Cybersecurity Governance for RIAs | ITOD

By Howard Globus, Founder & Principal, IT On Demand (ITOD), a Cybersecurity Governance as a Service (CGaaS) firm.

Cybersecurity Governance for RIAs: What the SEC Now Expects You to Prove

Cybersecurity governance for registered investment advisers means having documented policies, tested controls, and evidence you can hand an SEC examiner on request, because under the 2023 SEC Cybersecurity Rule, having security measures in place is no longer enough if you cannot demonstrate they work. RIAs that treat governance as a paperwork exercise will find that gap exposed during examination. The firms that pass are the ones that built their programs to be auditable, not just operational.

  • The SEC’s 2023 Cybersecurity Rule requires registered investment advisers to adopt written policies and procedures reasonably designed to address cybersecurity risks to client data and adviser operations.
  • Governance documentation and incident response plans must be reviewed at least annually, with evidence of that review retained and available for examination.
  • Significant cybersecurity incidents must be reported to the SEC on Form ADV-C within 30 days of determining that a reportable event occurred.
  • Firms that rely on informal security practices without written policies face direct examination exposure, regardless of whether a breach has occurred.
  • The NIST Cybersecurity Framework (CSF) provides a structured, examiner-recognized approach RIAs can use to organize and evidence their governance programs.
  • If a control exists but is undocumented and untested, regulators treat it as if it does not exist.

What Is Cybersecurity Governance for RIAs?

Cybersecurity governance for registered investment advisers is the formal system of written policies, documented controls, assigned ownership, and evidence-retention practices that allows a firm to demonstrate to SEC examiners that it identifies, manages, and responds to cybersecurity risk in a consistent and auditable way. It goes further than having antivirus software or a firewall. Those are controls. Governance is the structure that proves the controls exist, were chosen deliberately, are tested regularly, and are reviewed when circumstances change.

The distinction matters because the SEC does not examine what you have. It examines what you can prove. A firm running solid security operations with no written program is, from a regulatory standpoint, running nothing at all.

Governance is not the security program itself. It is the evidence that the security program is real, intentional, and supervised.

What Does the SEC’s 2023 Cybersecurity Rule Actually Require from RIAs?

The SEC’s 2023 Cybersecurity Rule, adopted under the Investment Advisers Act, requires registered investment advisers to implement written cybersecurity policies and procedures reasonably designed to address risks to adviser information systems and client data, review those policies at least annually, and report significant cybersecurity incidents to the Commission within 30 days on Form ADV-C. The rule also requires disclosure of cybersecurity risks and incidents to clients through Form ADV Part 2A, creating a dual accountability layer: the regulator and the client.

Key obligations under the rule include:

  • Written policies and procedures addressing cybersecurity risk management
  • Annual review of those policies, with documentation of the review
  • Designation of a person or persons responsible for cybersecurity oversight
  • Incident response procedures, tested and documented
  • Reporting of significant cybersecurity incidents to the SEC within 30 days
  • Client disclosure of material cybersecurity risks and incidents via Form ADV

The rule does not prescribe a single framework. It requires a program that is reasonably designed for the firm’s size, complexity, and risk profile. That flexibility sounds helpful. In practice it means firms must make and document deliberate choices, because an examiner will ask why you chose the controls you did.

How Does the NIST Cybersecurity Framework Apply to RIA Governance?

The NIST Cybersecurity Framework (CSF) gives registered investment advisers a structured, five-function model covering Identify, Protect, Detect, Respond, and Recover, which maps directly to the risk management program structure the SEC expects RIAs to demonstrate during examination. The CSF is not a compliance checklist, but it produces the kind of organized, traceable documentation that examiners find credible.

Using the NIST CSF as the organizing spine of an RIA governance program accomplishes several things at once:

  1. It forces the firm to inventory assets and data flows, satisfying the Identify function and supporting ADV disclosure accuracy.
  2. It provides a recognized taxonomy for describing controls, which reduces examiner ambiguity.
  3. It creates natural annual review checkpoints aligned with the SEC’s mandatory review cadence.
  4. It produces gap documentation that shows the firm is aware of its risk profile and actively managing it.

A governance program built on the NIST Cybersecurity Framework gives examiners a map. A program built on informal practices gives them a reason to dig deeper.

What Happens During an SEC Cybersecurity Examination?

During an SEC cybersecurity examination, staff from the Division of Examinations typically request written policies, evidence of annual reviews, incident response plans, vendor due diligence records, and documentation showing that the people responsible for cybersecurity actually oversee it, not just that the policies name them as responsible. The request list can arrive with a short response window, often 10 to 20 business days, which means the evidence must already exist, not be assembled after the fact.

Common examination findings for RIAs include:

  • Written policies that exist but have never been reviewed or updated
  • Incident response plans that have never been tested through a Tabletop Exercise (TTE)
  • Third-party vendor relationships with no documented due diligence or contract security requirements
  • Employee training records that are missing or cannot be produced
  • No designated cybersecurity responsible person, or a designation in name only

Each of these findings is a governance failure, not a technology failure. The firm may have had the underlying security controls in place. But without evidence, the control does not exist in the examiner’s view.

Why Do RIAs Treat Cybersecurity Governance as Optional Until It Isn’t?

Registered investment advisers frequently deprioritize cybersecurity governance because the consequences of the gap are invisible until an examination or incident forces them into view, and smaller RIAs in particular lack an internal resource whose job it is to track regulatory changes, maintain documentation, and run the annual review cycle without being prompted. This is the governance gap: the space between the security a firm believes it has and the governance a regulator can actually verify.

The problem compounds over time. A policy written in 2021 and never updated does not reflect current SEC requirements, current vendor relationships, or current threat conditions. An incident response plan that has never been tested through a Tabletop Exercise is a document, not a capability. The gap widens quietly, and firms often do not discover how wide it has grown until an examination request arrives.

Governance Element What Examiners Look For Common Gap
Written Policies Current, signed, scope-appropriate Outdated or template-only, never customized
Annual Review Documented date, reviewer, changes made No evidence of review ever occurring
Incident Response Plan Tested via TTE, updated after each test Plan exists but has never been exercised
Vendor Due Diligence Risk assessments, contract security terms Vendors onboarded with no security review
Employee Training Records showing completion dates Training done informally, no documentation
Responsible Person Active oversight, not just a named title Name in policy, no actual activity on record

The governance gap is not a technology problem. It is an accountability and documentation problem, and it is entirely solvable with the right structure in place.

How Can a vCSO Help an RIA Close the Governance Gap?

A virtual Chief Security Officer (vCSO) gives a registered investment adviser access to a dedicated governance resource who maintains the written program, manages the annual review cycle, designs and runs Tabletop Exercises, and produces the documentation trail that SEC examiners request, without the cost of a full-time executive hire. For most RIAs, the alternative is assigning governance responsibility to a Chief Compliance Officer or operations lead who already carries a full workload and lacks cybersecurity-specific training.

A vCSO engagement structured around the NIST CSF and SEC requirements typically produces:

  • A current, firm-specific written cybersecurity policy and incident response plan
  • An annual governance review calendar with documented outputs
  • A Tabletop Exercise run at least annually, with after-action documentation
  • Vendor due diligence templates and tracking records
  • A Form ADV disclosure review aligned to the firm’s actual risk profile
  • An evidence file organized for rapid response to an SEC examination request

By the Numbers

  • 30 days: The window the SEC’s 2023 Cybersecurity Rule gives registered investment advisers to report a significant cybersecurity incident to the Commission after determining it is reportable, using Form ADV-C.
  • Annual minimum: The SEC requires RIAs to review their cybersecurity policies and procedures at least once per calendar year and retain documentation of that review for examination.
  • Part 2A disclosure: RIAs must disclose material cybersecurity risks and significant incidents to clients through Form ADV Part 2A, creating an obligation that runs parallel to the SEC reporting requirement.
  • Pattern from practice: In roughly half the RIA engagements this firm conducts, the written incident response plan has never been tested through a Tabletop Exercise before the engagement begins. The plan exists. The capability does not.

Expert Insight

In my years running technology and security as CIO/CISO inside a corporate reinsurer, the pattern that shows up most is the gap between what a firm’s leadership believes the security program covers and what an external audit or examination actually finds documented. At Allianz Risk Transfer, we operated under rigorous internal audit cycles, regulatory oversight, and third-party examination. The lesson those experiences drove home is that governance documentation is not a bureaucratic formality. It is the only thing standing between your program and the conclusion that no program exists.

In my work with registered investment advisers, I see the same dynamic play out at a smaller scale with higher stakes per firm. The principals are competent. The intent is genuine. But the documentation infrastructure, the annual reviews, the tested incident response plans, the vendor records, is often years behind where the examination standard sits. The firms that close that gap before an exam find the process clarifying. The firms that encounter it during an exam find it expensive.

Frequently Asked Questions

What cybersecurity policies does the SEC require RIAs to have in writing?

The SEC requires registered investment advisers to have written policies and procedures reasonably designed to address cybersecurity risks to their information systems and client data. Those policies must cover risk assessment, access controls, incident response, vendor oversight, and training, and they must be reviewed and updated at least annually with documentation of each review.

How long does an RIA have to report a cybersecurity incident to the SEC?

An RIA has 30 days to report a significant cybersecurity incident to the SEC after determining that the incident is reportable, using Form ADV-C. The clock starts from the determination date, not the date the incident occurred, which makes the internal assessment process a critical part of the firm’s incident response plan.

What happens if an RIA fails an SEC cybersecurity examination?

If an RIA’s cybersecurity examination reveals deficiencies, the SEC typically issues a deficiency letter requiring remediation within a specified timeframe. Repeated or material deficiencies can result in enforcement referrals, formal orders, and civil penalties. Firms that cannot demonstrate a reasonable cybersecurity program face the most serious exposure because the absence of governance is itself a violation of the rule.

Does a small RIA need a formal cybersecurity governance program?

Yes. The SEC’s 2023 Cybersecurity Rule applies to all registered investment advisers, and while the rule acknowledges that program scope should reflect firm size and complexity, it does not exempt smaller firms from the written policy, annual review, and incident reporting requirements. A smaller firm’s program may be simpler, but it must still be written, documented, and auditable.

What is a Tabletop Exercise and why does the SEC care about it?

A Tabletop Exercise (TTE) is a structured simulation in which a firm walks through a hypothetical cybersecurity incident, testing whether its people, processes, and documented procedures actually work together under pressure. The SEC cares about TTEs because an untested incident response plan is not a functional capability, and examiners look for evidence that the plan has been exercised, not just written.

Can a vCSO satisfy the SEC’s requirement for a designated cybersecurity responsible person?

A virtual Chief Security Officer (vCSO) can fulfill the governance, oversight, and documentation functions the SEC associates with cybersecurity responsibility, provided the engagement is structured with clear scope, documented activities, and active involvement in the firm’s program rather than a passive advisory role. The SEC looks for evidence of actual oversight activity, not just a name on a policy page.

What is the SAFE Matrix and how does it relate to RIA cybersecurity governance?

The SAFE Matrix is a governance assessment tool used to map a firm’s current cybersecurity controls against the documentation and process standards an examiner would evaluate, producing a structured gap analysis rather than a pass/fail score. For RIAs, it provides a baseline from which to build or remediate the written program, prioritizing the elements most likely to surface during an SEC examination.

How often should an RIA update its Form ADV cybersecurity disclosures?

An RIA must update its Form ADV Part 2A cybersecurity disclosures annually as part of the standard annual amendment, and must file interim amendments promptly when a material change occurs, including a significant cybersecurity incident. The disclosure must accurately reflect the firm’s current risk profile, which means the written governance program and the ADV disclosure must stay synchronized.

Next Steps

If you are an RIA principal or CCO who is not confident that your cybersecurity governance program would hold up to an SEC examination request today, that gap is worth closing before an examiner identifies it for you. The written policies, annual review documentation, tested incident response plan, and vendor due diligence records the SEC expects are buildable. They require structure and consistent attention, not a large budget.

IT On Demand (ITOD) works with registered investment advisers to build and maintain governance programs designed to satisfy SEC examination standards, using the NIST Cybersecurity Framework as the organizing structure and a vCSO engagement model that keeps the program current without requiring a full-time internal hire. Schedule a Governance Gap Assessment to see exactly where your program stands and what it would take to close the distance between where you are and where an examiner expects you to be.

Schedule your Governance Gap Assessment with ITOD

Categories