SEC Cyber Disclosure Rules: The Compliance Gap Most RIAs Miss
Executive Summary
The SEC’s amended Regulation S-P took full effect for smaller registered investment advisers in June 2026, introducing enforceable requirements for written incident response programs, 30-day breach notifications to clients, and formal third-party vendor oversight. Most RIA firms do not have the internal resources or infrastructure to own these obligations. That gap is now a compliance liability.
Why It Matters
Cybersecurity compliance has become a non-negotiable for registered investment advisers. The SEC’s 2024 amendments to Regulation S-P moved beyond general guidance into specific, enforceable obligations: written incident response policies, documented customer notification procedures, and formal oversight of every third-party vendor that touches client data.
Larger firms with assets under management above $1.5 billion faced a December 2025 compliance deadline. Firms below that threshold had until June 3, 2026. That deadline has passed.
For many firms, the requirements arrived without a clear owner inside the organization. An IT support team can patch systems and manage endpoints. An outside IT provider can monitor the network and respond to threats. But neither typically drafts compliance policy, manages a formal incident response program, or sits across the table from an SEC examiner explaining how the firm detects, responds to, and recovers from a data security incident.
That responsibility requires expertise, bandwidth, and a structured process. For most RIAs, none of those three exist in adequate supply.
How It Impacts Businesses
The practical consequences of the updated Regulation S-P requirements show up in four places.
The first is incident response planning. The SEC now requires covered firms to have a written program for detecting, responding to, and recovering from unauthorized access to client data. This is not a checkbox. Examiners want to see policy documents, testing records, and evidence that the firm has rehearsed the response. If a breach occurs and no written program exists, the firm faces exposure on two fronts: the incident itself and the compliance failure.
The second is the 30-day client notification clock. When a breach involving sensitive customer information is confirmed or reasonably suspected, firms have 30 days to notify affected individuals. That window requires knowing what data was compromised, identifying the affected clients, preparing the notice, and executing the send, all under pressure, often while simultaneously managing technical remediation. Without a process defined in advance, 30 days is not enough time to do this well.
The third is vendor oversight. Third-party providers that access or store client data must now report security breaches to the RIA within 72 hours. But the obligation does not stop at receiving that notice. RIAs must have written policies for reviewing vendor security practices, ongoing monitoring, and documentation of due diligence. A list of vendors with an assumption that they are secure is not a policy.
The fourth is recordkeeping. Every element of the compliance program, policies, risk assessments, incident records, vendor reviews, must be documented and retained. SEC examiners do not grade on the honor system.
For more on how financial firms are being targeted today, read: Credential Attacks on Financial Firms: What to Know.
What Steps Companies Can Take
The first step is an honest assessment of who currently owns cybersecurity compliance at the firm. Not who handles IT support, but who owns the written policies, the incident response program, and the vendor oversight documentation the SEC expects to see. If that question does not have a clear answer, that is the gap.
The second step is building a written incident response program. This does not need to be hundreds of pages, but it must address detection, containment, notification timelines, and recovery steps specific to the firm’s environment. It should be tested at least once through a tabletop exercise and updated when systems or vendors change.
The third step is a vendor inventory and risk review. Every third-party service touching client data needs to be documented. Review contract terms, confirm they include a breach notification obligation in writing with a 72-hour window to the RIA, and retain records of the review.
The fourth step is establishing a recordkeeping process. Assign a clear owner for maintaining compliance documentation. If an SEC examination begins, the request for records arrives quickly. Firms that have to reconstruct documentation under deadline are in a meaningfully worse position than firms with a standing file.
How an MSP Helps
Managing these requirements internally works for firms large enough to have dedicated compliance and IT staff. For firms where one or two people handle operations, finance, and compliance alongside client responsibilities, carrying the SEC cybersecurity mandate alone is not realistic.
This is where a managed security partner changes the equation.
The requirements the SEC now imposes are not purely technical. They are operational and documentary. A written incident response program needs to be drafted, tested, and kept current. Annual risk assessments need to be conducted and documented. Vendor contracts need to be reviewed for specific breach notification language. Client notification templates need to exist before a breach occurs. Records of all of it need to be retained and accessible when an examiner asks.
Each of those functions requires more than standard IT monitoring and support. An IT team manages the technical infrastructure. A managed security partner handles the compliance and documentation layer that sits above it: building the written incident response program, conducting security risk assessments, reviewing vendor agreements for breach notification requirements, preparing the 30-day client notification process before it is needed, and maintaining the records SEC examiners look for.
For firms approaching an SEC examination without these elements in place, a managed security engagement provides a faster path to documented compliance than building the capability internally from scratch.
Best Practices and Key Takeaways
Firms that handle SEC cybersecurity compliance well tend to share a few habits. They assign a named owner to every compliance obligation. They maintain a central documentation file that includes the incident response program, vendor review records, risk assessment results, and records of any prior incidents with documented timelines. They test the incident response process at least annually, treating it like a fire drill rather than a theoretical document. They review vendor contracts specifically for 72-hour breach notification language and follow up when that language is absent. And they draft the 30-day client notification template now, before a breach occurs, rather than writing it under pressure afterward.
No firm eliminates cybersecurity risk entirely. The standard the SEC measures is not perfection. It is documented, proportional, and actively maintained risk management. Firms that can demonstrate a serious, ongoing effort to meet these requirements are in a fundamentally different position than those that cannot.
FAQ
What does Regulation S-P require for RIAs as of 2026?
Regulation S-P, as amended in May 2024, requires RIAs to maintain a written incident response program, notify affected clients within 30 days of a confirmed or reasonably suspected breach involving sensitive customer information, oversee third-party vendors through formal policies and contracts that include 72-hour breach notification back to the RIA, and retain documentation of all compliance activities. Smaller firms with AUM below $1.5 billion had until June 3, 2026 to comply.
What should RIAs look for in a managed security partner?
Firms subject to SEC cybersecurity requirements need a partner who handles more than network monitoring. Look for a provider that can help build and maintain a written incident response program, conduct security risk assessments, review vendor contracts for breach notification requirements, prepare client notification processes, and maintain the compliance documentation SEC examiners expect. Standard IT support and managed security are different service categories with different scope.
What happens if an RIA is not compliant during an SEC examination?
The SEC can issue deficiency letters, require remediation, and impose civil penalties. In cases involving significant or repeated violations, matters can be referred for enforcement action. Firms with no written incident response program or that cannot produce compliance documentation are at substantially greater risk than those with an incomplete but actively maintained program.
How does managed security support differ from standard IT support?
Standard IT support handles the technical infrastructure: network monitoring, endpoint management, and incident response at the system level. Managed security support addresses the compliance and documentation layer that sits above it: writing and maintaining the incident response policy, conducting annual risk assessments, managing vendor oversight documentation, and preparing the firm for regulatory examination. Both are valuable, but they serve different purposes, and the SEC’s requirements touch both.
For more on how MSPs turn IT challenges into competitive advantages, read our feature in the Atlanta Business Chronicle.
Protecting your business starts with the right partner. Core Managed helps companies secure their data, scale efficiently, and stay compliant so you can focus on running the business. Give us a call at 888-890-2673 or contact us to schedule a conversation.