Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeBlogCybersecurity

SEC Reg S-P Cybersecurity Rules for RIAs in 2026

Empty modern investment advisory boardroom at sunset with a closed laptop and a brass padlock resting on a stack of compliance documents, city skyline beyond the windows

The SEC's amended Regulation S-P now requires registered investment advisers to build a written incident response program, notify affected clients within 30 days of a breach, and hold their vendors to a hard reporting deadline. Smaller RIAs — those with under $1.5 billion in regulatory assets under management — have until June 3, 2026 to comply. If your firm has been treating cybersecurity as an IT afterthought, that clock is short.

What changed under Regulation S-P?

Regulation S-P has governed how financial firms handle customer data since 2000. The 2024 amendments modernized it for a world of cloud platforms and third-party breaches. The headline addition is a mandatory incident response program: written procedures to detect, respond to, and recover from unauthorized access to customer information. The rule also sets a firm customer-notification deadline and requires formal oversight of the service providers that touch client data.

The compliance dates split by firm size. Larger entities — advisers with $1.5 billion or more in AUM — had to comply by December 3, 2025. Smaller advisers get until June 3, 2026. Most independent RIAs fall into that second group.

Who counts as a "smaller entity"?

A smaller entity is a registered investment adviser with less than $1.5 billion in regulatory assets under management. If that describes your firm, June 3, 2026 is your deadline — and "smaller" does not mean "exempt." A two-person advisory that runs its practice through a handful of SaaS platforms carries the same core obligations as a national firm, scaled to its own size and risk.

What does the incident response program have to do?

Your written program has to cover four things: assess the nature and scope of an incident, contain and control it, notify affected clients, and keep records of what happened and what you decided. This isn't a document you write once and file away. Examiners will expect evidence that it matches how your firm actually operates — your systems, your custodian, your vendors.

When do we have to tell clients?

Under the amended rule, a covered firm must notify affected individuals as soon as reasonably practicable, and no later than 30 days after becoming aware that sensitive customer information was, or was likely, accessed without authorization. The notice has to explain the incident, the data involved, and what clients can do to protect themselves. Thirty days moves fast when you're also investigating and containing an attack, which is the whole argument for planning the response before you need it.

What about our vendors?

This is the part that catches firms off guard. The amendments require written policies for service provider oversight: due diligence when you select a vendor, ongoing monitoring, and contract terms requiring the vendor to notify you within 72 hours of discovering a breach. Your custodian, your CRM, your portfolio management platform, your email host — each one holds client data, and a breach at any of them can start your notification clock. Many existing vendor agreements don't include a 72-hour clause yet, so contracts may need a second look.

How does an RIA actually get ready?

Start with a data map: where does client information live, and which providers touch it? From there the work is concrete — draft the incident response plan, update vendor contracts, tighten access controls and multi-factor authentication, and run a tabletop exercise so the plan isn't theoretical. A firm without in-house security staff usually leans on a virtual CISO to own the program and a managed security partner to run detection and response. The same controls also make your next cyber insurance renewal easier, since carriers ask for most of the same things.

Frequently asked questions

Does Reg S-P apply to state-registered advisers?

The amendments apply to SEC-registered investment advisers, broker-dealers, and investment companies. State-registered advisers fall under their state's rules, but those states often mirror federal expectations, and many custodians impose similar requirements by contract. Treating Reg S-P as a baseline is the safer posture.

We already have a WISP. Is that enough?

A written information security program is a strong start, but Reg S-P specifically requires incident response procedures, the 30-day notification process, and documented vendor oversight. Most existing WISPs need to be extended to cover those elements explicitly rather than by implication.

What are the penalties for missing the deadline?

Reg S-P is enforced through SEC examinations and enforcement actions. Deficiencies can lead to findings, remediation orders, fines, and reputational damage. In practice, an unprepared incident response is also far more expensive and more damaging to client trust than the compliance work would have been.

How long does it take to get compliant?

For a small firm with clean systems, a focused effort takes a few weeks. Firms with scattered data, aging infrastructure, or thin vendor contracts should budget longer. The closer you get to June 2026, the more competition there is for security help, so earlier is cheaper.

NetSys has supported financial services firms across the New York metro and beyond since 1998. For a clear read on where your RIA stands against Regulation S-P, book a complimentary risk assessment and we'll map the gaps before the deadline does.

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.