’Allaird broadened the scope of her commentary to send a clear message to the wider financial technology and alternative trading community:

"All SCI entities are expected to take their regulatory responsibilities seriously and promptly fix issues when they’re identified."

Market observers noted that the inclusion of the Cyber and Emerging Technologies Unit in this enforcement action signals that the SEC increasingly views administrative compliance failures surrounding cybersecurity and system access not as mere paperwork oversights, but as active threats to market integrity. When a trading platform allows access controls and vulnerability management procedures to languish in "draft" status for nearly a decade, it invites systemic risk into the over-the-counter marketplace.


Broader Implications for the Financial Industry

The penalty against OTC Link LLC carries several vital takeaways for alternative trading systems, broker-dealers, and financial institutions operating complex technological infrastructure under SEC oversight.

1. The Perils of Ignoring Examination Findings

One of the most damning aspects of the SEC’s order is that the deficiencies were caught early and often by the Division of Examinations, yet remained unaddressed. For compliance officers across the financial sector, this case serves as a cautionary tale. Failing to remediate findings from routine SEC exams creates a paper trail of willful neglect. When enforcement divisions review a case file showing that examiners pointed out a missing policy year after year only for it to remain unaddressed, regulatory leniency evaporates.

2. Heightened Scrutiny on ATS and Over-the-Counter Markets

While major national securities exchanges often capture the lion’s share of public attention, alternative trading systems handle massive volumes of unlisted and over-the-counter securities. These markets are essential for smaller companies, foreign equities, and early-stage enterprises. Ensuring that the technological infrastructure supporting OTC trading is robust, secure, and resilient is vital for protecting retail and institutional investors alike.

3. Cybersecurity and Operational Resilience as Frontline Priorities

The message from Washington is unequivocal: cybersecurity governance, application vulnerability testing, and access controls are core compliance obligations. Firms cannot rely on patchwork IT systems or outdated policy manuals. As financial markets become increasingly digitized and interconnected, the SEC’s Cyber and Emerging Technologies Unit will continue to target entities that fail to maintain the rigorous standards demanded by Regulation SCI.

Conclusion

As the financial markets continue to evolve in complexity, the regulatory tolerance for administrative laxity is shrinking. For OTC Link LLC, the $575,000 penalty and formal censure close a damaging chapter of operational oversight. For the broader financial industry, the case stands as an unmistakable reminder that regulatory warnings must be met with immediate, decisive, and permanent corrective action.