SEC and FINRA cybersecurity examinations have increased significantly since 2023. Examiners now arrive with specific technical questions — not just policy reviews. This checklist covers the 12 controls most frequently cited in deficiency letters to small RIAs and independent advisors. Each item includes what to implement and what documentation satisfies an examiner.
A written information security policy exists covering client data protectionRegulation S-P requires a written privacy and safeguards policy. SEC examiners request this document on arrival — if you can't produce it, the examination starts poorly.Most common gap
Policy reviewed and updated annually — dated and signed by a principalAn undated or unchanged policy from 3 years ago signals to examiners that security is not actively managed.
All laptops storing client data have full-disk encryption enabled (BitLocker / FileVault)A lost unencrypted laptop containing client portfolio data is a reportable breach under Regulation S-P. This is the single most common technical gap in small advisory firms.Most common gap
Client data transmitted via email uses encrypted channels or a secure client portalSending account statements or financial plans as unencrypted email attachments does not meet the standard. Use a FINRA-compliant portal or encrypted email service.
Encryption status of all devices documented and verified quarterlyKnowing encryption is enabled is different from verifying it. Run a status report and save it.
MFA enabled on all email accountsEmail is the most common entry point for account takeover. MFA on email alone blocks the majority of credential-based attacks.Frequently cited
MFA enabled on CRM, portfolio management, and financial planning systemsRedtail, Wealthbox, Orion, eMoney, MoneyGuidePro — each system with client data needs MFA. A single gap is all it takes.
MFA enabled on custodian portals (Schwab, Fidelity, TD, etc.)Custodians increasingly require MFA, but verify it is actually enforced on your accounts — not just offered as an option.
Access to client data limited to staff who need it for their roleAdministrative staff may not need access to full portfolio data. Document who has access to what and review when roles change.
Departed employee access revoked immediatelyFormer staff with active CRM or email access is a common deficiency. Document your offboarding checklist.Frequently cited
Vendor and contractor access reviewed annuallyThird-party consultants, tech vendors, and compliance consultants with system access should be reviewed and revoked when the engagement ends.
Written business continuity plan (BCP) exists — FINRA Rule 4370 requires thisThe BCP must address: data backup location, alternate office arrangements, client communication during an outage, and succession if a principal is unavailable.FINRA Required
Client data backed up daily with off-site or cloud copyAn on-site-only backup is destroyed in the same disaster as your primary system. The 3-2-1 rule applies: 3 copies, 2 media types, 1 off-site.
BCP tested annually — test result documentedAn untested BCP is a policy document, not a continuity plan. Examiners ask when you last tested it and what the result was.
Written contracts with all vendors who access client dataYour IT provider, cloud storage vendor, and technology consultants must have contracts requiring appropriate data safeguards. Verbal agreements do not satisfy examiners.
Vendor list reviewed annually — include their security posture in due diligenceAsk new vendors for their SOC 2 report or security attestation before granting access to client systems.
SEC examination reality: Since 2023, SEC cybersecurity examinations for RIAs under $1B AUM routinely include a technical review — not just a policy review. Examiners now ask to see encryption status reports, MFA configuration screenshots, and access logs. Having a policy that says "we encrypt everything" without documentation of the actual configuration is treated as a deficiency.
Date completed
___________