The SEC's cybersecurity rules don't ask for your policies. They ask for evidence that they work.
IT On Demand builds the documented governance program that makes an RIA's cybersecurity posture defensible under SEC examination — and keeps it that way year-round.
The SEC's cybersecurity rules changed the standard. Most RIAs haven't caught up to what that means.
The SEC’s cybersecurity rules for investment advisers — adopted in 2023 and actively enforced — require registered investment advisors to adopt and implement written cybersecurity policies and procedures reasonably designed to address cybersecurity risks. They also require disclosure of material cybersecurity incidents and, for certain advisers, annual reports.
The examination standard is not whether the policies exist. It is whether the procedures are implemented — and whether the evidence of that implementation is documented and current.
For most RIAs with 25 to 150 employees and no dedicated CISO, that evidence gap is significant. The SEC examination asks for the same documentation that a DFS examiner would request — and finds the same gap in the same layer that no one was built to own.
The personal dimension that most advisors underestimate.
For registered investment advisors, the governance obligation is not abstract. Clients have entrusted the firm with financial assets and personal information. The CCO and senior officers have professional obligations to those clients and to the SEC.
An SEC examination that finds inadequate cybersecurity governance documentation does not produce a quiet corrective letter. It produces a deficiency that stays on the firm’s examination record, that prospective clients and institutional allocators can find, and that affects the firm’s ability to win and retain sophisticated mandates.
For firms managing institutional capital, a governance gap finding is a business problem as much as a regulatory one.
The governance documentation the SEC examines — built and maintained for your firm.
IT On Demand builds governance programs for RIAs that are specifically calibrated to the SEC’s cybersecurity examination standard — not a generic framework applied generically, but a program built for your firm’s size, structure, and client base.
We build and maintain the written information security policies, penetration test documentation, vendor risk assessment inventory, tested incident response plan, and MFA verification records that an SEC examination will look for. Year-round. Not in the three weeks before the examination team calls.
Questions we hear from registered investment advisors.
- Q: What do the SEC's cybersecurity rules actually require RIAs to document?
- A: The SEC's cybersecurity rules require registered investment advisers to adopt and implement written cybersecurity policies and procedures addressing risk assessment, user security, information protection, third-party service provider oversight, incident response, and business continuity. The examination standard focuses on whether those procedures are implemented — evidenced by operational documentation — not just whether the written policies exist. The documentation gap between a written policy and verifiable implementation is what most SEC examiners find.
- Q: How is the SEC's cybersecurity examination different from a DFS examination?
- A: The frameworks differ, but the examination dynamic is the same: examiners arrive with a documentation request list and ask for evidence that controls are implemented and current. For firms subject to both SEC and DFS obligations — RIAs that are also DFS-licensed entities — a single governance program built to satisfy both frameworks is more efficient than two separate programs. IT On Demand builds multi-framework programs specifically for this reason.
- Q: Our compliance consultant told us our policies are adequate. Isn't that enough?
- A: It depends on what "adequate" means. Policies that are well-written are a starting point. The SEC examination examines whether those policies are implemented — evidenced by penetration test results, vendor risk documentation, tested incident response plans, and MFA verification records. If the policies exist but the implementation evidence does not, the examination will find a gap. Compliance consultation and governance documentation are different services that address different layers of the same obligation.
- Q: We are a smaller RIA. Does the SEC actually examine firms our size?
- A: Yes. SEC examination resources have increasingly focused on mid-market RIAs, particularly since the adoption of the 2023 cybersecurity rules. Examination cycles for smaller RIAs are not announced in advance. The firms that enter examinations with adequate documentation are the ones that maintained it continuously — not the ones that built it after the examination was scheduled.