The SEC spent most of 2025 writing the rules. In 2026, it started checking whether firms followed them. The first wave of Regulation S-P examinations has arrived, and the findings are worth paying attention to. Not because they are surprising, but because they reveal exactly where the gap between intent and infrastructure tends to live.
For most RIAs, that gap lives in IT.
What examiners are actually looking for
Reg S-P requires firms to have a written incident response program, to notify affected clients within 30 days of a breach, and to manage vendor cybersecurity risk with documented oversight. Examiners are not showing up with a simple checklist. They are asking to see evidence that the policy matches the system. That the 30-day notification process is real. Not a paragraph in a PDF that nobody has read since it was drafted.
The firms that struggled in early exams had the policies. They lacked the infrastructure to carry them out. No centralized logging. No defined escalation path. Vendors operating under agreements that never addressed data protection. Incident response plans listing contacts who had left the firm two years ago.
A November 2025 SEC enforcement action illustrates exactly this. A dually registered broker-dealer and RIA with more than 120 branches experienced 17 email account takeovers between 2019 and 2024, exposing personally identifiable information for roughly 8,500 people and resulting in at least one unauthorized wire transfer. The SEC found that many branches lacked MFA, incident response plans, and annual security training. The firm had written a security policy in 2020. It had not meaningfully implemented it. The settlement was $325,000, a cease-and-desist order, and a censure.
A written policy is only as good as the IT environment behind it. Examiners know the difference between a firm that is prepared and one that is compliant on paper.
The IT signals examiners read
Whether or not an examiner directly asks about your IT setup, your infrastructure tells a story. Patched systems suggest active management. Multi-factor authentication on email and CRM says someone thought seriously about access control. A vendor list with no due diligence documentation tells the opposite story.
Firms without a managed IT partner tend to show the same pattern: strong intent, inconsistent follow-through. The principals care about compliance. But there is nobody whose job it is to make sure the security controls actually work month to month. Good intentions are not a compensating control.
What to do before your examination arrives
Start with your incident response plan. Read it critically. Does the contact list reflect the people actually at your firm today? Does it say you’re going to handle everything yourself internally without outside expertise? Is there a real, tested process for reaching affected clients within 30 days? That means the capability to send notifications at scale, quickly, from a system that keeps records. Not a manual email from the CCO’s personal inbox.
Then look at vendor agreements. Reg S-P requires you to ensure that vendors handling client data are also protecting it. That means more than choosing reputable names from familiar providers. It means documented reviews, signed agreements, and evidence that you asked the right questions and got specific answers. You also need to ensure that, at a minimum, they have provided you with an attestation to notify you within 72 hours of discovery of a breach in their systems.
Finally, test your logging and monitoring. Can you tell, today, whether unauthorized access occurred last week? If a threat actor launches their attack at 2am on a Saturday is there a mechanism in place to pull someone out of bed to investigate and respond? Has your IT company ever proactively contacted you regarding a potentially malicious event on your system? If not, you should be questioning whether they are watching, as attacks on every firm are nearly constant.
The bigger picture
The SEC is not trying to punish RIAs for having smaller IT budgets. It is trying to determine whether firms are serious about protecting client data or just serious about appearing to be. The firms that pass examinations cleanly are not the ones with the most sophisticated technology stack. They are the ones where technology and policy are aligned, tested, and maintained.
That alignment does not happen on its own. It requires someone who understands both sides: the regulatory expectation and the IT reality. For most RIAs, a qualified managed IT partner focused on your industry is what makes that possible.
itSynergy works exclusively with RIAs to align IT infrastructure with SEC compliance requirements. If your annual review is coming up and you are not sure your systems match your policies, that is a conversation worth having before an examiner starts it for you. Learn how we support RIA compliance at itsynergy.com/ria-compliance-readiness/.