Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeBlogCompliance

SEC Reg S-P Deadline Passed: What Small RIAs Do Now

Financial advisor reviewing compliance requirements

Short answer: the SEC's amended Regulation S-P now applies to smaller covered firms, and it requires more than a written policy: an incident response program, customer notification within 30 days of a qualifying breach, and real oversight of service providers who touch customer information. If your firm hasn't operationalized those, that's the work — and it's very doable at RIA scale.

What the Reg S-P amendments actually require

  • An incident response program — written, specific to your firm, covering how you detect, assess, contain, and recover from unauthorized access to customer information.
  • Customer notification — within 30 days when sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization.
  • Service provider oversight — contracts and monitoring that ensure vendors handling customer data protect it and tell you promptly when something goes wrong.
  • Safeguards and disposal — the scope of protected information is broader, including data you receive about others' customers.

What examiners ask for

Documentation and evidence: the written program, proof it's tested, vendor lists with due-diligence records, and logs showing controls operate. A policy written the week before an exam reads exactly like what it is.

The practical build-out for a small RIA

The security substance overlaps heavily with plain good practice: multi-factor authentication everywhere, endpoint detection and response, encrypted and tested backups, email security tuned for wire-fraud patterns, and monitoring that produces the logs your program promises. The compliance layer — policies, vendor oversight, notification procedures, board-level reporting — is where firms without a security executive stall. That's the exact gap a vCISO engagement fills: senior security leadership, sized monthly, without the executive salary.

Where to start this quarter

  1. Inventory where customer information lives — systems, vendors, spreadsheets.
  2. Stand up the incident response program and rehearse it once.
  3. Paper the vendor oversight: who touches data, under what terms, notifying whom.
  4. Close the technical basics that make incidents unlikely in the first place.

We work with RIAs, CPAs, and funds confidentially — no client names, by design. See IT & security for financial firms or book a 15-minute call to scope your gap list.

Sources and further reading

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.