Back to Insights

    Cybersecurity Compliance: 2025 Best Practices for RIAs

    Essential cybersecurity protocols, incident response plans, and SEC examination focus areas for investment advisors in the current threat landscape.

    NextReg Compliance Team
    January 3, 2025
    9 min read
    Cybersecurity protection and digital security protocols

    The Evolving Cyber Threat Landscape

    Cybersecurity threats facing investment advisers have intensified dramatically in recent years, with sophisticated attacks targeting client data, financial assets, and operational systems. The 2024 SEC examination priorities again highlighted cybersecurity as a critical focus area, reflecting regulatory concern about advisers' preparedness for evolving threats including ransomware, phishing, business email compromise, and insider threats.

    The financial services industry remains a prime target for cybercriminals due to the valuable data advisers maintain and the potential for direct theft of client funds. Successful breaches can result in significant financial losses, regulatory sanctions, reputational damage, and client lawsuits. As cyber threats grow more advanced and persistent, advisers must continuously strengthen their cybersecurity programs to protect client information and assets.

    The SEC's cybersecurity rule, adopted in 2023 and fully effective in 2024, establishes specific requirements for policies, procedures, incident response, and annual reviews. Compliance with this rule, combined with implementation of industry best practices, provides the foundation for effective cyber risk management.

    Core SEC Cybersecurity Requirements

    The cybersecurity rule requires advisers to adopt written policies and procedures reasonably designed to address cybersecurity risks. These policies must cover risk assessment processes, user access controls and authentication, data encryption and protection, system monitoring and threat detection, incident response procedures, vendor management and due diligence, employee training and awareness, and business continuity and disaster recovery planning.

    Advisers must conduct annual reviews of their cybersecurity policies to ensure they remain current and effective given evolving threats and business changes. This review should be documented and address whether the policies adequately identify and mitigate cyber risks, whether technological and organizational changes require policy updates, whether incidents or near-misses revealed program weaknesses, and whether employee training proved effective.

    The rule also requires prompt reporting of significant cybersecurity incidents to the SEC. While defining what constitutes a "significant" incident involves facts and circumstances analysis, advisers should establish clear escalation procedures to evaluate potential incidents quickly and determine reporting obligations.

    Essential Security Controls and Protocols

    Effective cybersecurity programs implement multiple layers of defense protecting against unauthorized access, data breaches, and operational disruptions. Core technical controls include multi-factor authentication for all system access, encryption of data in transit and at rest, network segmentation and access controls, endpoint protection and anti-malware software, regular security patching and updates, secure backup and recovery systems, and email filtering and anti-phishing protections.

    Multi-factor authentication has become particularly critical as a defense against credential theft and unauthorized access. The SEC expects advisers to implement MFA not just for client-facing systems but also for employee access to internal networks, email accounts, and administrative systems. Password-only authentication is no longer considered adequate for protecting sensitive systems or data.

    Data encryption protects information confidentiality if devices are lost, stolen, or improperly accessed. Advisers should encrypt laptops, mobile devices, portable storage media, and backup systems. Additionally, data transmitted over networks should use secure, encrypted protocols particularly when accessing systems remotely or transferring client information.

    Regular security assessments help identify vulnerabilities before attackers exploit them. This includes vulnerability scanning of networks and systems, penetration testing to evaluate defensive effectiveness, review of system configurations and security settings, assessment of user access rights and privileges, and evaluation of third-party vendor security practices.

    Incident Response Planning

    Well-designed incident response plans enable advisers to react quickly and effectively when cyber incidents occur, minimizing damage and facilitating recovery. Response plans should establish clear roles and responsibilities, decision-making authority during incidents, communication protocols internally and with external parties, procedures for containing and eradicating threats, processes for preserving evidence and documentation, and steps for restoring normal operations.

    The response plan should address various incident types including ransomware attacks, data breaches exposing client information, business email compromise or wire fraud, denial of service attacks, insider threats or unauthorized access, and vendor or third-party compromises. Each scenario may require different response actions and notification procedures.

    Advisers should identify in advance the external resources they may need during incidents such as forensic investigators, legal counsel specializing in cyber incidents, public relations or crisis communication firms, cyber insurance carriers, and law enforcement contacts. Having these relationships established before incidents occur speeds response and improves outcomes.

    Regular testing through tabletop exercises or simulations helps validate response plans and train personnel. These exercises should involve relevant staff including senior management, IT personnel, compliance, legal, and communications teams. Post-exercise reviews identify plan gaps or areas needing enhancement.

    Vendor Management and Third-Party Risk

    Investment advisers rely extensively on third-party service providers for portfolio management systems, client relationship management, custodial services, data storage and backup, and other critical functions. These vendor relationships create cybersecurity risks since breaches at service providers can expose adviser and client data or disrupt operations.

    The SEC expects advisers to conduct due diligence on vendors' cybersecurity practices before engagement and to monitor vendor security on an ongoing basis. Due diligence should assess vendor security policies and controls, data protection and encryption practices, incident response capabilities, business continuity planning, insurance coverage, regulatory compliance history, and audit reports or certifications such as SOC 2.

    Vendor contracts should include provisions addressing data security requirements, rights to audit vendor security controls, incident notification obligations, data ownership and return upon termination, and liability for breaches or failures. Advisers should also establish procedures for monitoring significant vendor incidents or security failures that may affect adviser systems or data.

    Employee Training and Awareness

    Human error remains a leading cause of cybersecurity incidents. Employees who fall victim to phishing emails, use weak passwords, mishandle sensitive data, or violate security protocols create vulnerabilities attackers exploit. Regular, effective training reduces these risks by building security awareness and promoting safe practices.

    Training programs should address recognizing and reporting phishing attempts, creating strong passwords and using password managers, protecting devices and data when working remotely, identifying and escalating security concerns, understanding data classification and handling requirements, and following incident reporting procedures. Training should occur at onboarding and regularly thereafter, with additional sessions when threats evolve or incidents occur.

    Simulated phishing campaigns test employee vigilance and identify individuals needing additional training. These simulations should track metrics such as phishing click rates, reporting rates, and improvement trends over time. Results inform training priorities and help measure program effectiveness.

    Key Takeaways for RIAs

    • The SEC cybersecurity rule requires written policies, annual reviews, and incident reporting for significant cyber events.
    • Multi-factor authentication, encryption, and layered security controls provide essential protection against common attack vectors.
    • Incident response plans with clear roles, procedures, and external resources enable effective reaction to cyber events.
    • Vendor due diligence and ongoing monitoring help manage third-party cybersecurity risks.
    • Regular employee training and simulated phishing reduce risks from human error and social engineering attacks.
    • Annual cybersecurity reviews should assess program effectiveness and incorporate lessons from incidents and threat evolution.
    • Cyber insurance provides financial protection but requires careful policy review to understand coverage and exclusions.