The SEC Cybersecurity Rule for RIAs: Reg S-P Guide
- Harrison Baron

- Aug 9
- 10 min read
Updated: Aug 11

If you run an RIA, you have probably heard two different things called "the SEC cybersecurity rule." One was proposed, drew heavy comment, and never took effect. The other is amended Regulation S-P, and it is the rule your firm actually has to follow today.
That mix-up matters. Firms that spent time preparing for the withdrawn proposal may have the wrong mental model for what examiners now check. The SEC cybersecurity rule for RIAs, in its current and enforceable form, lives in amended Regulation S-P, and it requires a written incident response program, 30-day breach notification, and documented oversight of the vendors that touch client data.
This guide walks through what applies, what changed, and how to turn the rule into working controls across the systems your firm already uses — custodian portals, Microsoft 365, your CRM, and cloud storage.
Key Takeaways:
Amended Regulation S-P, not the withdrawn cybersecurity proposal, sets the current SEC compliance obligations for RIAs.
Compliance depends on documented evidence — access reviews, incident decisions, vendor oversight, and tested recovery — not policy language alone.
Smaller firms need a right-sized program built around real risk, not a copy of large-firm controls.
The SEC Cybersecurity Rule for RIAs: Which Requirements Apply
Two SEC efforts get referenced when people talk about cybersecurity rules for investment advisers, and only one of them governs your firm right now. Amended Regulation S-P is the operative rule, and it works alongside your existing compliance program under Rule 206(4)-7 rather than replacing it.
The Withdrawn SEC Cybersecurity Proposal Versus Current Obligations
In 2022, the SEC proposed Rule 206(4)-9, a standalone cybersecurity risk management rule for RIAs. It would have required specific written policies, board-level reporting for some firms, and direct incident reporting to the SEC. The SEC withdrew that proposal, so it never became a binding requirement.
That withdrawal does not mean cybersecurity expectations went away. Amended Regulation S-P, finalized in 2024, stepped into that space with its own set of binding obligations, according to Wipfli's analysis of the new rules.
How Amended Regulation S-P Fits Within RIA Compliance
Regulation S-P started as a privacy rule under the Gramm-Leach-Bliley Act. The 2024 amendments turned it into a functional cybersecurity mandate, requiring written policies to protect customer information from unauthorized access, as described in CyberSecureRIA's overview of the update. It now sits at the center of ria compliance work for data protection.
The Relationship to Rule 206(4)-7 and Existing Policies

Rule 206(4)-7 already required RIAs to adopt and review compliance policies annually.
Reg S-P obligations get folded into that existing structure rather than standing apart from it. Your annual compliance review should now test whether cybersecurity controls, not just disclosure and trading policies, are actually working.
What Amended Regulation S-P Requires
The amended rule centers on four practical obligations: protecting customer information, responding to incidents on a defined timeline, overseeing service providers, and keeping records that prove the program works. Each one translates into specific tasks for the systems your team uses daily.
Protecting Customer Information With Reasonable Safeguards
Customer information under the amended rule covers more than account numbers and balances. It now includes any nonpublic personal information tied to a client, expanding what falls inside your safeguards program according to Insura's breakdown of the rule change. That means data sitting in your CRM, in email threads, and in shared drives all counts.
Establishing a Written Incident Response Program
The rule requires a documented plan for detecting, responding to, and recovering from cybersecurity incidents. A short memo referencing "best efforts" will not hold up in an exam. Examiners want named roles, defined steps, and proof the plan gets used.
Overseeing Service Providers That Handle Client Data
Your custodian, portfolio management platform, and cloud storage vendor all touch customer information. The rule makes you responsible for confirming those vendors protect that data appropriately, not just assuming they do.
Maintaining Required Compliance Records

Documentation needs to show a five-year retention pattern for incident response records, risk assessments, and vendor oversight decisions. A firm like Secure Wealth IT, which builds evidence collection into ongoing monitoring for financial firms, reflects the kind of operational discipline this recordkeeping expectation assumes.
Compliance Dates and Firm Scope
Compliance timing under amended Regulation S-P depended on firm size, measured by assets under management, with larger firms facing an earlier deadline than smaller ones. Every SEC-registered adviser is now inside the compliance window regardless of size.
How AUM Affected the Implementation Timeline
Larger RIAs and other covered institutions faced a compliance date of December 3, 2024, while smaller entities had until June 3, 2025, according to FINRA's advisory on the compliance date. Some sources point to a later smaller-firm deadline extending into 2026, so confirm your firm's specific applicable date with counsel.
What the Current Requirements Mean for Smaller Advisers
Smaller RIAs sometimes assume reduced AUM means reduced obligation. The rule does not scale down the core requirements — it scales the compliance date. A solo RIA still needs a written incident response plan, vendor oversight, and breach notification procedures, sized to its own operations rather than skipped entirely.
When State-Registered Firms Should Review Their Obligations

State-registered advisers fall outside SEC jurisdiction on this rule, but many states model their own privacy and cybersecurity expectations on SEC frameworks. If your firm is state-registered, or expects to cross into SEC registration soon, reviewing these requirements now avoids a scramble later.
Building a Risk-Based Cybersecurity Program
A defensible program starts with knowing what data you hold, where it lives, and what could go wrong before writing a single policy. That sequence — assessment, mapping, remediation — keeps the program grounded in your firm's actual risk instead of a generic template.
Performing a Documented Cybersecurity Risk Assessment
A cybersecurity risk assessment identifies where customer information is stored, who can access it, and what threats are most likely to affect your firm. This should happen at least annually and get written down, not just discussed in a meeting.
Mapping Assets, Data Flows, and Critical Systems
Build a simple asset inventory: laptops, phones, servers, cloud accounts, and the software that touches client data. Trace how information moves between your CRM, custodian portal, and email. Gaps in that map are usually where incidents start.
Turning a Gap Assessment Into a Remediation Roadmap

A gap assessment compares your current controls against what the rule and your own risk assessment require. The output should be a prioritized list — not a wall of findings — with owners and deadlines attached to each item. That roadmap becomes your cybersecurity policy's action plan and the evidence trail examiners look for.
Safeguarding Accounts, Devices, and Data
Reg S-P's "reasonable safeguards" language translates into specific, testable controls across accounts, devices, and stored data. These controls need to work the same way whether staff sit in the office or log in remotely from a laptop or phone.
Applying Least-Privilege Access Controls
Access controls should limit each person to the systems and data their role actually requires. A junior operations associate rarely needs the same custodian portal permissions as a principal. Review access lists quarterly and remove former employees immediately.
Enforcing Multi-Factor Authentication Across Key Systems
Multi-factor authentication (MFA) belongs on email, custodian logins, your CRM, and any cloud storage holding client files. Pair it with a password manager so staff are not reusing weak passwords across systems, and require a VPN for remote access to internal resources.
Securing Endpoints and Mobile Devices
Endpoint detection and response (EDR) tools monitor laptops and desktops for suspicious activity in real time. Mobile device management (MDM) extends that oversight to phones and tablets, letting you enforce passcodes and remote wipe capability if a device is lost.
Encrypting Client Data in Transit and at Rest
Full-disk encryption — BitLocker on Windows, FileVault on Mac — protects data if a device is stolen. Encryption should also cover data moving between systems and data sitting in cloud storage, addressing controls outlined in RegShield's guide to Reg S-P cybersecurity controls.
Managing Patches, Vulnerabilities, and Network Defenses

Patch management closes known software vulnerabilities before attackers exploit them. Firewalls filter traffic at the network edge. Together, these reduce the paths an outsider could use to gain unauthorized access to client systems.
Creating an Incident Response and Notification Process
An incident response plan only works if roles are assigned before an incident happens, not during one. The plan needs to define detection through recovery, set a clear notification clock, and get tested regularly so the written procedure matches what your team would actually do.
Defining Detection, Triage, Containment, and Recovery Roles
Name who monitors for alerts, who decides severity, who isolates affected systems, and who leads recovery. Small firms can assign these roles to existing staff and outside IT support — the point is clarity, not headcount.
Assessing Whether Unauthorized Access Triggered a Notifiable Incident
Not every alert is a reportable data breach. Your incident response procedures should include a documented process for evaluating whether unauthorized access actually exposed customer information, and at what scope.
Meeting the 30-Day Breach Notification Requirement
Once a firm determines that sensitive customer information was accessed without authorization, amended Regulation S-P generally requires notifying affected individuals within 30 days, a timeline emphasized across sources including Atlant Security's exam prep guide. Missing that window has drawn real enforcement attention — one case involving a 45-day delay after a ransomware event resulted in a substantial SEC fine, according to Insura's review of enforcement scenarios.
Preserving Evidence and Documenting Incident Decisions
Every incident, notifiable or not, should leave a paper trail: what was found, who decided what, and why. Evidence preservation protects your firm during a later SEC examination and supports any legal analysis counsel needs to perform.
Testing the Plan Through a Tabletop Exercise

A tabletop exercise walks your team through a simulated ransomware or phishing scenario without real consequences. Run one at least annually — it usually surfaces gaps a written plan alone would never reveal.
Managing Custodian and Vendor Risk
Vendor oversight has become one of the more heavily scrutinized parts of RIA compliance, since so much client data passes through outside systems. Custodians like Fidelity and Pershing, along with portfolio and CRM platforms, all need documented review rather than a one-time signup.
Maintaining a Complete Vendor Inventory
List every third-party vendor that stores, processes, or can access customer information.
This includes obvious ones like custodians and less obvious ones like email archiving tools or a marketing platform synced to your CRM.
Conducting Due Diligence for High-Risk Providers
Vendors holding large volumes of client data warrant deeper review — security certifications, breach history, and how they handle their own subcontractors.
Venminder's guidance on third-party risk management points to this tiered approach as a practical way to focus limited compliance resources.
Addressing Security and Notification Terms in Vendor Contracts
Vendor contracts should specify how the provider protects customer information and how quickly they must notify you of a breach on their end. Silence in a contract on this point creates real risk.
Reviewing Providers on an Ongoing Basis

Annual vendor reviews confirm nothing changed that increases risk — new subcontractors, expired certifications, or new data access. Cloud storage vendors in particular deserve a fresh look each year given how often their features and access settings shift.
Training Staff to Reduce Human Risk
Most incidents at RIAs start with a person, not a technical failure. Training staff to recognize phishing and social engineering attempts closes the gap that firewalls and encryption cannot cover on their own.
Making Security Awareness Training Part of Daily Operations
Security awareness training works better as short, frequent sessions than a single annual meeting. Cover real examples relevant to advisory firms — fake wire instructions, spoofed custodian emails, urgent requests from "clients."
Using Phishing Simulations to Reinforce Reporting
Phishing simulations test whether staff recognize and report suspicious emails rather than clicking through. Track results over time and use them to target follow-up training, not to single out employees who fall for a test.
Preventing Social Engineering and Wire Fraud
Wire fraud attempts often rely on urgency and impersonation rather than technical hacking. A simple callback verification rule for any wire request — no exceptions, even for "the client's" urgent email — stops most of these attempts before money moves.
Preparing for an SEC Examination
SEC examinations increasingly test whether your cybersecurity program works in practice, not just whether policies exist on paper. Examiners want to see evidence that matches your written procedures, organized in a way that does not require last-minute scrambling.
Maintaining Evidence That Policies Match Actual Practice
If your policy says access is reviewed quarterly, examiners want to see the actual review logs. A gap between stated policy and documented practice is one of the most common deficiency findings in cybersecurity exams.
Organizing Records for SEC Examiners
Keep incident response records, risk assessments, vendor reviews, and training logs organized and easy to retrieve. MTradecraft's exam readiness guide maps these expectations directly to Rule 206(4)-7, Regulation S-P, and Rule 204-2, which is a useful way to think about how the pieces connect.
Using Reviews and Testing to Address Deficiency Findings
Treat your annual compliance review and any tabletop exercise results as a chance to catch problems before an examiner does. Firms that document patch management cadence and vendor oversight consistently tend to face fewer follow-up questions during cybersecurity compliance reviews.
A Practical 90-Day Compliance Action Plan
A 90-day plan turns Reg S-P obligations into sequenced work rather than an overwhelming list. Start with the risks most likely to cause harm, assign clear ownership, and bring in the right people — technology, compliance, legal counsel, and cyber insurance — before problems surface.
Prioritizing Immediate Exposure Reduction
In the first 30 days, focus on MFA gaps, unpatched systems, and access permissions for former employees. These fixes are fast, low-cost, and address the most common entry points for incidents.
Assigning Ownership for Policies, Controls, and Evidence
By day 60, each policy — incident response plan, vendor management, business continuity — needs a named owner responsible for keeping it current and gathering supporting evidence. Ownership without a name attached tends to drift.
Aligning Technology, Compliance, Counsel, and Cyber Insurance
By day 90, confirm your technology partner, compliance team, outside counsel, and cyber insurance carrier are working from the same risk assessment and incident response plan. Coordination at this stage — not after an incident — is what keeps a bad day from becoming a bad year for the firm.
Next Steps for Your RIA or Broker-Dealer Firm
Secure Wealth IT helps Registered Investment Advisors, broker-dealers, and financial advisors stay secure, compliant, and audit-ready. Explore these free tools and resources:
Free Financial Calculators: calculator.securewealthit.com
Compliance Self-Assessment Tool: regulations.securewealthit.com
Resource Library: Browse free RIA and broker-dealer guides
Watch on YouTube: Secure Wealth IT YouTube channel.
Talk to a Specialist: Schedule a free consultation.
For more information about this topic, visit us at https://www.securewealthit.com




Comments