{"id":680382,"date":"2026-06-02T19:26:16","date_gmt":"2026-06-02T19:26:16","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/680382\/"},"modified":"2026-06-02T19:26:16","modified_gmt":"2026-06-02T19:26:16","slug":"rias-scramble-to-meet-reg-s-p-compliance-deadline","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/680382\/","title":{"rendered":"RIAs Scramble To Meet Reg S-P Compliance Deadline"},"content":{"rendered":"<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">As smaller firms comply with the Securities and Exchange Commission\u2019s changes to Regulation S-P, experts are warning reps to ensure their incident response plans for cybersecurity events are up to date and workable.<\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">The Reg S-P changes were passed in late 2024, which updated (and expanded) firms\u2019 responsibilities for safeguarding consumer data. Firms with over $1.5 billion in managed assets had a Dec. 3, 2025, compliance date, while firms below the threshold face a deadline this week, on June 3.<\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">Among the changes are requirements to update incident response programs, a 30-day requirement for consumer notification, and a 72-hour deadline for vendors to inform RIAs of cyber incidents.\u00a0<\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">In a discussion with\u00a0Wealth Management,\u00a0Michael Cocanower, the founder and CEO of RIA IT consulting firm itSynergy, said responses from clients about the Reg S-P ran the gamut from complete preparedness to total surprise.\u00a0According to Cocanower, RIAs\u2019 backup and disaster recovery\/business continuity plans did not serve as replacements for an incident response plan, which details how a firm will respond to a cybersecurity attack, and he said RIAs had complained that there was little guidance available on how to craft such a plan.<\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\">Related:<a class=\"RelatedArticle-RelatedContent\" href=\"https:\/\/www.wealthmanagement.com\/regulation-compliance\/dol-rule-to-ease-alternatives-in-401-k-s-draws-over-37k-comments\" target=\"_self\" data-discover=\"true\" rel=\"nofollow noopener\">DOL Rule to Ease Alternatives in 401(K)s Draws Over 37,000 Comments<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">Additionally, Cocanower worried that too many IRPs were being drafted by an attorney solely to \u201ccheck the regulatory box,\u201d which he warned would be \u201ccompletely useless\u201d in a cyber incident.<\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">\u201cI\u2019m seeing that disconnect where they check the box, and I go, \u2018Great, you did check the box, I agree,\u2019\u201d he said. \u201cBut in terms of this being a useful document during a cybersecurity incident, it\u2019s not even close.\u201d<\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">The changes in service provider oversight are particularly notable, with advisors now required to demonstrate ongoing oversight rather than a single review at vendor onboarding.\u00a0<\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">Mark Gilbert, the CEO and co-founder of Zocks, an AI assistant tool for advisors, said advisors should view vendors\u2019 willingness (or lack thereof) to discuss client data handling as a telling sign for whether they are a good fit. Additionally, the 30-day consumer notification mandate makes it essential for firms to know what data they have, where it is, and what it has touched.<\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">\u201cIf you don\u2019t have a current map of your data flows, you can\u2019t realistically notify affected clients within 30 days of a breach, because you won\u2019t even know who was affected or what was exposed,\u201d Gilbert said.<\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">According to Max Schatzow, a partner with RIA Lawyers, the rule requires advisors to obtain \u201creasonable assurances\u201d from service providers that those vendors are properly protecting client information and will notify the firm within 72 hours of a breach. However, advisors and vendors are struggling to define \u201creasonable assurances,\u201d and advisors are still struggling to document compliance before the deadline.<\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\">Related:<a class=\"RelatedArticle-RelatedContent\" href=\"https:\/\/www.wealthmanagement.com\/regulation-compliance\/ai-adoption-in-compliance-remains-limited-aca-says\" target=\"_self\" data-discover=\"true\" rel=\"nofollow noopener\">AI Adoption in Compliance Remains Limited, ACA Group Says<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">\u201cSome service providers are resisting these requests by arguing that they do not fall within the rule\u2019s definition of a service provider, while others are simply not responding to advisors seeking contractual or written assurances,\u201d Schatzow said.<\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">Lori Weston, the head of compliance for STP Investment Services, affirmed that advisors were having trouble getting \u201cclear vendor commitments\u201d to meet the 72-hour deadline, so firms are resorting to other solutions to get compliant, \u201cincluding contractual terms, vendor certifications, and in some cases, negative consent.\u201d<\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">Weston agreed with Gilbert, stressing that firms need to be able to locate consumer information in the event of a cybersecurity incident, including if that data flows toward service providers (and their third-party systems).<\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">Chief compliance officers \u201ccan\u2019t assume their IT staff or (managed security service provider) will handle the breach,\u201d she said. \u201cThey need to understand the incident response plan and have a plan for orchestrating it.\u201d<\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\">Related:<a class=\"RelatedArticle-RelatedContent\" href=\"https:\/\/www.wealthmanagement.com\/regulation-compliance\/finra-warns-finfluencers-pose-growing-risk-to-investors\" target=\"_self\" data-discover=\"true\" rel=\"nofollow noopener\">AI Creates Further Risk in the &#8216;Wild West&#8217; of Finfluencers<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">For Cocanower, small and mid-size firms are particularly vulnerable because they continue to focus on prevention rather than on detecting threats when they occur, as threats will be too overwhelming and sophisticated for firms to evade every time.<\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\">\u201cThe bad guys are going to get in. So, the issue is, in order for you to be able to provide a 30-day notice or a 72-hour notice, you have to equally prioritize the detection and the response, and not just the prevention,\u201d he said. \u201cBecause prevention alone is not going to do it.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"As smaller firms comply with the Securities and Exchange Commission\u2019s changes to Regulation S-P, experts are warning reps&hellip;\n","protected":false},"author":2,"featured_media":680383,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[39],"tags":[28,147,530],"class_list":["post-680382","post","type-post","status-publish","format-standard","has-post-thumbnail","category-personal-finance","tag-business","tag-personal-finance","tag-personalfinance"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/680382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=680382"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/680382\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/680383"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=680382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=680382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=680382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}