The Office of the Comptroller of the Currency (OCC) fined Morgan Stanley Bank, N.A. and Morgan Stanley Private Bank, N.A. $60 million in October 2020 over weaknesses in how they managed the decommissioning of two U.S. Wealth Management data centers and other network equipment. The OCC’s findings focused on risk assessment, vendor and subcontractor oversight, and tracking customer data on retired devices—not on a confirmed public data breach from the two data centers.
What happened when Morgan Stanley decommissioned its data centers?
On October 8, 2020, the OCC announced a $60 million civil money penalty against Morgan Stanley Bank, N.A. and Morgan Stanley Private Bank, N.A. The action concerned the banks’ oversight of work to decommission two U.S. Wealth Management business data centers in 2016. The OCC also cited similar vendor-management control deficiencies related to decommissioning other network devices in 2019.
The penalty was imposed on the two banks, not on Morgan Stanley Smith Barney LLC, which was the subject of a separate Securities and Exchange Commission (SEC) action in 2022. The OCC release said the 2020 penalty would be paid to the U.S. Treasury.
What did the OCC say the banks did wrong?
The OCC found that the banks did not effectively assess or address the risks of retiring hardware. It also found inadequate assessment of subcontracting risks, including due diligence in selecting vendors and monitoring their performance. The banks lacked appropriate inventories of customer data stored on decommissioned devices.
#1 Best Overall
- Save valuable floor space: 6U wall mount server cabinet Dimensions: 13.78" H x21.65" W x17.72" D.Maximum mounting depth is 14.2"
- Keep critical network equipment secure: glass door and side panels are lockable to prevent unauthorized access. Front door can be installed on either side of the front of the cabinet to satisfy your door swing orientation preference
- Easy equipment configuration: Fully adjustable mounting rails and numbered U positions, with square holes for easy equipment mounting with top and bottom punch-out panels for easy cable access
- Durability: Made of high quality cold rolled steel holds up to 110lb (50kg) (Easy Assembly Required)
- PCI & HIPPA and EIA/ECA-310-E compliant
The consent order summarized one vendor-control failure this way: “The Bank failed to exercise adequate due diligence in selecting the third party vendor engaged by Morgan Stanley and failed to adequately monitor the vendor’s performance.” That language appears in Article II of the OCC consent order.
The OCC found noncompliance with 12 C.F.R. Part 30, Appendix B, the Interagency Guidelines Establishing Information Security Standards, and described the practices as unsafe or unsound. The banks neither admitted nor denied the Comptroller’s findings.
Rank #2
- Save valuable floor space: 12U wall mount server cabinet Dimensions: 24.25" H x21.65" W x17.72" D. MAXIMUM MOUNTING DEPTH is 14.2".
- Keep critical network equipment secure: glass door and side panels are lockable to prevent unauthorized access; Front door can be installed on either side of the front of the cabinet to satisfy your door swing orientation preference
- Easy equipment configuration: Fully adjustable mounting rails and numbered U positions, with square holes for easy equipment mounting with top and bottom punchout panels for easy cable access
- Durability: Made of high quality cold rolled steel holds up to 110lb (50kg) (Easy Assembly Required)
- PCI & HIPPA and EIA/ECA-310-E compliant
Did the OCC find that customer data was stolen?
The OCC consent order does not establish that customer data was stolen or misused in the 2016 data-center decommissioning. It says the banks notified potentially impacted customers about the 2016 incident at the OCC’s direction; the banks also voluntarily notified potentially impacted customers about the 2019 incident. The order records that the banks had taken initial corrective actions and committed to further necessary and appropriate remediation.
How is the separate 2022 SEC case different?
The SEC’s September 2022 action involved Morgan Stanley Smith Barney LLC and a different hardware-disposition matter. The SEC announced a $35 million settlement over failures to protect customer information and dispose of it properly. In describing a local-office and branch-server hardware refresh, the SEC said a reconciliation exercise identified 42 missing servers, all potentially containing unencrypted customer personally identifying information and consumer report information.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- Sturdy:4u server rack is construct from cold rolled steel, with a weight capacity of 110lbs(50kg); Electrostatic powder coat prevents rust and corrosion,quality finish
- Direct use:Open and use, not having to assemble it.Network rack can be placed flat or mounted on the wall,also can be installed vertically under the table
- Design Features:maximum mounting depth of 14 in,cables can be fixed on the side panel;Open frame server rack achieves effortless inspection, replacement and assemble
- Installation:wall mount network rack is easy to install,with instructions or videos for reference;Equipped with multiple accessories, suitable for different needs
- Application:EIA/ECA-310-E Compliant;wall mounted 4u rack fits all 19" racks and cabinets to hold various IT, network, and AV equipment;wall mount rack available in 4U, 6U, and 8U to choose
Those figures and findings belong to the SEC’s later case, not the OCC’s 2020 order about two Wealth Management data centers. The SEC press release is available at SEC.gov.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What can organizations learn from the case?
The enforcement action illustrates why retiring equipment is an information-security governance task, not just a facilities or logistics project. An organization evaluating a hardware-retirement provider can ask whether its process includes:
- Documented data-sanitization or destruction procedures, with evidence that each item was handled as specified.
- Disclosure of subcontractors and clear responsibility for their selection and oversight.
- Item-level inventory and reconciliation so the organization can identify what equipment and data were in scope.
- Chain-of-custody records and auditable completion evidence.
- Monitoring and escalation procedures for missed milestones, inventory discrepancies, or other exceptions.
These are practical questions suggested by the control failures cited in the order; they are not a vendor checklist prescribed by the OCC in this case. The OCC announcement and consent order AA-EC-20-66 provide the official accounts of the 2020 action.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →

