SEC Cybersecurity Rules for RIAs: What Financial Advisors Need to Do Now

Dark financial data chart on screen

The SEC’s cybersecurity risk management rules for investment advisers, adopted in 2023, represent the most significant federal cybersecurity mandate affecting registered investment advisors to date. Unlike earlier guidance — which was advisory — these rules impose specific obligations with examination and enforcement consequences. Many smaller RIAs have been slow to respond, either assuming the rules are primarily aimed at large broker-dealers or underestimating the compliance burden involved. That assumption is worth revisiting.

Who the Rules Apply To

The SEC’s cybersecurity rules apply to investment advisers registered with the SEC — generally those managing $100 million or more in assets under management, as well as certain advisers below that threshold who are required to register with the SEC based on other criteria. Advisers registered solely with state regulators (generally those with AUM below $100 million) are subject to their state’s rules rather than the federal rule directly, though many states are adopting similar requirements. If you are a Boston-area RIA registered with the SEC, the federal rule applies to you regardless of firm size within that registered population.

What the Rules Require

The core obligations under the SEC’s cybersecurity rule for investment advisers include:

  • Written cybersecurity policies and procedures: Advisers must adopt and implement written policies and procedures reasonably designed to address cybersecurity risks that could harm clients or their information. These aren’t templates — they need to reflect how your firm actually operates, what data you hold, and what systems you use.

  • Cybersecurity risk assessment: The policies must include provisions for assessing cybersecurity risks — identifying the systems and data that matter most to your clients, the threats those assets face, and the controls in place to address them.

  • Annual review: Advisers must review and assess the design and effectiveness of their cybersecurity policies and procedures at least annually and after any significant change to their operations or systems. The review must be documented.

  • Incident response: Policies must address how the firm will detect, respond to, and recover from cybersecurity incidents — including preventing unauthorized access or use of client information and restoring affected systems and operations.

  • Recordkeeping: Advisers must maintain records related to their cybersecurity program, including the policies and procedures themselves, risk assessments, annual reviews, and documentation of any significant cybersecurity incidents.

Disclosure: What You Have to Report and When

The disclosure component is where many advisers are underprepared. The SEC’s rules require that advisers report significant cybersecurity incidents to the SEC promptly — the specific notification timeframe and mechanics were part of the rules as adopted, and advisers should verify the current operative requirements with compliance counsel. In addition, advisers are required to include cybersecurity-related information in their Form ADV filings — disclosing material cybersecurity risks and any significant cybersecurity incidents that occurred in the current or prior two fiscal years. This means your annual ADV update is now also a cybersecurity disclosure document. Clients and prospective clients reviewing your ADV can see whether you’ve had a material incident and how you’ve characterized your risk posture.

Where Small RIAs Typically Fall Short

  • No written cybersecurity policies at all, or policies borrowed from a template that don’t reflect the firm’s actual systems, vendors, or client data

  • No documented risk assessment — principals of small firms often understand their systems informally, but informal understanding doesn’t satisfy the documentation requirement

  • Annual review has never happened — the policies were adopted once and have sat unchanged even as the firm’s technology, vendors, and staff have changed

  • Incident response plan doesn’t exist or hasn’t been tested — many advisers have no documented sequence of steps for what to do if their email is compromised, their CRM is breached, or their client data is exfiltrated

  • Form ADV cybersecurity disclosure hasn’t been updated to reflect the current rules — advisers are still filing the same generic language that preceded the rule’s adoption rather than the substantive disclosure now required

What a Compliant Posture Looks Like

For a small RIA, compliance doesn’t require a security operations center or a dedicated CISO. It requires written policies that reflect your actual environment, a documented risk assessment, evidence of an annual review, and an incident response plan with names attached to roles. Those documents need to be real — not filed and forgotten, but reviewed, updated when the firm’s technology or operations change, and available to produce in an SEC examination. Given that cybersecurity is now an explicit examination priority for the SEC, advisers who treat this as optional are taking an increasingly visible risk.

DataMoat works with Boston-area financial advisory firms to build the cybersecurity documentation and controls the SEC now requires — proportionate to the size and complexity of a small RIA rather than built for a large broker-dealer. If your firm’s cybersecurity program hasn’t been updated to reflect the current rule, a compliance gap assessment is a practical place to start.

Shape

Direct Access, Real Answers.

Not Sure Where to Start? Let’s Find Out Together.

Most practices don’t know their actual risk exposure until someone looks. A free consultation tells you exactly where you stand — no commitment, no pressure.

Shape

Direct Access, Real Answers.

Not Sure Where to Start? Let’s Find Out Together.

Most practices don’t know their actual risk exposure until someone looks. A free consultation tells you exactly where you stand — no commitment, no pressure.

Shape

Direct Access, Real Answers.

Not Sure Where to Start? Let’s Find Out Together.

Most practices don’t know their actual risk exposure until someone looks. A free consultation tells you exactly where you stand — no commitment, no pressure.