Monday to Friday, 8am to 6pm CT832-907-5594
ServicesRIAs & Advisors

For registered investment advisers

When the SEC asks, you can hand over your incident-response program.

If an examiner asked today, could you produce the written incident-response program Regulation S-P now requires, and the process to notify clients of a breach? We build both, protect the client financial data your business runs on, and start with a gap assessment, not a contract. This is a plan, not a compliance guarantee.

Does Regulation S-P apply to us?

You hold the full financial picture of every client: account numbers, balances, Social Security numbers, custodian logins.

In 2024 the SEC amended Regulation S-P (17 CFR 248.30). The amendments require registered investment advisers to maintain a written incident-response program and to notify affected individuals of a breach (SEC, Regulation S-P final rule, Federal Register, June 3, 2024, federalregister.gov). If your firm is SEC-registered, it applies to you directly.

If you register with the Texas State Securities Board instead of the SEC, Reg S-P is not the rule that binds you. The FTC Safeguards Rule (16 CFR Part 314) is, because its covered examples include an investment adviser that is not required to register with the SEC (16 CFR 314.2(h)). The comparison further down sets the two side by side.

The exposure for a small firm is concrete: the cost of the breach itself, the client conversation about whether their money is safe with you, and an examiner who asks for a program you cannot produce.

The same work also protects your insurance posture. The controls a cyber-insurance carrier asks about before it will quote or pay are the controls Reg S-P expects, so building the program keeps you able to qualify, bind, and keep a claim from being denied.

What must the incident-response program contain?

Reg S-P names the parts. Written policies and procedures that cover each of these are what an examiner expects to see (SEC, Regulation S-P amendments, sec.gov).

Assess

Figure out what was reached

Written steps to determine the nature and scope of unauthorized access to client information, so you know what happened instead of guessing, and the scope is documented rather than estimated.

Contain

Stop the bleeding

Procedures to contain and control the incident and limit the damage, so a single compromised mailbox or laptop does not become every client account.

Notify

Tell affected clients in time

A process to notify affected individuals, generally within 30 days of determining their information was, or likely was, accessed. The clock starts on determination, not on cleanup.

Oversee

Hold your vendors to the standard

Oversight of the service providers that touch client data, your CRM, portfolio tools, and custodian access included, so a breach at a vendor is still your documented responsibility.

Record

Keep it in writing

The program and every response documented, so when the examiner asks, you hand over a real record instead of describing what you would have done.

What the 30-day breach notice actually requires

If you determine that a client’s nonpublic personal information was, or was likely, accessed without authorization, you generally must notify that person within 30 days (SEC, Regulation S-P amendments). The clock starts when you make the determination, not when the cleanup is finished.

That is why the program is written before anything happens. In the middle of an incident you do not want to be deciding how to assess scope, who to call, or what the notice says. You want to follow steps you wrote on a calm day.

FTC Safeguards Rule or SEC Reg S-P: which one am I under?

Both come from the same law, the Gramm-Leach-Bliley Act, and both protect client financial data. Which one binds you depends on who regulates your firm. The underlying security work overlaps heavily.

What it coversFTC Safeguards RuleSEC Regulation S-P
Who enforces itFederal Trade CommissionSecurities and Exchange Commission
Who it bindsNon-bank financial firms: CPA and tax practices, settlement and closing services, and investment advisers not required to register with the SECSEC-registered investment advisers and broker-dealers
Written security planWritten information security program (WISP) with a named qualified individualWritten policies and procedures, including the incident-response program
Breach notificationSafeguards Rule centers on the program; notification duties varyNotify affected individuals, generally within 30 days of determination
Shared rootBoth implement the Gramm-Leach-Bliley Act; the protective controls are substantially the same

State-registered Texas advisers, generally those under $100 million in assets under management who register with the Texas State Securities Board, are not bound by Reg S-P directly. They fall under the FTC Safeguards Rule instead, since 16 CFR Part 314 names an investment adviser that is not required to register with the SEC among its covered examples. The protective work is the same.

How this starts

The starting point is a fixed-scope gap assessment of your firm against Regulation S-P, or the equivalent state safeguarding duties, including your incident-response program and notification process. You get a written report ranked by risk, and a plan you keep whether or not you hire us.

The person who assesses your firm is the person who does the work and answers the phone, so the incident-response program is not something a generalist vendor “will get to.” And you own your Microsoft tenant, your credentials, and your backups, always, with a documented runbook and a named escalation path so you are never locked in, including to us.

A written incident-response program mapped to Regulation S-P
A client-notification process built to the 30-day window
Least-privilege access across your CRM, portfolio tools, and custodian logins
Tested, ransomware-resistant backups you own

This is a gap assessment plus an ongoing program. It is not a certification, and no honest provider guarantees compliance.

Common questions

June 3, 2026 for advisers under $1.5 billion in assets under management, and December 3, 2025 for larger advisers (SEC final rule, federalregister.gov). The smaller-adviser date has already passed, so a sub-$1.5 billion Houston RIA without a written incident-response program is behind the rule now, not preparing for it.

Written by Hammad Arain, founder of Arain Systems. CCNA, CompTIA Security+, Microsoft AZ-104. Updated June 2026. Educational, not legal advice.

Get a free Regulation S-P incident-response and safeguards review

We check your incident-response program and safeguards against what Regulation S-P requires and where the gaps are, then give you written findings.

Get a free gap report

The work behind it

The written incident-response program Regulation S-P requires, the records behind it, and the controls that keep client data from being the thing you have to notify about.

Based in Houston, on-site across the metro.