The Deadline That Already Passed

For two years, the SEC’s amended Regulation S-P was something smaller advisory firms could plan around. The amendments became effective in August 2024 with a phased compliance schedule: larger entities had to comply by December 3, 2025, and smaller entities — including registered investment advisers with under $1.5 billion in assets under management — had until June 3, 2026.

That date has passed. If you run an RIA, the amended rule now applies to you in full, and it asks for something categorically different from what most small firms’ compliance programs were built to produce. The SEC has also identified Reg S-P compliance as an examination priority for fiscal 2026, which means the first question is no longer whether the obligation applies. It is whether you can demonstrate it.

What the Amended Rule Actually Requires

The amendments transformed Reg S-P from a policies-and-safeguards rule into an operational one. Four obligations matter most for a small adviser.

A written incident response program

Not a paragraph in your compliance manual — a program with procedures to detect, respond to, and recover from unauthorized access to or use of customer information, including assessing the nature and scope of an incident, containing and controlling it, and preventing further unauthorized access.

Thirty-day customer notification

If sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, you must notify affected individuals as soon as practicable — and no later than 30 days after becoming aware of the incident. The clock runs from awareness, and the notice must describe the incident, the data involved, and what customers can do to protect themselves. The obligation extends to sensitive information you hold about customers of other financial institutions, not only your own.

Service provider oversight

Your custodians, portfolio-management platforms, CRM, performance reporting tools, and IT vendors must be covered by policies reasonably designed to ensure they protect customer information and notify you of breaches at their end promptly — the rule contemplates notification within 72 hours — so your 30-day clock can start on time. For most small RIAs, the majority of customer data lives on someone else’s infrastructure, which makes this the obligation with the widest practical gap between the contract language and reality.

Safeguards, disposal, and records

Administrative, technical, and physical safeguards for customer information; secure disposal of consumer report information; and written records documenting compliance. That last clause deserves emphasis: the rule expects you to be able to show the program operating, not merely assert that it exists.

The Four Clocks You Are Now Running

  • 0 hours — Awareness. Everything downstream starts here, and nothing in a compliance manual generates it.
  • 72 hours — Vendor notice. The window the rule contemplates for a service provider to tell you they were breached.
  • 30 days — Customer notice. From your awareness, not from the intrusion. A compromise you detect late does not extend the deadline; it consumes it.
  • Indefinite — The examination. Reg S-P is an SEC exam priority for fiscal 2026. Records demonstrating the program operated are what an examiner asks for.

The Word That Breaks the Model Is “Detect”

Most sub-$500M RIAs run compliance the same way, and it is a sensible way to run it: an outside consultant maintains the manual, conducts the annual review, files the ADV, and keeps the firm current on rule changes. The model works because most adviser obligations are satisfied by documents, disclosures, and periodic review.

The amended Reg S-P is not satisfied by documents. Look at the obligations again and notice what they quietly assume:

An incident response program with no detection capability behind it is a fire evacuation plan for a building with no smoke alarms: perfectly drafted, correctly filed, and completely inert. The plan is not the control. The plan describes what happens after the control fires.

This is where the small-firm math gets uncomfortable. Detection is a continuous function, not a periodic one. Attackers who target advisory firms — and they do, because where advisers sit, money moves on emailed instructions and client data has direct resale value — work nights and weekends by preference, precisely because that is when nobody is looking.

The compromise that matters usually looks small at first. A sign-in from an unfamiliar location. A mail-forwarding rule quietly added to a principal’s mailbox. Credentials tested against your accounts at 2 a.m. in a slow, low-volume pattern designed not to trip lockout thresholds. A workstation that starts making outbound connections it has never made before. None of these is dramatic. All of them are the early phase of something that is.

A consultant reviewing quarterly cannot see any of it — not because of any failing on their part, but because the artifacts they review are not the artifacts where this appears. An IT provider patching servers and resetting passwords is not looking for it either; keeping systems running and keeping systems watched are different jobs with different economics. And staffing analysts to watch around the clock is a mid-six-figure commitment no small RIA can justify against its revenue.

So most firms are now carrying a mandatory obligation with no operational capability behind it. That gap resolves in one of two ways: an examiner surfaces it during a routine review, or an incident surfaces it at the worst possible moment. The SEC did not amend this rule to collect better manuals.

What the Gap Looks Like in Practice

Consider a twelve-person RIA with $340 million under management. The principal’s email credentials are phished through a fake custodian login page on a Thursday evening. Over the next eleven days:

The custodian’s callback procedure catches the distribution — this time. That is the good outcome, and it is where most firms stop thinking about the incident. But the good outcome still leaves the firm with a full Reg S-P event: sensitive customer information for an indeterminate number of clients was reasonably likely accessed without authorization. Now the CCO must determine which clients, based on eleven days of mailbox activity nobody recorded in a usable form, and notify them within 30 days of the moment the firm became aware.

The cost of not detecting the intrusion on day one is not measured in the distribution that was blocked. It is measured in the scoping exercise that follows, the notification the firm may have to send to every client because it cannot prove a narrower scope, and the examination question about why eleven days of anomalous access produced no response.

Why Late Detection Costs More Than the Breach

  • Scope you cannot narrow becomes scope you must assume. Without records of what was accessed, the defensible notification is the broad one — every client, not the four who were actually exposed.
  • The 30-day clock does not care when you started looking. Awareness on day 11 leaves the same 30 days as awareness on day 1, with eleven more days of activity to reconstruct.
  • Client notification is a business event, not just a filing. At a twelve-person firm, it is a phone call to every relationship you have.
  • The examiner’s question is about the gap, not the attacker. “Your logs show this. What did your program do?”

What Intruex Does About It

Intruex is an AI security operations platform: a coordinated team of specialist AI analysts that connects to the security tools and logs you already have — leading endpoint and cloud security platforms among them, or nearly any log source via a standards-based interface — and investigates every alert your environment produces, continuously.

Mapped to the rule:

Your compliance consultant remains essential — someone has to own the written program, run the annual review, maintain the vendor oversight documentation, and manage the regulatory relationship. Intruex is the operational half that the amended rule now assumes exists: the part that detects, so that the part that responds has something to respond to.

What to Do Before Your Next Exam

Fiduciary Duty Was Already the Reason

The deadline makes this urgent, but it was never really about the deadline. Your clients gave you the two things attackers most want: their money and their information. They did that on the strength of a relationship, usually with one or two named people, at a firm they chose specifically because they would not be a number.

A breach at a twelve-person RIA does not read to those clients the way a breach at a wirehouse reads. It does not land as an institutional failure covered by an institutional apology. It lands as a betrayal by the people they picked because they would be looked after.

The rule now requires what fiduciary duty always implied. The difference is that today, a firm your size can actually afford to do it.

Sources: SEC, Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information, final amendments (effective August 2, 2024; compliance dates December 3, 2025 for larger entities and June 3, 2026 for smaller entities, including registered investment advisers with under $1.5 billion in assets under management). SEC Division of Examinations fiscal 2026 priorities. The scenario described is a composite drawn from publicly documented compromise patterns against advisory firms, not a specific incident. This article is informational and is not legal or compliance advice.