The message is increasingly common: “Information security is a critical consideration.” But this time the cyber-security warning wasn’t handed down by a regulator – it was the Securities and Exchange Commission being scolded for its own security gaps and lapses.

Without proper safeguards, including those required by the Federal Information Security Management Act and National Institute of Standards and Technology, the SEC’s systems are vulnerable to hackers looking to those with malicious intent who want to obtain or manipulate sensitive information, commit fraud, disrupt operations, or launch attacks against others, a report issued by the Government Accountability Office says.