The SEC's cybersecurity rules don't ask for your policies. They ask for evidence that they work.

IT On Demand builds the documented governance program that makes an RIA's cybersecurity posture defensible under SEC examination — and keeps it that way year-round.

The SEC's cybersecurity rules changed the standard. Most RIAs haven't caught up to what that means.

The SEC’s cybersecurity rules for investment advisers — adopted in 2023 and actively enforced — require registered investment advisors to adopt and implement written cybersecurity policies and procedures reasonably designed to address cybersecurity risks. They also require disclosure of material cybersecurity incidents and, for certain advisers, annual reports.

The examination standard is not whether the policies exist. It is whether the procedures are implemented — and whether the evidence of that implementation is documented and current.

For most RIAs with 25 to 150 employees and no dedicated CISO, that evidence gap is significant. The SEC examination asks for the same documentation that a DFS examiner would request — and finds the same gap in the same layer that no one was built to own.

The personal dimension that most advisors underestimate.

For registered investment advisors, the governance obligation is not abstract. Clients have entrusted the firm with financial assets and personal information. The CCO and senior officers have professional obligations to those clients and to the SEC.

An SEC examination that finds inadequate cybersecurity governance documentation does not produce a quiet corrective letter. It produces a deficiency that stays on the firm’s examination record, that prospective clients and institutional allocators can find, and that affects the firm’s ability to win and retain sophisticated mandates.

For firms managing institutional capital, a governance gap finding is a business problem as much as a regulatory one.

The governance documentation the SEC examines — built and maintained for your firm.

IT On Demand builds governance programs for RIAs that are specifically calibrated to the SEC’s cybersecurity examination standard — not a generic framework applied generically, but a program built for your firm’s size, structure, and client base.

We build and maintain the written information security policies, penetration test documentation, vendor risk assessment inventory, tested incident response plan, and MFA verification records that an SEC examination will look for. Year-round. Not in the three weeks before the examination team calls.

Questions we hear from registered investment advisors.

Start with a Compliance Gap Assessment.

A 30-minute private diagnostic, specific to your firm’s SEC and applicable DFS regulatory exposure. We identify what documentation you have, what is missing, and what an examiner would find if they arrived next month. No pitch. No obligation.