Financial advisor reviewing breach response documents at a conference table with a laptop

Data Breach Response for Financial Advisors and CPA Firms

October 03, 2026

A CPA firm in Miami found out their payroll vendor had been hit by ransomware. The vendor's systems, which processed W-2s and direct deposit information for dozens of the firm's clients, were down for five days. The firm's managing partner called us on day three. His question: "Do I have to tell my clients?"

He did. Under SEC Regulation S-P (amended in May 2024) and FINRA's longstanding guidance, registered advisers and broker-dealers must notify affected individuals when their financial data is exposed. For investment advisers registered with the SEC, the amended rule gives you 30 days from discovery to notify clients. For many FINRA members, the expectation is faster.

The harder question was not whether to notify. It was that the firm had no plan for how to do it. No written procedures, no designated response lead, no list of which vendors handled which client data. Three days had passed before anyone even called their IT provider. That delay matters for data breach response for financial advisors and CPA firms, because regulators look at when you discovered the breach and when you acted on it.

Key Takeaways

  • SEC Regulation S-P (amended May 2024) requires SEC-registered investment advisers to notify affected clients within 30 days of discovering a breach involving their personal financial information.
  • The most common source of client data exposure for small financial firms is a vendor breach, not a direct attack on the firm's own systems.
  • A written response plan built before an incident keeps you from making regulatory decisions under pressure at 11 PM on a Friday.
  • FINRA expects member firms to document incident response procedures as part of their cybersecurity program, whether or not a breach has occurred.
  • When a regulator or cyber insurer asks for documentation after a breach, the first two things they want are your incident response plan and your vendor inventory.

What a Data Breach Looks Like for a Small RIA or CPA Firm

Vendor Breaches Are the Most Common Entry Point

The client data sitting in your portfolio management software, your CRM, your document storage, your e-signature tool, and your payroll processor is technically not yours to control. It lives in systems operated by other companies. When any one of those vendors gets hit, your clients' Social Security numbers, account numbers, and tax data can be exposed, even though your own systems never saw an intrusion.

SEC Reg S-P explicitly covers vendor-caused breaches under its service provider oversight requirements. If you hired the vendor and they touched client data, you bear the notification and oversight obligation. Saying "it was the vendor's fault" is not a regulatory defense. Your compliance program needs to include written vendor oversight, signed data security agreements, and a way to track what each vendor can access.

Actionable tip: Make a list of every vendor that processes or stores client personally identifiable information. For each one, confirm you have a signed data processing agreement that spells out their breach notification obligations to you. If any vendor can't produce one, that's your first fix this week.

Business Email Compromise Hits Differently at Financial Firms

In a business email compromise (BEC) attack, an attacker impersonates a known contact, often your IT vendor, a client, or your own firm's email account, to redirect a wire transfer or change ACH information. These attacks don't require breaking into your systems at all. They work by fooling a person.

At RIAs and CPA firms, BEC attacks often target the moment a client is making a large financial move: a rollover, a property purchase, an estate distribution. The attacker monitors email traffic, waits for a transaction to be discussed, and steps in with a spoofed message at exactly the right moment. The money is usually gone within hours, and recovery depends heavily on how fast you can alert your bank.

BEC is not a ransomware incident and does not always trigger a regulatory breach disclosure, but it is a financial data exposure event. Understanding what counts as a "covered data breach" under your specific registration status shapes what your notification obligations are. If you're unsure, your compliance attorney needs to be on your incident response call list before anything happens. For more on how these attacks work and how to stop them before money moves, see our guide on BEC fraud targeting financial advisors.

What Does the SEC Require After a Data Breach?

SEC Regulation S-P was amended in May 2024 and applies to registered investment advisers, broker-dealers, funding portals, and transfer agents. The changes added specific incident response and notification requirements that many small firms have not fully absorbed into their compliance programs.

The 30-Day Notification Rule

Under the amended Reg S-P, if you experience a breach involving client personal financial information, you must notify affected individuals "as soon as reasonably practicable, but no later than 30 days" after you discover, or have reason to believe, the breach occurred. The notice must be clear and include what information was exposed, the date range of the exposure, and what you're doing about it.

Two things trip up financial firms on this deadline. First, the clock starts at discovery, not at confirmation. You don't get 30 days from the day your forensics team finishes their report. If you have reason to believe a breach occurred on October 1st and you don't investigate until October 20th, a regulator may view the 30-day window as having started on October 1st.

Second, smaller RIAs sometimes assume they're exempt because of their AUM thresholds. The May 2024 amendments to Reg S-P apply to all SEC-registered investment advisers, regardless of size. State-registered advisers fall under their state's data breach notification laws, which vary but generally have similar or shorter windows.

Actionable tip: Write a policy that says: "When we become aware of a potential breach involving client personal data, we will begin our response and notify our compliance attorney within 24 hours, regardless of whether the breach is confirmed." That 24-hour internal trigger keeps you from losing days waiting for certainty before you act.

What FINRA Expects From Member Firms

FINRA's cybersecurity guidance doesn't set a specific breach notification timeline the way Reg S-P does, but FINRA Rule 4370 requires member firms to have a business continuity plan that covers data breach scenarios. FINRA also expects firms to document their cybersecurity program and be able to produce it during an examination.

When FINRA examines a member firm after a breach, they look at three things: whether the firm had a written incident response plan, whether it followed the plan, and whether client notifications went out within a reasonable timeframe. A firm that had no plan and took three weeks to tell clients their data was exposed is in a very different position than a firm that followed its written procedures and notified clients on day 12. For a breakdown of what FINRA examiners look for in a cybersecurity review, see our post on FINRA cybersecurity exam preparation for RIAs.

What to Do in the First 72 Hours After a Breach

The first 72 hours of a financial data breach are where most response mistakes happen. Firms either freeze and do nothing while they wait for certainty, or they start notifying clients before they know what was exposed. Both create problems.

Contain the Exposure First

Your first step is stopping the bleeding. That means disconnecting any compromised system from your network, or asking your IT provider to do it, resetting credentials for any accounts that may have been accessed, and preserving the logs and evidence you'll need for your investigation. Don't wipe or rebuild systems before your forensics team has reviewed them.

If the breach originated at a vendor, call the vendor and get written confirmation of what they know: when they discovered it, what data was involved, and what they've done to stop it. That written confirmation is what you'll hand to your compliance attorney and, if needed, the SEC.

Call Your Compliance Attorney on Day One

Your IT provider handles the technical containment. Your compliance attorney handles the regulatory analysis. These two calls need to happen at the same time, not one after the other. The attorney's job in hour one is to confirm your notification obligations under SEC Reg S-P, your state's breach notification law, and any contractual provisions in your client agreements. Waiting until the technical investigation wraps before calling the attorney is how firms miss their reporting window.

Actionable tip: Add your compliance attorney's personal cell number to your incident response contact list today. Not their office number. The firm that hits a breach on a Friday afternoon needs a person who picks up, not a voicemail box.

Document Every Step as You Go

From the moment you discover a potential breach, keep a running written log: who was notified and when, what systems were reviewed, what data was confirmed exposed, and what actions were taken. This log is your regulatory defense if the SEC or a state attorney general investigates later. Firms that can hand over a timestamped record of their response are treated very differently from firms that have to reconstruct the timeline from memory six months after the fact.

If your cybersecurity program includes a pre-built response log template, your team fills it in during the incident rather than building it from scratch. That's one less thing to think about when you're already under pressure.

GDS helps financial firms build exactly this kind of documented response framework. Schedule a free assessment and we'll review your current incident response posture in one session.

How to Build a Data Breach Response Plan Before You Need One

The best time to write an incident response plan is before you've ever needed one. For a small RIA or CPA firm, it doesn't have to be a 50-page document. It has to be specific enough that whoever finds the breach first knows exactly what to do in the next 60 minutes.

Designate a Response Lead

Your plan needs one person whose job is to start the response process when a potential breach surfaces. That person calls IT, calls the compliance attorney, and owns the documentation log. At a two-partner CPA firm, it's probably one of the partners. At a 10-person RIA, it might be your office manager. What matters is that the plan names a specific person, not a job title, and that person knows they're the response lead before anything happens.

Know What Data You Have and Where It Lives

I reviewed a firm's vendor list during a security assessment last year. They had 14 vendors with access to client personally identifiable information. Six had no signed data security agreement. One had stopped issuing security updates two years prior and the firm didn't know it. You can't protect what you haven't mapped, and you can't notify clients about an exposure you can't describe to them.

Your incident response plan needs an attached vendor inventory: every system, every tool, every third-party service that touches client data, with a contact name and phone number for each vendor's security team. That inventory is also what your managed IT program needs to stay current under Reg S-P's service provider oversight requirements.

Actionable tip: If you use a document storage service, a CRM, or an e-signature tool, find the vendor's security page and check the date of their most recent SOC 2 Type II report. If you can't find one, or if the last report is more than 18 months old, that vendor belongs on your risk review list.

Test the Plan Once a Year

A tabletop exercise takes about 90 minutes. You walk through a hypothetical breach scenario, step by step, and find the gaps before a real incident does. FINRA examiners and cyber insurers both ask whether firms have tested their plans. A firm that runs an annual tabletop exercise can answer yes with documentation. A firm that hasn't can't.

Your financial services cybersecurity program should include the tabletop exercise date in your written documentation. It's a one-line entry that shows your program is active, not just a document sitting in a folder.

Frequently Asked Questions

Do I have to notify clients if a vendor was breached, not me?

Yes, if the vendor was processing or storing client personally identifiable financial information on your behalf. Under amended SEC Reg S-P, your service provider oversight obligation means a vendor breach that exposes your clients' data triggers your notification requirements, not just the vendor's. The vendor notifying their own clients doesn't satisfy your separate obligation to your clients.

What counts as "personal financial information" under Reg S-P?

Reg S-P covers "nonpublic personal information," which includes Social Security numbers, account numbers, tax identification numbers, financial account details, and any information tied to a client's financial relationship with your firm. If a vendor's breach exposed any of this for your clients, the notification requirements apply.

What happens if we miss the 30-day notification deadline?

Late notification is a regulatory violation. The SEC can issue a deficiency letter, a censure, or a civil monetary penalty. The penalty range depends on the number of clients affected, the sensitivity of the data, and whether the firm has prior violations. Late notification combined with a poorly documented response is a more serious finding than a breach that was handled quickly and properly, even if imperfectly.

Does cyber insurance cover client notification costs?

Most cyber insurance policies cover notification costs, including printing, mailing, and credit monitoring services for affected clients. Some policies also cover legal fees for regulatory response and forensics costs. What most policies don't cover is a regulatory fine, since penalties are typically excluded. Review your policy's coverage for notification expenses and regulatory defense costs before you have a breach, not after.

Ready to Test Your Firm's Response Plan?

A 30-day notification deadline sounds manageable until you're three days in and you still don't know what was exposed or who to call. The firms that get through a data breach without lasting regulatory consequences are the ones that had a plan in place before they needed it. If your firm doesn't have a written incident response plan, a current vendor inventory, and a designated response lead, those are three gaps worth closing this week.

GDS works with RIAs, CPA firms, and mortgage brokers across South Florida to build the documentation and controls that satisfy Reg S-P, FINRA examiners, and cyber insurers. Book your free assessment and we'll show you exactly where your gaps are in one meeting.

financial servicesdata breachsec complianceria cybersecurityincident response
Back to Blog

Get Your Questions Answered

We're happy to help. Call us at (786) 386-1092 or send us a message.