Category: SEC Regulations: Reg S-P & Reg S-ID
-
The Camera on Your Analyst’s Face: Why Smart Glasses Have No Place Near Client Data
Camera-equipped glasses that look like ordinary Ray-Bans now sit at your workstations, recording screens, credentials, and conversations to a consumer cloud you do not control. Why it is a foreseeable risk under Reg S-P and Rule 206(4)-7 — and the one-paragraph prohibition that closes the gap.
-
Employees From Hell: What Disgruntled Insiders Actually Do, and How to Survive It
The insider threat at a financial firm is not usually a spy. Six attack patterns from the adversary point of view — grounded in the CISA framework and mapped to the rules an examiner will hold you to.
-
KerberRose Wealth Management Breach Post Mortem: One Inbox, 27,000 People
One compromised employee mailbox at a wealth management firm reached a backup holding 27,076 clients’ Social Security and bank details. A breach teardown — and what amended Reg S-P now expects on identity, backup segmentation, and the 30-day notice clock.
-
Is a Remote CISO for You?
A five-sign self-assessment for RIA compliance officers — when a fractional Remote CISO closes the cybersecurity accountability gap the amended Reg S-P now assumes, at a fraction of a full-time hire.
-
The Reg S-P Deadline Just Passed for Small Firms. Here’s What Examiners Ask For First.
The June 3 compliance date for the amended Regulation S-P has passed for smaller firms. The five documents an examiner will request first — and the 30-day clock most incident response plans still don’t mention.
-
The Wire Transfer Call-Back: The Procedure That Stops One of the Most Preventable RIA Losses
The fraudulent wire request arrives in a genuine thread, from the genuine address, referencing genuine details. The only control that catches it is one that never trusts email at all.
-
You Can’t Protect Data You Haven’t Mapped
Every safeguards obligation shares one silent prerequisite: knowing where customer information actually lives. A five-column worksheet beats a data-governance platform — if it gets maintained.
-
Your Identity Theft Red Flags Program Is Probably a Dead Document
Regulation S-ID requires a written Identity Theft Prevention Program — but the SEC now treats identity theft as a cyber-first risk. Why most Red Flags programs are static documents that no longer survive an exam, and how to fix them.
-
“We Have a Plan” Is Not the Same as “We Tested It”: Incident Response Tabletops for RIAs
The amended Regulation S-P requires a workable incident response program — and the SEC judges incident response by how a firm reacts, not what is in the binder. What a tabletop exercise is, why it matters, and what evidence of testing looks like.
-
The New SEC Regulation S-P Amendments: What Every RIA Needs to Know
A plain-language briefing on the 2024 Regulation S-P amendments: the written incident response program, the 30-day notification clock, 72-hour vendor breach standard, expanded definitions, and five-year recordkeeping.