Cybersecurity Governance for RIAs: Close the Gap

By Howard Globus, Founder & Principal, IT On Demand (ITOD), a Cybersecurity Governance as a Service (CGaaS) firm.

Cybersecurity Governance for Registered Investment Advisers: What the SEC Expects and How to Prove It

Cybersecurity governance for registered investment advisers means maintaining documented, tested, and examiner-ready controls that demonstrate your firm protects client data and can respond to a breach, because the SEC no longer accepts intent as a substitute for evidence. If you cannot show an examiner your policies, your incident response records, and your vendor risk documentation, your program does not exist in the eyes of the regulator. Building that evidence is the work.

  • The SEC treats cybersecurity governance as an ongoing operational obligation, not a one-time checklist item, and examiners arrive expecting documented proof at every layer.
  • Registered investment advisers must maintain written policies, conduct regular risk assessments, and test their incident response plans under the SEC’s cybersecurity rules finalized in 2023.
  • Vendor and third-party risk management is a named examination focus, meaning your controls must extend beyond your own systems to the platforms and service providers your firm depends on.
  • A governance gap, the distance between what a firm claims its program does and what its documentation actually proves, is the single most common finding in SEC cybersecurity examinations.
  • Annual tabletop exercises, or TTEs, are among the most efficient ways to generate documented evidence of incident preparedness that holds up under examiner review.
  • Governance is not the same as security technology. Firewalls and endpoint protection do not satisfy an examiner’s documentation requests without accompanying policies and testing records.

What Is Cybersecurity Governance for Registered Investment Advisers?

Cybersecurity governance for registered investment advisers is the structured system of written policies, assigned accountabilities, tested controls, and documented evidence that allows a firm to demonstrate to the SEC, to clients, and to itself that it manages cybersecurity risk in a repeatable and verifiable way. It is distinct from cybersecurity technology. A firewall is a tool. Governance is the framework that proves the firewall is configured correctly, monitored consistently, and part of a broader risk management program.

The distinction matters because the SEC examines governance, not infrastructure. An examiner will not audit your network. They will request your written information security policy, your most recent risk assessment, your incident response plan, and your vendor due diligence records. If those documents do not exist, or exist but have never been tested or updated, your technology investments become legally irrelevant.

Governance is not what your systems do. Governance is what your documentation proves your systems do, and the gap between those two things is exactly what the SEC is trained to find.

What Does the SEC Actually Require from RIAs on Cybersecurity?

The SEC’s cybersecurity rules for registered investment advisers, adopted in 2023, require firms to adopt and implement written cybersecurity policies and procedures reasonably designed to address cybersecurity risks, conduct periodic risk assessments, test the effectiveness of those controls, and provide prompt disclosure of material cybersecurity incidents. These requirements apply to SEC-registered investment advisers regardless of firm size, though the SEC acknowledges that implementation may scale with the complexity of the firm’s operations.

The core obligations break down into four practical categories:

  1. Written policies and procedures that address how the firm identifies, protects against, detects, responds to, and recovers from cybersecurity threats.
  2. Periodic risk assessments that evaluate the firm’s current threat environment, its controls, and the gaps between them. These must be documented.
  3. Annual reviews of the cybersecurity program, including a review of any cybersecurity incidents that occurred during the prior year.
  4. Incident disclosure requirements that obligate firms to report material cybersecurity incidents to the SEC and, in certain circumstances, to clients.

The NIST Cybersecurity Framework, or CSF, maps cleanly to these obligations. Its five functions, Identify, Protect, Detect, Respond, and Recover, align directly with what the SEC’s rules require. Firms that structure their written program around the NIST CSF have a defensible architecture that examiners recognize.

Why Do RIAs Fail Cybersecurity Examinations?

Registered investment advisers fail cybersecurity examinations not because they lack security technology, but because they cannot produce documented evidence that their controls exist, function as intended, and are reviewed on a regular basis, which is what the SEC’s examination process is specifically designed to test. The failure mode is almost always the same: policies that were written once and never updated, risk assessments that reference the prior year without substantive revision, and incident response plans that have never been exercised.

A policy that has never been tested is a promise, not a control. Examiners know the difference, and they will ask for the testing records to prove it.

Three patterns appear consistently in firms that receive examination deficiency letters:

  • Stale documentation. Policies written two or three years ago that do not reflect current vendors, current systems, or current personnel.
  • Missing vendor oversight records. No documented due diligence on third-party platforms, no vendor inventory, no review of vendor SOC 2 Type II reports.
  • Untested incident response. An incident response plan exists as a document, but no tabletop exercise has ever been conducted and no results are recorded.

How Does Vendor Risk Management Fit into RIA Cybersecurity Governance?

Vendor risk management is a formal component of cybersecurity governance for registered investment advisers because SEC examiners now treat third-party platform risk as an extension of the firm’s own risk posture, meaning your governance program must document how you select, monitor, and review every vendor that touches client data or firm systems. Portfolio management platforms, custodians, CRM systems, and cloud storage providers all fall within scope.

At a minimum, your vendor risk program should include:

  • A written vendor inventory that identifies every third party with access to firm data or systems.
  • Pre-engagement due diligence, including review of each vendor’s SOC 2 Type II report where available.
  • Annual review of vendor security posture, ideally documented in a risk register.
  • Contractual requirements that obligate vendors to notify the firm of material security incidents within a defined timeframe.

ISO 27001, the international standard for information security management systems, includes vendor relationship security as a dedicated control domain. Firms that align their vendor governance to ISO 27001’s Annex A controls have a recognized external standard to point to when an examiner asks why the program was structured a certain way.

What Is a Tabletop Exercise and Why Does It Matter for Compliance?

A tabletop exercise, or TTE, is a structured, discussion-based simulation in which firm leadership and relevant staff walk through a realistic cybersecurity incident scenario step by step, with the explicit goal of identifying gaps in the incident response plan and generating a written record that the exercise occurred and produced actionable findings. That written record is what matters to an SEC examiner.

TTEs serve two functions simultaneously. First, they expose gaps in your incident response plan before a real incident forces you to find them under pressure. Second, they create examiner-ready documentation that your firm tests its controls, exactly what the SEC’s annual review requirement demands.

Running a tabletop exercise without documenting the findings and follow-up actions is like taking a compliance exam and refusing to show your work. The regulator needs to see the process, not just the outcome.

A well-structured TTE scenario for an RIA might simulate a ransomware attack on a portfolio management platform, a phishing compromise of an adviser’s email account, or a data breach at a third-party custodian. Each scenario tests different dimensions of the incident response plan and surfaces different gaps.

How Should Smaller RIAs Approach Cybersecurity Governance Without a Full-Time CISO?

Smaller registered investment advisers can build a defensible cybersecurity governance program without hiring a full-time CISO by engaging a vCSO, or virtual Chief Security Officer, who provides the strategic governance function on a fractional basis, ensuring the firm maintains written policies, conducts risk assessments, and generates examination-ready documentation without the cost of a full-time executive hire. This model scales to firm size while meeting the SEC’s substantive requirements.

The vCSO engagement is not a technology deployment. It is a governance relationship. The vCSO owns the program architecture, coordinates risk assessments, facilitates TTEs, and maintains the documentation library that an examiner will request. The firm’s leadership retains accountability and signs off on the program, which is the structure the SEC expects regardless of who builds it.

Frameworks like the SAFE Matrix™ can help smaller firms map their current control environment, identify gaps relative to SEC expectations, and prioritize remediation in a way that is documented and defensible from the start.

By the Numbers

  • 30 days. The SEC’s cybersecurity rules require registered investment advisers to report material cybersecurity incidents to the Commission within 30 days of determining that an incident is material, a timeline that demands a functioning incident response process, not a plan written the day after the breach.
  • 2023. The SEC adopted its final cybersecurity risk management rules for investment advisers and investment companies in July 2023, making written policies, annual reviews, and incident disclosure formal regulatory obligations rather than best-practice recommendations.
  • Roughly half. In the pattern observed across client engagements by IT On Demand, approximately half of RIAs that believe they have an incident response plan in place have never conducted a tabletop exercise to test it, meaning the plan is untested and unlikely to function as written under real incident conditions.
  • Annual cadence. The SEC’s rules require an annual review of the cybersecurity program, including a review of material changes and incidents from the prior year. Firms that treat this as a point-in-time exercise rather than a continuous governance rhythm are the ones most likely to receive deficiency letters.

Expert Insight

In my years running technology and security as CIO/CISO inside a corporate reinsurer, the pattern that shows up most is the assumption that documentation follows naturally from good security practice. It does not. Security teams focus on controls. Governance requires that someone separately owns the task of proving those controls exist, function correctly, and are reviewed on a defined schedule. Those are two different disciplines, and conflating them is how firms end up with strong technical environments and indefensible examination records.

In my work with registered investment advisers, the gap I encounter most consistently is between what the CCO believes the firm’s program covers and what the actual documentation library can prove to an examiner. The CCO is often correct that the firm does the right things operationally. The problem is that doing the right thing and being able to prove you do the right thing are not the same. The SEC examines the proof. Building the proof is the governance work, and it requires someone to own it explicitly, not as a side project of the IT department.

Frequently Asked Questions

What does the SEC look for in a cybersecurity examination of an RIA?

SEC examiners reviewing an RIA’s cybersecurity program request written policies and procedures, documented risk assessments, incident response plans, evidence that those plans have been tested, vendor due diligence records, and records of annual program reviews. Examiners are not auditing your technology stack. They are auditing your documentation, your governance process, and your ability to demonstrate that your program is reviewed and updated on a regular basis.

How often does an RIA need to update its cybersecurity policies?

The SEC requires an annual review of the cybersecurity program, but policies should be updated whenever a material change occurs, including a new vendor relationship, a change in key personnel, a significant technology migration, or a cybersecurity incident. Annual review is the floor, not the ceiling. A policy that was accurate last year but does not reflect the firm’s current environment is a deficiency waiting to be documented.

What happens if an RIA has a data breach and doesn’t report it to the SEC?

Failure to report a material cybersecurity incident within the required 30-day window is an independent regulatory violation separate from the breach itself. The SEC has brought enforcement actions against firms not only for the underlying security failure but for inadequate disclosure processes. Having a defined incident response plan with clear materiality assessment criteria is the mechanism that allows firms to meet that deadline consistently.

Does cybersecurity governance apply to small RIAs with just a few advisers?

Yes. The SEC’s cybersecurity rules apply to all registered investment advisers regardless of firm size. The Commission acknowledges that implementation may scale with operational complexity, but the core obligations, written policies, risk assessments, annual reviews, and incident disclosure, apply to every registered firm. Small size is not an exemption. It is an argument for proportionate, well-documented controls rather than no controls.

What is the difference between a cybersecurity policy and a cybersecurity program?

A cybersecurity policy is a single written document that describes what the firm does in a specific area, such as access control or incident response. A cybersecurity program is the full governance architecture: the complete set of policies, the risk assessment process, the testing cadence, the vendor oversight function, the training records, and the annual review documentation that together demonstrate a functioning risk management system. The SEC requires the program, not just individual policies.

What is a SOC 2 Type II report and why does it matter for RIA vendor oversight?

A SOC 2 Type II report is an independent audit of a service organization’s security, availability, and confidentiality controls over a defined period, typically six to twelve months, which provides evidence that the vendor’s controls function as described and have been tested by an independent auditor. For RIAs, reviewing a vendor’s SOC 2 Type II report is one of the most direct ways to document third-party due diligence and demonstrate to an SEC examiner that vendor risk oversight is active, not theoretical.

How does the NIST Cybersecurity Framework help RIAs structure their governance program?

The NIST Cybersecurity Framework provides a five-function structure, Identify, Protect, Detect, Respond, and Recover, that maps directly to the obligations in the SEC’s cybersecurity rules for investment advisers. Using the NIST CSF as the architecture for a written program gives the firm a recognized external standard to reference when explaining why the program is structured as it is, which strengthens the examiner’s confidence that the design was intentional and risk-based rather than assembled ad hoc.

What is a vCSO and when does an RIA need one?

A vCSO, or virtual Chief Security Officer, is a fractional senior security and governance executive who provides the strategic oversight, policy ownership, and examination readiness functions of a full-time CISO without the cost of a permanent hire. An RIA needs to consider a vCSO engagement when no one inside the firm owns the cybersecurity governance program explicitly, when documentation has fallen behind examination standards, or when the firm has received a deficiency letter and needs to close gaps with documented, verifiable remediation.

Next Steps

If your firm’s cybersecurity documentation would not hold up to an examiner’s request today, the time to address that is before the examination notice arrives. The gap between what your program claims to do and what your documentation can prove is a solvable problem, but it requires a structured approach and someone who owns it.

Start with an honest assessment of what you can produce right now: your written information security policy, your most recent risk assessment, your incident response plan, and your vendor due diligence records. If any of those are missing, outdated, or untested, that is your remediation priority list.

To discuss what a governance program built for SEC examination readiness looks like for your firm, schedule a conversation with the ITOD team. The assessment is direct, the recommendations are specific, and the work is designed to produce documentation that holds up when it matters.

Categories