\n\n

As of June 3, 2026, smaller registered investment advisers (RIAs) must now comply with significant amendments to Regulation S-P (“Reg S-P”), the Securities and Exchange Commission’s primary rule governing the protection of customer records and information.

The undertakings are significant and may require organizations now subject to the rule to take a close, resource-intensive look at their security practices.   This marks an important shift for smaller RIAs that have not previously had to adhere to more rigorous cybersecurity regulations.

Firms that have not yet reviewed their policies, procedures, and incident response capabilities, or created robust governance and internal documentation protocols, should do so promptly, as the SEC has signaled that compliance with the amended rule will be an examination priority.

What Is Regulation S-P?

Reg S-P is the SEC’s rule obligating organizations governed by the rule to protect customer data.  Reg S-P implements portions of the Gramm-Leach-Bliley Act (which governs financial institutions) and requires broker-dealers, investment companies, and registered investment advisers to adopt written policies and procedures designed to safeguard sensitive customer records and information.

Under the amended rule, “sensitive customer information” extends beyond obvious identifiers such as Social Security numbers, driver’s license numbers, passport numbers, and financial account credentials. It also includes any customer information that could reasonably be used to gain access to a customer’s account or facilitate identity theft, fraud, or other harm. In practice, firms should think broadly about what information they collect and maintain. Customer account numbers, login credentials, security questions and answers, tax identification numbers, and combinations of otherwise innocuous personal information may all qualify if unauthorized access could create a risk of misuse. The SEC intentionally adopted a broad definition to account for evolving cyber threats and the many ways bad actors can exploit customer information.

In 2024, the SEC adopted amendments intended to modernize the rule in response to evolving cybersecurity risks. The amendments expand requirements related to incident response, customer notification, service provider oversight, and recordkeeping.

The amendments have been implemented on a staggered basis depending on type of organization:  they became effective for “large” RIAs as of December 2025.  June 3, 2026, marked the compliance deadline for smaller entities, including RIAs managing less than $1.5 billion in assets.

Core Requirement: Incident Reporting and a Written Incident Response Program

Two cornerstones of the rule are (1) the requirement to report a cybersecurity incident involving sensitive customer data, and (2) the requirement to maintain and implement a written Incident Response Program (IRP).

Prior to the amended Reg, RIAs suffering an incident did not have a specific notification obligation in the event of a security breach (although applicable state laws, other federal or foreign laws, or contractual obligations might still apply). With the amended rules, RIAs must report to individuals within 30 days of becoming aware of a compromise of sensitive customer information that could lead to a risk of harm. This requirement sits in parallel with other breach notification requirements (although note that many state breach notification laws will defer to compliance with federal obligations in certain circumstances). While an earlier version of the amended rule also included notification to the SEC, the final rule does not create such an obligation.

This requirement means organizations should ensure that legal, compliance, information technology, and cybersecurity personnel are aligned before an incident occurs. Delays in identifying affected information, engaging forensic investigators, or coordinating internal decision-making can make compliance significantly more difficult.

The requirement of maintaining an IRP is an important component of cybersecurity risk management and is meant to minimize the fallout from an incident.  An IRP is a documented framework that helps an organization prepare for, identify, respond to, and recover from cybersecurity incidents involving unauthorized access to or use of customer information. The program should establish clear roles and responsibilities, outline response procedures, and provide a roadmap for communicating with customers, regulators, vendors, and other stakeholders during an incident.

Importantly, the amendments require firms to not only to have written procedures, but also to be able to operationalize them when an incident occurs.

Crafting a Compliant IRP

At a minimum, firms should ensure their Incident Response Program addresses the following:

✓ Designate an incident response team and define responsibilities.

✓ Establish procedures to identify and assess cybersecurity incidents.

✓ Implement processes to determine whether sensitive customer information has been accessed or used without authorization.

✓ Develop procedures to contain affected systems and prevent further compromise.

✓ Create remediation and recovery protocols to restore systems and operations.

✓ Maintain procedures for investigating incidents and documenting findings.

✓ Establish processes for notifying affected customers when required.

✓ Review and update contracts with third-party service providers to address cybersecurity incidents and notification obligations.

✓ Conduct regular tabletop exercises and testing of response procedures.

✓ Maintain records demonstrating compliance with Regulation S-P requirements.

Service Provider Oversight is a Key Risk Management Requirement

The SEC has also placed increased emphasis on third-party risk management.

Many cybersecurity incidents originate with vendors, cloud providers, software platforms, or other service providers that maintain customer information on behalf of regulated firms. The amended rule makes clear that RIAs remain responsible for protecting customer information even when those functions are outsourced.

Firms should review vendor management programs, contractual notification provisions, and incident reporting requirements to ensure they can meet their obligations if a service provider experiences a cybersecurity event.

What the SEC Is Watching: Early Enforcement Signals

Despite having not yet announced a dedicated sweep focused on the amended requirements, the SEC recent compliance outreach initiatives and examination priorities suggest that cybersecurity governance, customer information safeguards, incident response planning, and vendor oversight will receive heightened scrutiny.  Early enforcement actions provide a window into these priorities.

In January 2025, for example, Robinhood Securities LLC and Robinhood Financial LLC agreed to pay $45 million in combined civil penalties after the SEC determined, among other things, that the firms violated both Rule 30(a) of Regulation S-P by failing to safeguard customer information, and Rule 201 of Regulation S-ID by failing to maintain adequate identity theft prevention programs. The SEC emphasized that broker-dealers must “satisfy their legal obligations” when carrying out their market functions, including obligations to protect customer data.

In November 2025, the SEC announced a settlement with M Holdings Securities, Inc., a broker-dealer and investment adviser, which the SEC alleged violated Rule 30(a) of Regulation S-P. According to the SEC, M Holdings did not have any written policies and procedures to govern information security across its member firms.

For many firms, compliance with the amended Regulation S-P will require more than updating a policy manual. Effective compliance depends on coordination among compliance personnel, legal counsel, information technology teams, cybersecurity professionals, and third-party vendors.  And as always, documented policies and procedures should match actual practice.  To that end, organizations cannot just “set it and forget it”:  developing a robust governance program compliant with Reg S-P also means developing training programs and periodically assessing effectiveness and material changes to practices and risk posture.

Organizations should also remember that Regulation S-P does not exist in isolation. A cybersecurity incident may simultaneously trigger obligations under state data breach notification laws, contractual commitments to clients or business partners, insurance policy requirements, and other federal or international privacy regimes. An effective incident response program should account for these overlapping obligations and establish procedures for evaluating them quickly when an incident occurs.

Whether you are a newly covered small RIA or a larger organization seeking to strengthen your cybersecurity and privacy compliance program, proactive planning can help reduce regulatory risk and improve preparedness when an incident occurs.

With Sadie Keller.  Originally Posted on Anderson & Kreiger’s Privacy, Cybersecurity & AI Blog.