
Short answer: the SEC's amended Regulation S-P now applies to smaller covered firms, and it requires more than a written policy: an incident response program, customer notification within 30 days of a qualifying breach, and real oversight of service providers who touch customer information. If your firm hasn't operationalized those, that's the work — and it's very doable at RIA scale.
What the Reg S-P amendments actually require
- An incident response program — written, specific to your firm, covering how you detect, assess, contain, and recover from unauthorized access to customer information.
- Customer notification — within 30 days when sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization.
- Service provider oversight — contracts and monitoring that ensure vendors handling customer data protect it and tell you promptly when something goes wrong.
- Safeguards and disposal — the scope of protected information is broader, including data you receive about others' customers.
What examiners ask for
Documentation and evidence: the written program, proof it's tested, vendor lists with due-diligence records, and logs showing controls operate. A policy written the week before an exam reads exactly like what it is.
The practical build-out for a small RIA
The security substance overlaps heavily with plain good practice: multi-factor authentication everywhere, endpoint detection and response, encrypted and tested backups, email security tuned for wire-fraud patterns, and monitoring that produces the logs your program promises. The compliance layer — policies, vendor oversight, notification procedures, board-level reporting — is where firms without a security executive stall. That's the exact gap a vCISO engagement fills: senior security leadership, sized monthly, without the executive salary.
Where to start this quarter
- Inventory where customer information lives — systems, vendors, spreadsheets.
- Stand up the incident response program and rehearse it once.
- Paper the vendor oversight: who touches data, under what terms, notifying whom.
- Close the technical basics that make incidents unlikely in the first place.
We work with RIAs, CPAs, and funds confidentially — no client names, by design. See IT & security for financial firms or book a 15-minute call to scope your gap list.
Sources and further reading
- SEC — Regulation S-P amendments (2024) — the Commission's adopting release, including the 30-day customer notification requirement.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



