The Deadline That Already Passed
For two years, the SEC’s amended Regulation S-P was something smaller advisory firms could plan around. The amendments became effective in August 2024 with a phased compliance schedule: larger entities had to comply by December 3, 2025, and smaller entities — including registered investment advisers with under $1.5 billion in assets under management — had until June 3, 2026.
That date has passed. If you run an RIA, the amended rule now applies to you in full, and it asks for something categorically different from what most small firms’ compliance programs were built to produce. The SEC has also identified Reg S-P compliance as an examination priority for fiscal 2026, which means the first question is no longer whether the obligation applies. It is whether you can demonstrate it.
What the Amended Rule Actually Requires
The amendments transformed Reg S-P from a policies-and-safeguards rule into an operational one. Four obligations matter most for a small adviser.
A written incident response program
Not a paragraph in your compliance manual — a program with procedures to detect, respond to, and recover from unauthorized access to or use of customer information, including assessing the nature and scope of an incident, containing and controlling it, and preventing further unauthorized access.
Thirty-day customer notification
If sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, you must notify affected individuals as soon as practicable — and no later than 30 days after becoming aware of the incident. The clock runs from awareness, and the notice must describe the incident, the data involved, and what customers can do to protect themselves. The obligation extends to sensitive information you hold about customers of other financial institutions, not only your own.
Service provider oversight
Your custodians, portfolio-management platforms, CRM, performance reporting tools, and IT vendors must be covered by policies reasonably designed to ensure they protect customer information and notify you of breaches at their end promptly — the rule contemplates notification within 72 hours — so your 30-day clock can start on time. For most small RIAs, the majority of customer data lives on someone else’s infrastructure, which makes this the obligation with the widest practical gap between the contract language and reality.
Safeguards, disposal, and records
Administrative, technical, and physical safeguards for customer information; secure disposal of consumer report information; and written records documenting compliance. That last clause deserves emphasis: the rule expects you to be able to show the program operating, not merely assert that it exists.
The Four Clocks You Are Now Running
- 0 hours — Awareness. Everything downstream starts here, and nothing in a compliance manual generates it.
- 72 hours — Vendor notice. The window the rule contemplates for a service provider to tell you they were breached.
- 30 days — Customer notice. From your awareness, not from the intrusion. A compromise you detect late does not extend the deadline; it consumes it.
- Indefinite — The examination. Reg S-P is an SEC exam priority for fiscal 2026. Records demonstrating the program operated are what an examiner asks for.
The Word That Breaks the Model Is “Detect”
Most sub-$500M RIAs run compliance the same way, and it is a sensible way to run it: an outside consultant maintains the manual, conducts the annual review, files the ADV, and keeps the firm current on rule changes. The model works because most adviser obligations are satisfied by documents, disclosures, and periodic review.
The amended Reg S-P is not satisfied by documents. Look at the obligations again and notice what they quietly assume:
- You cannot notify customers within 30 days of becoming aware of unauthorized access unless something in your environment is positioned to make you aware.
- You cannot assess the scope of an incident without records of what actually happened — which accounts were touched, from where, and when.
- You cannot contain an intrusion you have not identified.
- You cannot demonstrate the program operated if the only artifact it produces is the document describing it.
An incident response program with no detection capability behind it is a fire evacuation plan for a building with no smoke alarms: perfectly drafted, correctly filed, and completely inert. The plan is not the control. The plan describes what happens after the control fires.
This is where the small-firm math gets uncomfortable. Detection is a continuous function, not a periodic one. Attackers who target advisory firms — and they do, because where advisers sit, money moves on emailed instructions and client data has direct resale value — work nights and weekends by preference, precisely because that is when nobody is looking.
The compromise that matters usually looks small at first. A sign-in from an unfamiliar location. A mail-forwarding rule quietly added to a principal’s mailbox. Credentials tested against your accounts at 2 a.m. in a slow, low-volume pattern designed not to trip lockout thresholds. A workstation that starts making outbound connections it has never made before. None of these is dramatic. All of them are the early phase of something that is.
A consultant reviewing quarterly cannot see any of it — not because of any failing on their part, but because the artifacts they review are not the artifacts where this appears. An IT provider patching servers and resetting passwords is not looking for it either; keeping systems running and keeping systems watched are different jobs with different economics. And staffing analysts to watch around the clock is a mid-six-figure commitment no small RIA can justify against its revenue.
So most firms are now carrying a mandatory obligation with no operational capability behind it. That gap resolves in one of two ways: an examiner surfaces it during a routine review, or an incident surfaces it at the worst possible moment. The SEC did not amend this rule to collect better manuals.
What the Gap Looks Like in Practice
Consider a twelve-person RIA with $340 million under management. The principal’s email credentials are phished through a fake custodian login page on a Thursday evening. Over the next eleven days:
- The attacker signs in from an unfamiliar IP address — an event logged by the firm’s cloud email platform, and reviewed by no one.
- A forwarding rule is created, sending copies of everything to an external address. Logged. Not reviewed.
- The attacker reads client correspondence, learns which clients are mid-transfer, and downloads statements containing account numbers, balances, and Social Security numbers.
- A distribution request is sent to the custodian from the principal’s real mailbox, referencing a real client and a real balance, with updated banking instructions.
The custodian’s callback procedure catches the distribution — this time. That is the good outcome, and it is where most firms stop thinking about the incident. But the good outcome still leaves the firm with a full Reg S-P event: sensitive customer information for an indeterminate number of clients was reasonably likely accessed without authorization. Now the CCO must determine which clients, based on eleven days of mailbox activity nobody recorded in a usable form, and notify them within 30 days of the moment the firm became aware.
The cost of not detecting the intrusion on day one is not measured in the distribution that was blocked. It is measured in the scoping exercise that follows, the notification the firm may have to send to every client because it cannot prove a narrower scope, and the examination question about why eleven days of anomalous access produced no response.
Why Late Detection Costs More Than the Breach
- Scope you cannot narrow becomes scope you must assume. Without records of what was accessed, the defensible notification is the broad one — every client, not the four who were actually exposed.
- The 30-day clock does not care when you started looking. Awareness on day 11 leaves the same 30 days as awareness on day 1, with eleven more days of activity to reconstruct.
- Client notification is a business event, not just a filing. At a twelve-person firm, it is a phone call to every relationship you have.
- The examiner’s question is about the gap, not the attacker. “Your logs show this. What did your program do?”
What Intruex Does About It
Intruex is an AI security operations platform: a coordinated team of specialist AI analysts that connects to the security tools and logs you already have — leading endpoint and cloud security platforms among them, or nearly any log source via a standards-based interface — and investigates every alert your environment produces, continuously.
Mapped to the rule:
- Detection, operationalized. Every alert is triaged, enriched with threat intelligence, and dispositioned with a confidence level and plain-language reasoning — in minutes, not at next quarter’s review. The precursors of an advisory-firm breach — suspicious logins, impossible travel, mailbox rule changes, credential attacks, malware on a workstation — are exactly the categories the platform’s specialist analysts cover.
- Awareness that starts your clock on your terms. When evidence indicates real compromise, your designated contacts are notified immediately with a complete investigation package: what happened, which systems and accounts are affected, and what the evidence shows. That package is precisely the input your incident response program needs to assess scope, contain the incident, and — if it comes to it — draft an accurate customer notice well inside 30 days, covering the clients who were actually affected rather than every client you have.
- The paper trail regulators actually want. Every verdict carries a full, replayable record: what was examined, what was found, what action was taken and by whom. Your written program stops describing a hypothetical process and starts describing a running one, with evidence attached. Intruex also maps monitoring activity to major control frameworks, so demonstrating your safeguards during an examination is a report you pull rather than a project you run.
- Coverage that includes the vendor edge. Much of your customer data sits with service providers, but the access to it usually runs through identities and endpoints you control. Monitoring authentication and access patterns against those platforms is how a service-provider problem becomes visible on your side rather than arriving as a letter.
- Humans stay in charge. Response is recommendation-first and approval-gated. The only autonomous behavior — closing high-confidence benign alerts — is opt-in, threshold-controlled, and fully audited. Your firm keeps accountability where the rule puts it; the platform removes the noise around it.
Your compliance consultant remains essential — someone has to own the written program, run the annual review, maintain the vendor oversight documentation, and manage the regulatory relationship. Intruex is the operational half that the amended rule now assumes exists: the part that detects, so that the part that responds has something to respond to.
What to Do Before Your Next Exam
- Read your own incident response program and find the word “detect.” Then identify, by name, the system and the person that make detection real. If you cannot, that is the finding an examiner will write.
- Confirm logging is enabled and retained on your email tenant, portfolio system, CRM, and remote access. Retention shorter than your likely detection lag makes scoping impossible.
- Inventory every service provider that touches customer information and check the actual breach notification terms in each contract against the 72-hour expectation.
- Audit all mailboxes for forwarding and inbox rules, and alert on new ones. This single control addresses the most common adviser compromise pattern.
- Enforce phishing-resistant MFA on email and custodian access before anything else.
- Run one tabletop exercise against the 30-day clock. Start it at “we just learned a mailbox was compromised eleven days ago” and see how far your program gets.
Fiduciary Duty Was Already the Reason
The deadline makes this urgent, but it was never really about the deadline. Your clients gave you the two things attackers most want: their money and their information. They did that on the strength of a relationship, usually with one or two named people, at a firm they chose specifically because they would not be a number.
A breach at a twelve-person RIA does not read to those clients the way a breach at a wirehouse reads. It does not land as an institutional failure covered by an institutional apology. It lands as a betrayal by the people they picked because they would be looked after.
The rule now requires what fiduciary duty always implied. The difference is that today, a firm your size can actually afford to do it.
Sources: SEC, Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information, final amendments (effective August 2, 2024; compliance dates December 3, 2025 for larger entities and June 3, 2026 for smaller entities, including registered investment advisers with under $1.5 billion in assets under management). SEC Division of Examinations fiscal 2026 priorities. The scenario described is a composite drawn from publicly documented compromise patterns against advisory firms, not a specific incident. This article is informational and is not legal or compliance advice.