Report · Updated September 14, 2026

Securing Compliance:
How to Survive an SEC
Cybersecurity Examination

The amended Reg S-P is now in effect for all covered advisers. This report sets the rules alongside the specific documentation requests firms receive before an exam begins, so you can see what examiners actually ask for.

Download the PDF
Executive Summary

The compliance landscape has changed

Cybersecurity compliance is no longer a technical checkbox. It is a regulatory obligation with direct consequences for examination outcomes, investor confidence, and firm continuity. The SEC cites cybersecurity deficiencies in examinations and has brought enforcement actions over safeguarding failures and misleading statements about cybersecurity.

CCOs are expected to speak fluently about cybersecurity risk without technical training. IT managers are juggling infrastructure with audit prep, often without dedicated support. Managing partners face questions from LPs, boards, and insurers that require defensible, documented answers.

This report was written to address a specific problem: public regulatory guidance is general, while examination request lists are specific. That gap can leave firms without documentation that answers the requests.

Overview of the regulatory framework

The following rules form the primary cybersecurity compliance obligations for SEC-registered investment advisers.

Rule 206(4)-7: The Compliance Program Rule

Often called the compliance rule, Rule 206(4)-7 requires each SEC-registered investment adviser to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act and its rules. Firms must review, at least annually, the adequacy of those policies and the effectiveness of their implementation, and designate a Chief Compliance Officer to administer the program. The rule does not mention cybersecurity, but examiners review cybersecurity policies as part of the compliance program, and Rule 204-2(a)(17) requires the firm to keep its policies and records of each annual review.

Regulation S-P: Privacy & Safeguards Rule

Regulation S-P requires advisers to adopt written policies and procedures that address administrative, technical, and physical safeguards for customer records and information. The 2024 amendments are in effect for all covered advisers: larger advisers ($1.5 billion or more in assets under management) had to comply by December 3, 2025, and all others by June 3, 2026. They added three core duties. First, a written incident response program. Second, notice to affected individuals as soon as practicable, and within 30 days, when sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization; notice is not required if a reasonable investigation determines the information has not been and is not reasonably likely to be used in a manner that would result in substantial harm or inconvenience, and it may be delayed if the U.S. Attorney General determines in writing that notice poses a substantial risk to national security or public safety. Third, written policies requiring oversight of service providers through due diligence and monitoring, reasonably designed to ensure each provider notifies the firm as soon as possible, but no later than 72 hours after becoming aware of a breach in security resulting in unauthorized access to a customer information system the provider maintains. The related records must be kept under Rule 204-2(a)(25).

Regulation S-ID: Identity Theft Red Flags

Regulation S-ID requires RIAs that qualify as financial institutions or creditors with covered accounts to develop and implement a written Identity Theft Prevention Program. The program must identify, detect, and respond to red flags that could indicate identity theft, its initial version must be approved by the board or a board committee (or a designated senior manager if the adviser has no board), and it must be updated periodically. Examiners focus on whether the adviser has assessed which red flags are relevant to its business model and whether staff are trained to recognize them.

Proposed Rule 206(4)-9: Cybersecurity Risk Management (Withdrawn)

The SEC proposed this rule in February 2022, reopened the comment period in March 2023, and withdrew the proposal in June 2025. It never took effect. Much of its operational ground, including incident response and service provider oversight, is now covered by the amended Reg S-P.

Part Two

What examiners actually ask for

The following documentation categories are drawn from examination request lists compiled across multiple SEC examinations of registered investment advisers. These are not the categories the SEC describes in published guidance. They are the items that appear in the request lists firms receive before an examiner arrives, including the March 2023 list reproduced in the PDF.

Policies and procedures

Examiners request all written compliance and operational policies and procedures in effect during the examination period, with a description of any material amendment related to cybersecurity or safeguarding client NPI, and a current copy of the policies that protect client NPI at rest and in transit. They then ask, area by area, whether the policies address topics such as patch management, access rights, remote devices, data loss prevention, penetration testing and vulnerability scans, verification of client requests to transfer funds, and oversight of service providers.

Asset and environment documentation

Firms are asked when devices and software were last inventoried, when network maps of connections and data flows (including where customer data is housed) were last updated, and who does the work. The 2023 request also asks for an inventory of where and how client NPI is stored, including every third-party system that holds it.

Access controls and user management

Examiners ask whether policies control access by role or job function and revise it promptly when employment status changes. The 2023 request asks for the last ten changes to or terminations of access rights for supervised persons and vendor representatives, with the date, how access changed (terminated, expanded, or reduced), and the reason.

Incident response

Examiners ask for the written incident response policy, the year it was last updated, and whether, when, and by whom it was last tested. They also ask for a history of actual or suspected breaches, including the dates of occurrence and discovery, the type of incident, whether clients were notified, any client losses and insurance recoveries, and the remediation taken, along with copies of any breach communications sent to clients.

Training records

Examiners ask whether the firm provides written guidance and periodic information security training, and request the written materials along with the dates, topics, and groups of employees who participated in each training event. Some request lists also ask for training materials provided to vendors with network access.

Vendor management

Firms are asked for a list of all vendors with access to the firm's network, systems, or data, or that provide web, cloud, or cybersecurity services. For each vendor, examiners want a description of the service, whether the vendor has access to client NPI, and whether an executed contract addresses the vendor's cybersecurity and safeguarding practices. Other request lists ask how the firm assesses vendors' cybersecurity and whether security requirements are written into vendor contracts.

Business continuity and disaster recovery

Examiners request the written business continuity plan that addresses mitigating or recovering from a cybersecurity incident, and ask when the backup system was last tested. Some lists also ask whether the plan addresses the resiliency, disaster recovery plans, and recovery time objectives of key vendors.

Cyber insurance

Firms are asked whether they maintain insurance that covers cybersecurity losses and expenses, the nature of the coverage, and whether any claims were filed and how they were resolved. For incidents involving lost client funds, the 2023 request also asks whether insurance applied and how much was recovered.

Annual review documentation

The 2023 request asks for any reports and documentation from the examination period evidencing reviews or testing of the firm's cybersecurity and safeguarding policies under Rule 206(4)-7. It also asks for a record of any exceptions to those policies with the remediation taken, and for any compliance consultant or mock-examination reports on cybersecurity.

Part Three

A full examination notice

The PDF reproduces an SEC examination notice and information request list sent to a registered investment adviser in March 2023. Names and identifying information have been redacted. It is included because the gap between regulatory guidance and examination reality is best understood by reading what the SEC actually sends.

The request list covers nineteen numbered items, including organization charts, supervised person lists, cybersecurity oversight, the cybersecurity risk assessment, an inventory of client NPI, compliance and cybersecurity policies, the annual review, compliance exceptions, complaints, access rights changes, vendors, and breaches. The examination period ran from January 1, 2022 through February 28, 2023.

Key observations from the 2023 request list:

  • The request for cybersecurity policies is separate from the request for general compliance policies, and asks for the dates of any updates made since January 1, 2022.
  • Item 9 asks the firm to state, for each of fourteen topics, whether its policies address it, and for each gap whether the topic is not applicable, low risk, or scheduled for development.
  • The vendor request covers every vendor with access to the firm's network, systems, or data, not just major vendors, and asks whether an executed contract addresses each one's cybersecurity practices.
  • The access rights request asks for the last ten changes or terminations, with dates and reasons, not just the current state.
  • The breach requests ask about actual and suspected incidents, client notification, lost funds, and insurance recoveries, and for copies of any breach communications sent to clients.
  • The list predates the Reg S-P amendments, so it has no explicit items on the incident response program, customer notice procedures, or 72-hour service provider notice. Expect current requests to add them.

The full text of this examination notice, including the complete information request list, is available in the downloadable PDF.

Summary

Recommended examination-readiness documentation

The following artifacts are the core documentation set we recommend an SEC-registered adviser keep ready. Each item corresponds to one or more categories in a typical examination request list.

Document Related rule What to have ready
Written cybersecurity policies and procedures Rule 206(4)-7 Current version with dated revision history
Annual compliance review memo Rule 206(4)-7 Tests performed, results, remediation with owners and dates
Incident response plan Reg S-P, Rule 206(4)-7 Named roles, decision triggers, notification steps, test records
Training records Rule 206(4)-7 Dates, topics, participant groups, completion rates
Vendor inventory and oversight records Reg S-P 248.30(a)(5) List of all vendors with NPI or network access; due diligence and monitoring records; contract terms where used
Access rights documentation Rule 206(4)-7 Current access list plus history of changes with authorization
Asset and network inventory Rule 206(4)-7 Devices, software, data flows, and where NPI is stored
Business continuity plan Rule 206(4)-7 Cybersecurity incident coverage, test records, RTO/RPO
Identity theft prevention program Reg S-ID Written program with red flags relevant to the firm's accounts

Sign up to download

Create a free BrainTrust account to download this document and access the rest of the starter library.

Sign in or join BrainTrust