Cybersecurity Regulatory Reference — SEC, FINRA, and State Rules for Financial Firms.
Regulations describe outcomes. Technology delivers them. Verification produces the artifacts examiners require. This page reorganizes the cybersecurity rules governing broker-dealers, SEC-registered investment advisers, and NYDFS-covered financial institutions into a structure designed to operationalize and defend a program — not just read the rules.
How to Use This Page
This page reorganizes the cybersecurity rules that govern broker-dealers, SEC-registered investment advisers (RIAs), and NYDFS-covered financial institutions into a structure designed for compliance officers, IT managers, and senior leadership who must operationalize and defend a program — not just read the rules.
Every regulation below is presented in five parts:
- The Rule — citation, effective dates, and what the regulation actually says
- The Obligation — what the firm must do, in plain English
- Technology Control — how the control is typically implemented (Microsoft 365 / Entra ID examples are used because that is what most of our clients run; the underlying control is what matters, not the vendor)
- How to Verify — how a CCO confirms the control is actually working without relying solely on the IT team's word
- Evidence for Examination — the artifact an examiner will ask for
A NIST CSF 2.0 function tag is included for each rule as MTradecraft's mapping layer, not a regulator-mandated taxonomy. Examiners increasingly reference the Framework's six functions — Govern, Identify, Protect, Detect, Respond, Recover — when structuring their requests. NYDFS itself does not require any specific framework but references nationally recognized frameworks, including NIST, as relevant points of reference.
A note on Microsoft 365: it is named throughout this page because the overwhelming majority of RIAs and small financial firms operate within the Microsoft 365 / Entra ID / Azure ecosystem. The technology examples are illustrative, not prescriptive. Firms running Google Workspace, on-premises Exchange, or hybrid environments must achieve the same control outcomes using equivalent native tooling.
Summary Crosswalk
Every requirement below is treated in full in the sections that follow. Citations are the controlling source; the NIST CSF 2.0 column is MTradecraft's mapping layer, not a regulator-mandated taxonomy.
| Requirement | Primary Citation(s) | Regulator | Core Action | NIST CSF 2.0 |
|---|---|---|---|---|
| Written Cybersecurity Program | SEC Rule 206(4)-7; Reg S-P; 23 NYCRR §500.3; FINRA 3110 | SEC, NYDFS, FINRA | Maintain a current, board-approved cybersecurity policy | GV |
| Designated Cybersecurity Leader | SEC Rule 206(4)-7 (CCO); 23 NYCRR §500.4 (CISO) | SEC, NYDFS | Identify a qualified individual responsible for the program | GV |
| Risk Assessment | SEC examination practice; 23 NYCRR §500.9 | SEC, NYDFS | Document and update on material change; at least annually | ID |
| Annual Cyber Review | SEC Rule 206(4)-7; FINRA 3120; 23 NYCRR §500.3 | SEC, FINRA, NYDFS | Evaluate effectiveness; document results | ID, GV |
| Incident Response Program | Reg S-P §248.30; 23 NYCRR §500.16; FINRA 4370 | SEC, NYDFS, FINRA | Written program covering assessment, containment, recovery | RS, RC |
| Breach Notification — Individuals | Reg S-P §248.30 | SEC | 30 days from awareness of compromise of sensitive customer information | RS |
| Breach Notification — Regulator | 23 NYCRR §500.17(a), (c) | NYDFS | 72 hours for covered incidents; 24 hours for any extortion payment (written explanation within 30 days) | RS |
| Multi-Factor Authentication | 23 NYCRR §500.12; Reg S-P (implicit) | NYDFS, SEC | MFA for all users (phishing-resistant methods recommended) | PR |
| Encryption | 23 NYCRR §500.15; Reg S-P safeguards | NYDFS, SEC | Encryption at rest and in transit for nonpublic information | PR |
| Vendor / Third-Party Oversight | Reg S-P §248.30(a)(5); 23 NYCRR §500.11; SEC Rule 206(4)-7 | SEC, NYDFS | DDQ, documented vendor safeguards, 72-hour incident notification | GV, ID |
| Identity Theft Prevention | SEC Reg S-ID | SEC | Written Red Flags program; train and test | ID, DE, RS |
| Books & Records — Cyber | SEC Rule 204-2 | SEC | 5-year retention; first 2 years easily accessible | GV, PR |
| Asset Inventory | 23 NYCRR §500.13 | NYDFS | Written procedure plus maintained inventory | ID |
| Penetration Testing | 23 NYCRR §500.5 | NYDFS | Annual pen test by a qualified internal or external party | ID |
| Security Awareness Training | 23 NYCRR §500.14; FINRA 3120 | NYDFS, FINRA | Documented training with completion tracking | PR |
| Annual Certification | 23 NYCRR §500.17(b) | NYDFS | Signed by highest-ranking executive and CISO by April 15 | GV |
| Business Communications Capture | SEC Rule 17a-4(b)(4); Rule 204-2(a)(7) | SEC, FINRA | Capture and retain business communications on every channel, including personal devices | GV, PR |
| Electronic Records Integrity | SEC Rule 17a-4(f)(2)(i) | SEC | Audit-trail or WORM preservation, plus a designated executive officer or third party | PR |
| Fund Compliance Program | Investment Company Act Rule 38a-1 | SEC | Board-approved program covering the fund's adviser and service providers; annual CCO report | GV, ID |
| Correct Safeguards Regime | GLBA §§ 501, 505 (15 U.S.C. 6801, 6805); Reg S-P; 16 CFR 314.1(b) | SEC, FTC, CFTC | Map each legal entity to its functional regulator and cite the rule that actually governs it | GV |
| AML Program & Cyber-Event SARs | 31 CFR 1023.210; 31 CFR 1023.320; FINRA 3310 | FinCEN, SEC, FINRA | Written AML program with independent testing; SAR within 30 days of initial detection | DE, RS |
| Information Systems Security Program | NFA Interpretive Notice 9070; CFTC Regs 160.30, 162.30 | NFA, CFTC | Written ISSP approved by CEO/CTO/CISO; reviewed every twelve months; annual training | GV, PR, RS |
SEC Rules
Rule 206(4)-7 — Compliance Program Rule
1. The Rule
17 C.F.R. § 275.206(4)-7. Requires every SEC-registered investment adviser to (a) adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act, (b) review those policies at least annually for adequacy and effectiveness, and (c) designate a Chief Compliance Officer responsible for administering the program.
2. The Obligation
The firm must own a written cybersecurity compliance program that is current, effective, tested annually, and supervised by a qualified CCO. "Written" means written — not assumed, not delegated to the MSP, not described verbally. "Effective" means the firm can demonstrate that the policy is followed in practice, not just that the document exists.
3. Technology Control
The compliance program itself is a document, but its effectiveness rests on operational controls that produce evidence. In a Microsoft 365 environment, the foundational controls include:
- Documented baseline configuration for Entra ID, Exchange Online, SharePoint, and Intune
- Conditional Access policies governing user sign-in, device compliance, and risk-based authentication
- Audit logging enabled in Microsoft Purview with a defined retention period
- A documented annual cybersecurity review process with assigned owners, evidence collection, and a sign-off workflow
The technology control that operationalizes 206(4)-7 is not a single tool — it is the discipline of documenting the firm's intended security posture, configuring the tenant to enforce it, and reviewing both the document and the configuration on a fixed cadence.
4. How to Verify
The CCO should be able to answer three questions without calling the IT team or the MSP:
- When was the cybersecurity policy last reviewed, by whom, and what changed?
- What evidence exists that the controls described in the policy are actually in force in the production environment?
- If the SEC asked tomorrow for the firm's annual compliance review, what would we hand them?
If the answers require a phone call, the program is paper-only. Verification at this level means scheduled drift reports comparing the current M365/Azure configuration to the documented baseline, and an annual review meeting that produces a dated, signed memorandum.
5. Evidence for Examination
- Dated, version-controlled cybersecurity policy with a clear revision history
- Annual review memorandum signed by the CCO documenting the scope, findings, and remediation status
- Configuration baseline document for the M365/Azure tenant
- Drift reports showing the tenant matches the baseline (or documenting and remediating where it does not)
- Board or senior-officer approval of the cybersecurity policy and material updates
Regulation S-P — Privacy, Safeguards, and Incident Response
1. The Rule
17 C.F.R. §§ 248.1–248.100. The 2024 amendments, effective August 2, 2024, expanded Regulation S-P substantially. Compliance was phased in by entity size:
- Larger entities — RIAs with $1.5B+ AUM, investment companies with $1B+ in net assets, and broker-dealers with $500K+ in net capital: December 3, 2025
- Smaller entities — RIAs under $1.5B AUM and most other covered entities: June 3, 2026
Both compliance dates have now passed. As of June 3, 2026, the amended Regulation S-P is fully in effect for every covered institution, regardless of size. A firm that has not yet adopted the written incident response program, the 30-day individual notification procedures, and the service provider oversight requirements described below is out of compliance today — not preparing for a future deadline.
The amendments require covered institutions to:
- Adopt written administrative, technical, and physical safeguards to protect customer information (definition broadened to cover a wider range of nonpublic personal information)
- Develop, implement, and maintain a written incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information
- Notify affected individuals no later than 30 days after the firm becomes aware of an incident where sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization
- Oversee service providers through written policies and procedures — including due diligence and monitoring — reasonably designed to ensure they safeguard customer information and notify the firm as soon as possible, but no later than 72 hours after becoming aware of a breach in security resulting in unauthorized access to a customer information system (§248.30(a)(5)). A contractual notification clause is the clearest way to evidence this oversight, but the final rule permits other documented means and does not mandate a specific contract term.
- Maintain records of policies, incidents, notifications, and related compliance activities
2. The Obligation
The firm must protect customer information from unauthorized access, detect breaches when they occur, notify affected individuals within 30 days, and prove all of it with documentation. The shift from the prior version of the rule is that detection, response, recovery, vendor oversight, and individual notification are no longer best practices — they are explicit, written, testable requirements. The SEC is already enforcing these expectations: see the November 2025 enforcement action discussed under Regulation S-ID below, which charged safeguards failures alongside Red Flags program deficiencies.
3. Technology Control
Safeguarding customer information (administrative, technical, physical):
- Encryption of customer data at rest in SharePoint, OneDrive, and Exchange; encryption in transit enforced via Conditional Access
- Multi-factor authentication for all users (see also NYDFS 500.12)
- Conditional Access policies blocking sign-in from unmanaged devices and untrusted locations
- Microsoft Purview Data Loss Prevention (DLP) policies that detect and block transmission of customer PII
- Sensitivity labels applied to documents containing customer information
- Role-based access controls via Entra ID groups, with least-privilege provisioning and access reviews at least annually (quarterly recommended for firms with elevated turnover or privileged-account counts)
Incident response:
- Written incident response plan with assigned roles, communication trees, and the cyber insurance carrier's IR panel pre-documented
- Microsoft Defender XDR or equivalent EDR producing alerts that feed a documented triage process
- Defined runbooks for the most likely incident categories: business email compromise, ransomware, credential theft, third-party breach affecting firm data
- Pre-drafted notification templates for affected individuals and regulators
Service provider oversight:
- Vendor inventory listing every third party with access to customer information, with the data category accessed, the notification obligations that apply (including the 72-hour standard, however evidenced), and last review date
- Standardized vendor due diligence questionnaire (DDQ) with documented review
4. How to Verify
For safeguards:
- Run a Microsoft Secure Score export and review the score and the unimplemented recommendations against the firm's documented baseline
- Pull the Entra ID sign-in logs and confirm that MFA was enforced for every authentication event in the last 90 days
- Review DLP policy reports for the volume and disposition of policy matches
- Confirm that every customer-data location (SharePoint sites, OneDrive accounts, mailbox folders) has appropriate sensitivity labels and access restrictions
For incident response:
- Conduct a tabletop exercise at least annually that walks through a realistic incident scenario from detection to individual notification, with timestamps
- Confirm that the cyber insurance carrier's IR panel contact information is current and that someone other than the CCO knows where to find it
For service provider oversight:
- Pull the vendor inventory and spot-check three vendors at random: when was their last DDQ review, how is the 72-hour notification standard evidenced for that vendor — a contract clause or other documented oversight (§248.30(a)(5)) — and is their security documentation current?
5. Evidence for Examination
- Written cybersecurity policy with customer information safeguards explicitly addressed
- Written incident response program meeting the three Reg S-P minima: assessment, containment, notification
- Incident log covering attempted and successful incidents for the prior five years (see Rule 204-2)
- Notification templates and any actual notifications sent, with timestamps demonstrating the 30-day window was met
- Service provider inventory and completed DDQs, with the 72-hour notification standard evidenced through contract clauses or other documented oversight (§248.30(a)(5))
- Sample sensitivity labels and DLP policies in force
- Tabletop exercise after-action reports
Regulation S-ID — Identity Theft Red Flags
1. The Rule
17 C.F.R. § 248.201. Requires covered financial institutions and creditors to develop and implement a written Identity Theft Prevention Program designed to detect, prevent, and mitigate identity theft in connection with covered accounts. The program must identify relevant red flags, detect them, respond appropriately, and be updated periodically.
2. The Obligation
RIAs offering or maintaining covered accounts — those permitting multiple payments or transactions, such as accounts where clients can transfer funds, plus any other account presenting a reasonably foreseeable identity-theft risk to customers (17 CFR §248.201(b)(3)) — must have a documented Red Flags program. The program must list the specific red flags the firm watches for, describe how those red flags are detected, and define the firm's response.
3. Technology Control
- Documented enumeration of red flags relevant to the firm's account types — for example: address-of-record changes followed quickly by transfer requests, mismatched IP geolocation on client logins, requests to wire funds to new beneficiary accounts
- Email security tooling (Microsoft Defender for Office 365 or equivalent) configured to detect spoofed sender addresses and impersonation attempts
- Conditional Access policies flagging risky sign-ins on client portals
- For firms with client-facing portals: identity proofing on sensitive account changes (callback verification, multi-channel confirmation)
- Logging of every red-flag event and the firm's documented response
4. How to Verify
- Annually, walk through each enumerated red flag and ask: in the past year, has this red flag been detected? If yes, how was it handled? If no, are we confident our detection mechanism works?
- Test the detection by sending a known-spoofed email from a controlled address and confirming it was flagged
- Review wire transfer authorization procedures with the operations team and confirm callback verification is occurring
5. Evidence for Examination
- Written Identity Theft Prevention Program identifying covered accounts and red flags
- Log of red flags detected and the firm's response
- Annual program review documentation
- Training records demonstrating staff have been trained on the program
Enforcement Note — November 2025
On November 25, 2025, the SEC settled charges against a dual-registered investment adviser and broker-dealer operating a nationwide network of member firms for violations of both the Regulation S-P Safeguards Rule and Regulation S-ID. Between 2019 and 2024, unauthorized actors took over roughly 17 business email accounts across 13 member firms and sent credential-harvesting emails to approximately 8,500 recipients, including a significant number of customers; at least one compromise led to an unauthorized wire transfer. The SEC found the firm lacked an enterprise-wide multi-factor authentication requirement, an adequate incident response framework, and security training — and that its Identity Theft Prevention Program had not been materially updated since at least 2015 and did not address cybersecurity-related red flags. The firm was censured and paid a $325,000 civil penalty.
The takeaway for RIAs: a Red Flags program written once and left static is itself a deficiency. The program must be periodically updated to reflect the firm's actual threat profile — and business email compromise is now squarely within the red flags the SEC expects it to cover.
Rule 204-2 — Books and Records
1. The Rule
17 C.F.R. § 275.204-2. Requires SEC-registered investment advisers to make and keep specified books and records. As applied to cybersecurity, the rule requires retention of policies, communications relating to compliance, and records evidencing the firm's compliance program for five years from the end of the fiscal year during which the last entry was made, maintained in an easily accessible place — the first two years in an appropriate office of the adviser (17 C.F.R. § 275.204-2(e)(1)).
2. The Obligation
The firm must retain its cybersecurity policies, incident records, communications about cyber matters, evidence of policy reviews and testing, and the underlying records of any investigation, determination, or notification made in connection with a cybersecurity incident. Retention runs five years from the end of the fiscal year during which the last entry was made, in an easily accessible place, the first two years in an appropriate office of the adviser (§ 275.204-2(e)(1)).
3. Technology Control
- Microsoft Purview retention policies applied to mailboxes, SharePoint, OneDrive, and Teams covering cybersecurity-relevant content for five years minimum
- Retention labels for incident response artifacts (incident logs, forensic reports, notification records, after-action memos)
- Immutable retention (preservation lock) for incident records to prevent deletion before the retention period expires
- Audit log retention configured to the maximum available under the firm's M365 license (Audit Premium provides one year by default; longer retention requires explicit configuration)
- A defined records schedule that maps every Reg S-P artifact category to a retention label and a storage location
4. How to Verify
- Pull the Purview retention policy export and confirm that mailboxes, SharePoint sites, and Teams used for compliance work are covered
- Spot-check by attempting to delete a record under retention — the system should block the deletion
- Confirm audit log retention is set correctly; the default in many M365 licenses is shorter than 204-2 requires for cybersecurity-relevant logs
- Annually, sample a record from each of the past five years and confirm it is retrievable
5. Evidence for Examination
- Written records retention policy with cybersecurity records explicitly addressed
- Purview retention policy export showing coverage and retention periods
- A retrieval test demonstrating the firm can produce a specific record from year four or five
- Audit log configuration showing retention periods
- Sample records from each year of the retention window
Rules 17a-4 and 17a-3 — Broker-Dealer Recordkeeping and Off-Channel Communications
1. The Rule
17 C.F.R. § 240.17a-3 specifies the records a broker-dealer must make; 17 C.F.R. § 240.17a-4 specifies how long those records must be preserved and in what form. Rule 17a-4(a) requires six-year preservation, the first two years in an easily accessible place, for the core books specified in § 240.17a-3(a)(1) through (3), (5), (21) and (22). Rule 17a-4(b) requires three-year preservation, the first two years in an easily accessible place, for a longer list — including, at § 240.17a-4(b)(4), "[o]riginals of all communications received and copies of all communications sent (and any approvals thereof) by the member, broker or dealer (including inter-office memoranda and communications) relating to its business as such."
Rule 17a-4(f) governs electronic recordkeeping. Following the 2022 amendments, an electronic recordkeeping system must either maintain "a complete time-stamped audit trail" of all modifications and deletions (§ 240.17a-4(f)(2)(i)(A)) or preserve records "exclusively in a non-rewriteable, non-erasable format" (§ 240.17a-4(f)(2)(i)(B)). A firm relying on the audit-trail alternative must be able to demonstrate that the audit trail exists and is complete. Rule 17a-4(f)(3)(v)(A) separately requires the firm to have on file at all times with its designated examining authority an undertaking signed by either a designated executive officer or a designated third party, committing that person to furnish the records and to download them into both a human-readable format and a reasonably usable electronic format if the firm itself fails to do so. A designated executive officer may act through a designated specialist, but under § 240.17a-4(f)(3)(v)(C) doing so does not relieve the officer of the undertaking. Rule 17a-4(j) requires the firm to furnish "promptly" legible, true, complete, and current copies to a Commission representative on request.
This is the broker-dealer counterpart to Rule 204-2. A dually registered firm is subject to both.
2. The Obligation
A communication relating to the firm's business is a required record regardless of the device, application, or account on which it occurs. Text messages, WhatsApp, Signal, personal email, and direct messages on collaboration platforms are all within § 240.17a-4(b)(4) when the subject matter is the firm's business. The SEC's off-channel communications enforcement actions have been charged as recordkeeping failures, not as cybersecurity rule violations — for broker-dealers, as violations of Section 17(a) of the Exchange Act and Rule 17a-4(b)(4); for investment advisers, under the parallel Advisers Act recordkeeping provisions discussed above. The sweep announced in SEC Press Release 2022-174 charged sixteen firms and has been followed by further actions. The exposure is created by uncaptured channels, not by a breach.
The practical obligation is therefore threefold: define which channels are approved, technically prevent or capture the rest, and be able to produce what was captured on demand.
3. Technology Control
- Microsoft Purview retention policies covering Exchange Online, Teams chat and channel messages, SharePoint, and OneDrive, set to the retention period required for each record category
- An archive whose vendor will state in writing which path under § 240.17a-4(f)(2)(i) it satisfies — audit trail or non-rewriteable, non-erasable format
- An executed undertaking, signed by either a designated executive officer or a designated third party, on file at all times with the firm's designated examining authority
- A written approved-channel policy, enforced technically: Intune application protection and Entra ID Conditional Access to restrict firm data to managed applications, and mobile device configuration that prevents business use of unarchived messaging apps
- Where a channel is approved rather than blocked — business SMS, WhatsApp Business — a compliant archiving connector that feeds the same retention system
- Microsoft Purview Communication Compliance policies to surface off-channel solicitation ("text me at…", "let's move to WhatsApp") within captured traffic
- Periodic written attestations from registered persons regarding personal-device use
4. How to Verify
- Obtain the archive vendor's written attestation and confirm it names § 240.17a-4(f)(2)(i)(A) or (B) specifically — a general claim of "SEC compliance" is not sufficient
- Confirm the undertaking on file is current, is signed by a designated executive officer or a designated third party, and that the signatory still holds that role — appointing a specialist internally does not satisfy the requirement
- Run a live production test: pick a Teams message and an archived text message from eighteen months ago and time how long retrieval takes end to end
- Pull the Communication Compliance alert log and confirm off-channel solicitation alerts are being reviewed and dispositioned, not merely generated
- Reconcile the attestation roster against the current registered-person list and confirm there are no gaps
5. Evidence for Examination
- Written communications retention policy identifying approved channels and the retention period for each record category
- Archive vendor attestation citing the specific paragraph of § 240.17a-4(f)(2)(i) relied upon
- The undertaking filed with the designated examining authority, signed by a designated executive officer or a designated third party
- Production test log demonstrating retrieval within a defensible timeframe
- Communication Compliance policy configuration, alert log, and review dispositions
- Signed personal-device attestations and records of any disciplinary action taken for off-channel use
Rule 38a-1 — Fund Compliance Programs
1. The Rule
17 C.F.R. § 270.38a-1 applies to registered investment companies and business development companies. Rule 38a-1(a)(1) requires the fund to adopt written policies and procedures reasonably designed to prevent violation of the Federal Securities Laws, "including policies and procedures that provide for the oversight of compliance by each investment adviser, principal underwriter, administrator, and transfer agent of the fund." Rule 38a-1(a)(2) requires approval by the fund's board, including a majority of directors who are not interested persons, based on a finding that the policies and procedures are reasonably designed. Rule 38a-1(a)(3) requires review no less frequently than annually of the adequacy of the policies and procedures of the fund and of each investment adviser, principal underwriter, administrator, and transfer agent, and the effectiveness of their implementation. Rule 38a-1(a)(4) requires designation of a chief compliance officer whose designation and compensation are board-approved, who may be removed only with board approval, who must report in writing to the board at least annually on the operation of the policies and procedures and on each Material Compliance Matter, and who must meet separately with the independent directors at least annually.
2. The Obligation
Rule 38a-1 is the fund-side analog of Rule 206(4)-7, and it is broader in one respect that matters for cybersecurity: the fund's program must reach the compliance of its adviser, principal underwriter, administrator, and transfer agent. A cybersecurity failure at a transfer agent is a fund compliance matter, not merely a vendor problem. The fund CCO cannot discharge the rule by accepting assurances; the annual review must cover each of those four categories of service provider, and the results must reach the board.
Advisers to registered funds should expect examiners to ask how cybersecurity was addressed in the 38a-1 annual review and whether any cyber incident at a service provider was escalated as a Material Compliance Matter.
3. Technology Control
- A vendor due diligence questionnaire issued at onboarding and refreshed annually for the adviser, principal underwriter, administrator, and transfer agent
- Documented evidence sufficient to assess each named firm's relevant controls; where a SOC 2 Type II report is relied upon, a review memorandum recording its scope, period, exceptions, and complementary user entity controls
- Contractual incident notification clauses with defined timeframes, aligned to the fund's own reporting obligations
- A consolidated service provider register recording, for each firm, the current report date, the review date, open exceptions, and the responsible owner
- A standing cybersecurity section in the CCO's annual board report package
4. How to Verify
- Confirm the annual review holds current, documented evidence sufficient to assess the controls of each firm named in the rule; Rule 38a-1 does not require a SOC 2 report, and some providers will not have one
- Confirm the annual review workpapers address each service provider by name rather than as a group
- Read the board minutes and confirm they record the finding required by Rule 38a-1(a)(2), not merely that approval occurred
- Confirm the CCO's annual written report addressed cybersecurity and that any cyber incident was assessed against the Material Compliance Matter definition
- Confirm the separate meeting with independent directors occurred and is minuted
5. Evidence for Examination
- Board minutes recording approval and the reasonable-design finding
- Annual review report covering the fund and each service provider
- The CCO's annual written report to the board
- Control evidence for each named firm — SOC 2 reports where available — with dated review memoranda
- Service provider contracts showing incident notification obligations
- Minutes of the separate session with independent directors
GLBA Title V and the FTC Safeguards Rule — Which Regime Actually Applies
1. The Rule
The Gramm-Leach-Bliley Act, 15 U.S.C. §§ 6801–6809, is the statute underneath Regulation S-P. Section 501(b) (15 U.S.C. § 6801(b)) directs the functional regulators to establish safeguards standards; Section 505 (15 U.S.C. § 6805) allocates enforcement among them. For broker-dealers, SEC-registered investment advisers, and investment companies, the functional regulator is the SEC, and the SEC's implementation of the GLBA safeguards mandate is Regulation S-P, 17 C.F.R. Part 248.
The FTC's Safeguards Rule, 16 C.F.R. Part 314, implements the same statutory provision for a different population. Its scope provision is explicit: the rule applies to financial institutions over which the FTC has jurisdiction, and "[t]he 'financial institutions' subject to the Commission's enforcement authority are those that are not otherwise subject to the enforcement authority of another regulator under section 505 of the Gramm-Leach-Bliley Act, 15 U.S.C. 6805" (16 C.F.R. § 314.1(b)). Entities whose financial activity is subject to CFTC jurisdiction are likewise outside it.
2. The Obligation
The obligation this creates is a scoping obligation: determine, entity by entity, which safeguards rule governs, and write each program to the rule that actually applies to it.
This matters because many firms sit inside a group that also contains entities the SEC does not regulate — a tax preparation arm, an unregistered lending or finance company, a mortgage brokerage, or a family office administrative entity. Coverage is not established by affiliation. An entity falls under Part 314 only if it is itself a "financial institution" — which § 314.2(h)(1) defines as an institution "significantly engaged" in an activity that is financial in nature or incidental to such activities — and no other regulator has enforcement authority over it under § 6805. Insurance activity, for example, generally answers to state insurance authorities rather than the FTC.
Where an entity does fall under Part 314, its program must address elements Regulation S-P does not state in the same terms — among them a designated Qualified Individual (§ 314.4(a)), a written risk assessment (§ 314.4(b)), encryption of customer information in transit and at rest (§ 314.4(c)(3)), and multi-factor authentication for any individual accessing any information system (§ 314.4(c)(5)). Two qualifications matter in practice. The encryption and MFA requirements each admit an alternative: where encryption is infeasible the firm may use compensating controls reviewed and approved by the Qualified Individual, and MFA may be replaced by reasonably equivalent or more secure access controls the Qualified Individual approves in writing. And § 314.6 exempts financial institutions maintaining customer information concerning fewer than five thousand consumers from § 314.4(b)(1), (d)(2), (h), and (i) — meaning the written risk assessment specifications, the continuous monitoring and testing requirement, the written incident response plan, and the annual written report do not apply to a small affiliate below that threshold. Determine the consumer count before assuming the full element set applies.
The same analysis applies to vendors. A service provider may be an FTC-regulated financial institution in its own right, which changes what its diligence answers should say and what its contract should require.
3. Technology Control
- An entity-level register listing every legal entity in the group, its registrations, its activities, the regulator with enforcement authority under § 6805, and the safeguards rule that governs it
- Where an entity is determined to fall under FTC jurisdiction, a written information security program drafted to the elements of § 314.4 with a named Qualified Individual — not an implicit extension of the registered entity's Reg S-P program
- Tenant segmentation, or at minimum documented administrative and access boundaries, where affiliates share a Microsoft 365 tenant, so that each entity's data scope is determinable
- A data flow map showing which entity is the source of each category of customer information
4. How to Verify
- List every legal entity in the group and, for each, record the activities it conducts and whether any regulator holds enforcement authority under § 6805
- For entities with no such regulator, assess FTC jurisdiction under § 314.1(b) on the activity — absence of another regulator is necessary but not sufficient
- Confirm each entity's written program cites the rule that actually governs it
- Review outbound DDQ responses, RFP answers, and contractual representations for claims of compliance with the wrong regime
- For any entity determined to be FTC-regulated, establish its consumer count against the § 314.6 threshold, and where the exemption does not apply, confirm the annual written report under § 314.4(i) was delivered and retained
5. Evidence for Examination
- Entity-to-regulator matrix with supporting registration records and the activity-based coverage determination for each entity
- Regulation S-P program for the registered entities
- Section 314.4 program and Qualified Individual designation for any entity determined to be FTC-regulated, with the § 314.6 consumer-count determination on file, and the annual written report where that exemption does not apply
- Data flow map identifying the originating entity for each category of customer information
- Index of external cybersecurity representations and the regime each one cites
Advisers Act Sections 204 and 206 — General Authority
1. The Rule
Section 204 (15 U.S.C. § 80b-4) gives the SEC general recordkeeping authority over investment advisers. Section 206 (15 U.S.C. § 80b-6) is the anti-fraud provision — it prohibits any adviser from engaging in fraudulent, deceptive, or manipulative practices.
2. The Obligation
The firm must not misrepresent its cybersecurity posture to clients, prospects, or regulators. Marketing claims about security, statements in Form ADV, and responses to client DDQs must be accurate and substantiable. A breach that affected client data must be disclosed when disclosure is required; misleading statements about a breach, or about controls that do not exist, are enforceable as fraud regardless of whether a specific cyber rule was violated.
3. Technology Control
This rule is governed primarily by process, not technology, but technology supports it:
- Every public claim about cybersecurity (in Form ADV, RFP responses, DDQ answers, marketing materials) is supported by an internal artifact demonstrating the claim is true
- Statements like "we use multi-factor authentication" are backed by an Entra ID Conditional Access export showing MFA enforcement
- Statements like "we encrypt customer data" are backed by encryption configuration evidence
- A defined review process before any cybersecurity statement is published externally
4. How to Verify
- Pull the firm's current Form ADV and identify every cybersecurity-related statement
- For each statement, locate the supporting evidence
- If supporting evidence cannot be produced within thirty minutes, the statement is at risk
5. Evidence for Examination
- Mapped index of public cybersecurity claims and supporting evidence
- Review and approval workflow for cybersecurity marketing content
- Documentation of any disclosure or notification made under Reg S-P or related obligations
Rule 206(4)-9 — Cybersecurity Risk Management (Withdrawn)
Why this still matters
The proposed rule articulated the SEC's view of what a mature RIA cybersecurity program should look like — written policies, annual reviews, 48-hour incident reporting on a proposed Form ADV-C, vendor access governance. The withdrawal removed the prescriptive deadline; it did not remove examiner expectations. The proposal remains a useful indicator of the SEC staff's prior policy direction and overlaps heavily with current obligations under Reg S-P (as amended), Rule 206(4)-7, and Rule 204-2.
For programs already built to those rules there is no operational gap created by the withdrawal. Firms that built their programs assuming 206(4)-9 would never arrive are usually under-prepared for current examination expectations regardless.
FINRA Rules
FINRA rules apply to broker-dealers. RIAs without a broker-dealer affiliate are not directly subject to FINRA rules, but the cybersecurity expectations are substantially similar and FINRA guidance frequently aligns with SEC examination priorities.
Rule 3110 — Supervision
The Rule
Requires firms to establish and maintain a supervisory system reasonably designed to achieve compliance with applicable securities laws and FINRA rules.
Cybersecurity Obligation
The supervisory system must cover cybersecurity hygiene: access reviews, vendor technology decisions, supervision of associated persons' use of firm technology, and staff training. Common exam findings include outdated policies and missing periodic access reviews.
Technology Control
Quarterly Entra ID access reviews using Microsoft Entra Access Reviews; documented onboarding and offboarding workflows; periodic supervisory reviews of cybersecurity training completion and policy attestation.
Verification
Pull the Access Reviews report. Confirm that every reviewer completed every review, that decisions were documented, and that access changes were enforced. Confirm cybersecurity training completion rate exceeds the firm's documented threshold.
Evidence
Quarterly access review reports, training completion reports, supervisory review memoranda.
Rule 3120 — Supervisory Control System
The Rule
Requires annual testing and verification of supervisory controls.
Cybersecurity Obligation
Annual supervisory reviews should include cybersecurity exercises appropriate to the firm's risk profile — typical examples include phishing simulations, tabletop drills, and vendor evaluations.
Technology Control
Phishing simulation platform (FieldCraft or equivalent) running monthly campaigns; documented tabletop exercise program; vendor review schedule aligned to annual cycle.
Verification
Annual phishing simulation results with click rates and remediation; tabletop exercise after-action reports; vendor review log.
Evidence
Annual supervisory control test report covering cybersecurity exercises; phishing simulation history; tabletop exercise documentation.
Rule 4370 — Business Continuity Plans
The Rule
Requires written business continuity plans for significant business disruptions.
Cybersecurity Obligation
The BCP must explicitly cover cyber incidents — ransomware, distributed denial of service, prolonged platform outages — and must include recovery procedures, testing cadence, and response protocols.
Technology Control
Documented recovery time and recovery point objectives for critical systems; Microsoft 365 backup solution (native retention is not a backup — see the "M365 as a Books and Records issue" topic in The BrainTrust); tested failover procedures.
Verification
Annual BCP test that exercises the cyber incident scenarios specifically. Confirm that backups are tested by performing a real restore — not by inspecting the backup console.
Evidence
Current BCP with cyber scenarios; annual BCP test report; restore test documentation.
Rule 4530 — Reporting Requirements
The Rule
Requires firms to report specified events to FINRA, including certain customer complaints and disciplinary actions.
Cybersecurity Obligation
Rule 4530 is not a standalone cyber-incident reporting rule. The obligation, when a cybersecurity event occurs, is to evaluate whether the event triggers one of the rule's enumerated reporting categories — for example, customer complaints, internal discipline arising from a cyber incident, or other reportable events. Coordinate with legal counsel promptly when that evaluation is in play.
Technology Control
Process control. Incident response plan must include a Rule 4530 evaluation step at the appropriate stage of an incident.
Verification
During tabletop exercises, confirm the 4530 evaluation step is identified and executed.
Evidence
Incident response plan referencing Rule 4530 evaluation; any actual 4530 filings made in connection with cyber events.
Rule 3310 — AML Compliance Program
The Rule
Requires firms to detect and report suspicious transactions.
Cybersecurity Obligation
Integrate cybercrime indicators into AML monitoring — credential-stuffing patterns, anomalous logins, transactions following phishing-induced compromises. See FinCEN Advisory FIN-2016-A005 on cyber events and cyber-enabled crime.
Technology Control
Coordination between the AML monitoring platform and the firm's identity / Conditional Access logs; flagging procedures for transactions that follow anomalous authentication events.
Verification
Sample review of recent SARs (if any) and AML alerts to confirm cyber indicators are being considered.
Evidence
AML program documentation reflecting cyber indicators; SARs filed in connection with cyber events.
Bank Secrecy Act — 31 CFR Part 1023 (the obligation behind Rule 3310)
The Rule
FINRA Rule 3310 enforces a statutory obligation that originates elsewhere. 31 U.S.C. § 5318(h) requires an anti-money laundering program; 31 C.F.R. § 1023.210 sets out what a broker-dealer's program must contain to be deemed to satisfy it — a written program approved by senior management that includes policies, procedures, and internal controls; independent testing by firm personnel or a qualified outside party; a designated individual responsible for implementation and monitoring; ongoing training; and risk-based ongoing customer due diligence. 31 C.F.R. § 1023.320 governs suspicious activity reporting: a SAR must be filed no later than 30 calendar days after initial detection of facts that may constitute a basis for filing, extendable by a further 30 days if no suspect has been identified, but never beyond 60 days.
Cybersecurity Obligation
A cyber event is not automatically reportable. The mandatory trigger is transactional: under § 1023.320(a)(2), reporting is required where a transaction is conducted or attempted by, at, or through the broker-dealer, involves or aggregates at least $5,000 in funds or other assets, and the firm knows, suspects, or has reason to suspect one of the enumerated grounds. FinCEN Advisory FIN-2016-A005 (October 25, 2016) applies that existing standard to cyber activity: where a firm "knows, suspects, or has reason to suspect that a cyber-event was intended, in whole or in part, to conduct, facilitate, or affect a transaction or a series of transactions," the event should be treated as part of an attempt to conduct a suspicious transaction. The advisory also directs firms to include available cyber-related information — IP addresses with timestamps, device identifiers, virtual-wallet information, and indicators of compromise — in any SAR they file, and encourages voluntary filing for significant cyber events that fall below the mandatory threshold.
This is where the AML program and the incident response plan meet: an account takeover or a business email compromise that reaches a qualifying transaction is simultaneously a security incident and a SAR trigger, and the 30-day clock runs from initial detection of the facts, not from the conclusion of the investigation.
Technology Control
A documented handoff between the incident response process and the AML function, so that a security incident is routed for SAR assessment as a defined step rather than by informal judgment. Identification of the technical artifacts that support a filed SAR — Entra ID sign-in logs, Conditional Access results, mail flow and inbox rule audit records — as supporting documentation, retained with the SAR for five years from the filing date under § 1023.320(d). Log retention beyond that scope is a separate, risk-based decision driven by the firm's own detection and investigation needs.
Verification
Trace a recent security incident through the AML process and confirm the SAR assessment was performed and documented, including where the conclusion was that no filing was required. Confirm the independent testing required by § 1023.210(b)(2) covered the cyber-event pathway. Confirm the artifacts referenced in any filed SAR are still retrievable.
Evidence
Written AML program showing senior management approval; independent testing report; escalation procedure linking incident response to SAR assessment; incident log recording the SAR determination for each incident and the date of initial detection; filed SARs and supporting documentation.
Rule 1220(b)(3) — Operations Professional, and Rule 2010 — Standards of Commercial Honor
These are foundational rules whose cybersecurity impact is principles-based rather than prescriptive. Operations personnel must demonstrate competence in secure data handling; material cybersecurity lapses can support violations of Rule 2010 even when no specific cyber rule is cited.
State Cybersecurity Regulations
23 NYCRR Part 500 — NYDFS Cybersecurity Regulation
1. The Rule
23 NYCRR Part 500 applies to entities licensed, registered, or chartered under New York Banking Law, Insurance Law, or Financial Services Law. The Second Amendment was finalized November 1, 2023; all transitional periods have now closed. The final phase of the Second Amendment — expanded multi-factor authentication and written asset inventory procedures — took effect November 1, 2025. The annual Certification of Material Compliance for calendar year 2025 was due April 15, 2026, signed by the covered entity's highest-ranking executive and CISO (or, if there is no CISO, the senior officer responsible for the cybersecurity program).
Key requirements include:
- §500.3 — Written cybersecurity policy, annually approved by a senior officer or the senior governing body
- §500.4 — Designation of a Chief Information Security Officer
- §500.5 — Vulnerability management: annual penetration testing by a qualified internal or external party (from both inside and outside the system boundaries); automated vulnerability scans, with manual review for systems not covered by automated scanning, at a frequency set by the firm's risk assessment and promptly after material system changes; documented monitoring, prioritization, and remediation
- §500.7 — Access privilege management, including limitations on privileged accounts; privileged access management for Class A companies
- §500.9 — Risk assessment, updated at least annually and whenever there are material changes
- §500.11 — Third-party service provider security policy
- §500.12 — Multi-factor authentication for all users (effective November 1, 2025)
- §500.13 — Asset management and data retention (effective November 1, 2025)
- §500.14 — Cybersecurity awareness training; endpoint detection and response and centralized logging for Class A companies
- §500.15 — Encryption of nonpublic information in transit and at rest
- §500.16 — Incident response and business continuity plans
- §500.17(a)/(c) — 72-hour notice to NYDFS of cybersecurity incidents (§500.17(a)); notice of any extortion payment within 24 hours, and within 30 days of the payment a written description of the reasons it was necessary, alternatives considered, and diligence performed (§500.17(c))
- §500.17(b) — Annual Certification of Material Compliance or Acknowledgment of Noncompliance, signed by the covered entity's highest-ranking executive (typically the CEO) and CISO; if the firm has no CISO, the senior officer responsible for the cybersecurity program signs in that role
2. The Obligation
The firm must operate a comprehensive cybersecurity program covering governance, risk assessment, access controls, encryption, training, vendor oversight, incident response, and reporting — and must annually certify compliance with personal accountability resting on the firm's highest-ranking executive and the CISO. NYDFS has issued consent orders and fines (including a $30M settlement) for compliance failures, with MFA gaps among the most cited findings.
3. Technology Control
The MTradecraft baseline for an M365-centric NYDFS-covered firm:
Governance and risk:
- Named CISO (internal or outsourced under §500.4)
- Written cybersecurity policy reviewed and approved annually by the senior governing body
- Risk assessment updated annually and on material change
Identity and access:
- MFA enforced via Entra ID Conditional Access for all users; NYDFS guidance flags SMS-based MFA as weaker and push-based MFA without number matching as vulnerable to push-fatigue attacks, and recommends phishing-resistant methods (FIDO2 security keys, Windows Hello for Business, certificate-based authentication) where the firm's environment supports them
- Privileged Identity Management (PIM) for all administrative roles, with just-in-time elevation, approval workflow, and audit logging
- Quarterly access reviews using Entra Access Reviews
- Automated password blocking via Entra Password Protection (banned password list)
Data protection:
- Encryption at rest enforced across SharePoint, OneDrive, Exchange (native), with customer key for Class A firms where appropriate
- TLS 1.2+ enforced on all external connections
- Microsoft Purview DLP policies and sensitivity labels for nonpublic information
Detection and response:
- Microsoft Defender XDR or equivalent EDR for Class A firms
- Microsoft Sentinel or equivalent SIEM for centralized logging (Class A requirement)
- Documented incident response plan with NYDFS 72-hour notification procedures explicitly mapped
- Annual penetration test by a qualified internal or external party, from both inside and outside the system boundaries
- Automated vulnerability scans, with manual review for systems not covered by automated scanning, at a frequency set by the risk assessment and run promptly after material system changes
Asset management (§500.13):
- Written asset inventory procedures defining update frequency, validation method, and per-asset tracking (owner, location, classification, support expiration, RTO)
- Asset inventory maintained in accordance with the written procedure
Vendor oversight:
- Third-party service provider policy under §500.11
- DDQ process with documented review
4. How to Verify
- Run an Entra ID MFA enforcement report against the full user list; the gap must be zero (excluding documented and CISO-approved compensating controls)
- Pull the PIM activation log and confirm administrative role activations are time-bound and approved
- Confirm the firm's penetration test was conducted within the last twelve months by a qualified internal or external party and that findings have been remediated or risk-accepted with documentation
- Review the §500.17(b) certification supporting documentation as it would be presented to NYDFS — does it actually demonstrate material compliance, or does it rely on assertion?
- Confirm the asset inventory matches reality — sample five assets and verify the inventory entry against the live environment
5. Evidence for Examination
- Annual Certification of Material Compliance (or Acknowledgment of Noncompliance), signed by the highest-ranking executive and CISO (or, if no CISO, by the highest-ranking executive and the senior officer responsible for the cybersecurity program)
- Written cybersecurity policy with senior-governing-body approval evidence
- Risk assessment with material-change updates documented
- Penetration test report (annual)
- Vulnerability scan reports and manual review records, with cadence consistent with the firm's risk assessment
- Asset inventory and written asset inventory procedure
- Third-party service provider policy and DDQ records
- MFA enforcement evidence
- Training records
- Incident response plan and any §500.17 notifications made
State Privacy Laws — Practical Impact for Financial Firms
Most state privacy laws (CCPA/CPRA in California, VCDPA in Virginia, CPA in Colorado, CTDPA in Connecticut, UCPA in Utah, and the growing number of similar statutes enacted since) include broad exemptions for entities subject to the Gramm-Leach-Bliley Act and personal information collected, processed, sold, or disclosed under GLBA. In practice this means most SEC-registered investment advisers and broker-dealers operate primarily under the federal regime — Reg S-P and Reg S-ID — for personal information processed in the course of providing financial services.
The exemptions are not absolute. Considerations include:
- Employee data — many state privacy laws cover employee personal information separately from financial customer data, even where the firm's customer data is exempt
- Marketing data — personal information collected outside a financial service context (general marketing inquiries, prospect lists) may fall outside GLBA exemption
- Texas Data Privacy and Security Act (TDPSA) — effective July 1, 2024, with GLBA exemption similar to other state laws; firms headquartered or operating in Texas should confirm the exemption analysis given the firm's specific data flows
- Massachusetts 201 CMR 17.00 — pre-dates the modern state privacy wave and imposes written information security program requirements on entities handling Massachusetts residents' personal information
Technology Control
A defensible state-law posture rests on the same controls already required by Reg S-P and 23 NYCRR Part 500 — written information security program, encryption, access controls, vendor oversight, and incident response. The marginal addition is data inventory: knowing which categories of personal information the firm holds, where they reside, and which legal regime governs each category.
Verification
Annual data mapping exercise. Confirm that customer financial data, employee data, and marketing data are each identified and matched to the governing regime.
Evidence for Examination
Data inventory; written information security program; vendor contracts with appropriate notification clauses; state-specific notifications, if any, sent in connection with prior incidents.
CFTC and NFA Requirements
These requirements reach commodity trading advisors, commodity pool operators, introducing brokers, futures commission merchants, retail foreign exchange dealers, swap dealers, and major swap participants. They matter to this audience mainly because dual registration is common: an adviser that runs a managed futures sleeve, or a fund manager registered as a CPO, is subject to both the SEC regime described above and the regime below, and the two have different triggers.
NFA Interpretive Notice 9070 — Information Systems Security Programs
1. The Rule
NFA Interpretive Notice 9070, "NFA Compliance Rules 2-9, 2-36 and 2-49: Information Systems Security Programs," was adopted by the NFA Board on August 20, 2015, effective March 1, 2016, and amended effective April 1, 2019 and September 30, 2019. It interprets the general supervisory obligations in Compliance Rule 2-9 (FCMs, CTAs, CPOs, IBs), Rule 2-36 (RFEDs), and Rules 2-9(d) and 2-49 (swap dealers and major swap participants, adopting CFTC Regulation 23.602 by reference).
The Notice requires each Member to adopt and enforce a written information systems security program appropriate to its size, complexity, customer base, data sensitivity, and electronic interconnectivity. Specific requirements include:
- Written approval by the Member's Chief Executive Officer or other senior level officer with primary responsibility for information system security — a CTO or CISO — or another senior official who is a listed principal with authority to supervise execution of the ISSP
- Review at least once every twelve months, performed either by in-house staff with appropriate knowledge or by an independent third-party information security specialist; penetration testing is expected where circumstances warrant
- Training on hiring and annually thereafter, with the ISSP identifying the topics the training covers
- Third-party service provider risk addressed in the security risk assessment, with due diligence on critical providers and procedures to remove provider access on a timely basis once services end
- Prompt notice to NFA of a cybersecurity incident related to the Member's commodity interest business that results in any loss of customer or counterparty funds, any loss of the Member's own capital, or the Member providing notice to customers or counterparties under state or federal law
Two CFTC rules sit alongside the Notice. CFTC Regulation 160.30 (17 C.F.R. § 160.30) requires every FCM, RFED, CTA, CPO, IB, MSP, and swap dealer subject to Commission jurisdiction to adopt policies and procedures addressing administrative, technical, and physical safeguards for customer records and information — the functional analog of Regulation S-P. CFTC Regulation 162.30 (17 C.F.R. § 162.30) requires a registrant to periodically determine whether it offers or maintains covered accounts and, if it does, to develop and implement a written identity theft prevention program under § 162.30(d) — the functional analog of Regulation S-ID, applicable to covered registrants rather than to all of them.
2. The Obligation
A dually registered firm runs one security program but answers to two sets of triggers, and the notification triggers do not align. Regulation S-P requires notice to affected individuals as soon as practicable and not later than 30 days after becoming aware that sensitive customer information was or is reasonably likely to have been accessed or used without authorization. The NFA trigger is different in kind: it applies to a cybersecurity incident related to the Member's commodity interest business, and turns on loss of customer or counterparty funds, loss of the Member's own capital, or the fact that the firm has given notice to customers or counterparties under state or federal law. It sets no fixed deadline — the Notice requires prompt notification.
The two can diverge in both directions. An incident can require NFA notice without triggering Reg S-P. A Reg S-P notification to individuals triggers the NFA provision as well, but only where the underlying incident also relates to the Member's commodity interest business. Incident response procedures should therefore evaluate the Reg S-P deadline and the NFA trigger as separate determinations rather than treating one as a proxy for the other.
3. Technology Control
- A written ISSP with a signed and dated approval page identifying the signer's role, retained as the approval record
- The same underlying control stack described elsewhere on this page — MFA, encryption, access reviews, logging, vendor diligence; NFA sets no specific technology requirements by policy
- An annual review record naming who performed it and whether they were in-house or an independent specialist
- Training assigned on hire and annually, with the ISSP's stated topic list and the training content reconciled to each other
- A decision step in the incident response plan that evaluates the NFA notice trigger and the Reg S-P trigger separately, with the NFA Cyber Notice filing route documented
4. How to Verify
- Confirm the ISSP approval is in writing, is current, and was signed by someone holding one of the roles the Notice permits — an approval by a compliance officer who is neither the CEO nor the senior officer responsible for information security does not meet the standard unless that person is a senior official who is a listed principal with authority to supervise execution of the ISSP
- Confirm the last review occurred within twelve months and that its scope and reviewer are documented
- Reconcile the training completion report against the current personnel roster, including new hires
- Run a tabletop exercise on a scenario that triggers NFA notice but not Reg S-P notification, and a second on the reverse, confirming the plan reaches each determination independently
- Confirm the vendor due diligence file covers the providers the ISSP identifies as critical
5. Evidence for Examination
- The written ISSP with its signed approval page
- Annual review report identifying reviewer, scope, findings, and remediation
- Training records showing completion on hire and annually, and the topic list
- Vendor due diligence file for critical service providers, with evidence of access removal at termination
- Incident log recording, for each incident, the NFA notice determination and the Reg S-P determination separately
- Copies of any notice filed with NFA, or the customer notice provided in lieu of a written summary
How MTradecraft Operationalizes This
A firm that follows the verification guidance on this page will be better positioned to address many common examiner requests — provided the controls are implemented, documented, and reviewed in practice. The most common failure mode at small and mid-size RIAs is not the absence of policy; it is the absence of evidence that the policy has been followed.
MTradecraft's engagements are built around producing that evidence on a continuous schedule:
- Quarterly external attack surface reports
- Monthly M365 / Azure configuration drift monitoring against the firm's documented baseline (weekly under the Remote CISO tier)
- Continuous breach and credential exposure monitoring
- Annual policy refresh aligned to current SEC and NYDFS examination priorities
- For Remote CISO clients: named CISO function for Form ADV, vendor questionnaires, board reporting, and §500.4 disclosures, plus annual penetration testing and tabletop exercise
If your program rests on the MSP's word, on a policy document that hasn't been opened in eighteen months, or on the assumption that an examiner won't ask for evidence — the conversation worth having is whether continuous evidence production costs less than the deficiency it prevents.
The BrainTrust starts free — the library's rule summaries and templates are maintained as regulations change.
Useful Compliance References
SEC
NYDFS
State Regulators
Frequently asked questions
Which cybersecurity regulations apply to SEC-registered investment advisers?
The core SEC rules are Rule 206(4)-7 (the compliance program rule), Regulation S-P (privacy, safeguards, and incident response), Regulation S-ID (identity theft red flags), and Rule 204-2 (books and records). Broker-dealers are additionally subject to FINRA rules including 3110, 3120, 4370, 4530, and 3310. Firms operating under a New York Department of Financial Services authorization may also be covered by 23 NYCRR Part 500.
What is the Regulation S-P breach notification deadline?
Under the 2024 amendments to Regulation S-P, a covered firm must notify affected individuals no later than 30 days after it becomes aware of an incident in which sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization.
When did the 2024 Regulation S-P amendments take effect?
The amendments became effective August 2, 2024, with tiered compliance deadlines. Larger entities — RIAs with $1.5 billion or more in assets under management, investment companies with $1 billion or more in net assets, and broker-dealers with $500,000 or more in net capital — had until December 3, 2025. Smaller entities, including RIAs under $1.5 billion in AUM, had until June 3, 2026. Both dates have now passed, so the amended rule is fully in effect for all covered institutions regardless of size.
What does SEC Rule 206(4)-7 require for cybersecurity?
Rule 206(4)-7 requires every SEC-registered investment adviser to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act, to review them at least annually for adequacy and effectiveness, and to designate a Chief Compliance Officer to administer the program. Applied to cybersecurity, that means a written, current, annually tested compliance program supported by operational controls that produce evidence the policy is actually in force.
Does Regulation S-ID apply to RIAs?
Regulation S-ID applies to RIAs that offer or maintain 'covered accounts' — generally accounts that permit multiple payments or transfers, such as those that let clients move funds. Those firms must maintain a written Identity Theft Prevention Program that identifies the relevant red flags, describes how the firm detects them, and defines the firm's response, and they must update it periodically.