The Reg S-P Clock Ran Out: Then The Breaches Began

Shield graphic with headline: The Reg S-P clock ran out, then the breaches began. Advice for small RIAs facing 2026 SEC exams.

Last updated: August 4, 2026 · Author: Zach Carothers · Reading time: 6 minutes

What Happened After the Reg S-P Deadline?

On July 28, 2026, three wealth management and advisory firms, including Gold Peak Wealth Management, appeared on breach trackers in a single day, with two more popping up before the month closed. Every SEC-registered adviser now operates under the amended Regulation S-P requirements, with compliance being required since June 3, 2026.

In the spring, we warned that the clock was ticking on the June 3 Reg S-P deadline for smaller RIAs. The clock has now run out, and the thing we warned about is happening on schedule.

The Previous Deadline Is Now the Base of Your Exam

In review: the SEC now expects a written incident response program, customer notification procedures, and vendor oversight to exist before a breach happens, not to be assembled by outside counsel while one unfolds. That is certainly the core of the amendment, but if you want to know more details, we broke down all four requirements, including the 30-day client notification window and the 72-hour vendor notification standard, in our pre-deadline guide to the Reg S-P amendments.

What matters now is the sequencing. Gold Peak surfaced on July 28, four weeks after the compliance date for smaller advisers. The attacks aren’t stopping because of a regulation, and every incident from here forward lands on a firm that either did the preparation or didn’t.

Adviser Size Threshold Reg S-P Compliance Date
Larger advisers $1.5 billion or more in AUM December 3, 2025
Smaller advisers Less than $1.5 billion in AUM June 3, 2026

Does This Affect You If You’re Under $1.5B in AUM?

Almost Certainly. Wealth management and advisory firms are surfacing in breach trackers week after week, and most of these incidents never show up in mainstream publications. But your regulators and peer firms are watching.

Your SEC exam team will be watching, as well. The SEC’s 2026 Division of Examinations priorities explicitly flag amended Reg S-P compliance. Examiners in 2026, and probably from here on out, will ask to see your written incident response program and your customer notification procedures. Unfortunately, this is not just implied, it is literally on their checklist.

Why Your Incident Response Program Now Doubles as Your Exam Strategy

For a small RIA, the hard truth is structural: the documents that satisfy an SEC examiner are exactly the same documents that determine whether a real breach becomes a managed incident or a crisis.

Picture two outcomes:

Firm A has a written incident response program before a breach hits. It names the point person, lists escalation contacts, and when the breach happens, the team has a playbook. The incident may be painful, but it is contained. The examiner later sees that the program was in place beforehand, and compliance is demonstrated correctly.

Firm B gets breached without a written program in place and the team scrambles to figure out notification, escalation, and disclosure. When the examiner asks for the program months later, the answer is “we did not have one.” The same breach becomes a compliance and reputational liability, not just a security incident.

The firms working through July’s incidents are learning this distinction in the hardest way. Almost every firm can find a valuable lesson in at least one of these incidents.

What Should You Do This Week? The Three-Step Checklist

If you are a smaller adviser and any of these three items is unfinished, this is the week to close it. In order.

  1. Document your incident response program. Name the point person, and list the escalation chain (including your broker-dealer). Describe the steps from discovery through customer notification. One page is fine. And remember, “done is better than perfect”.
  2. Review your vendor agreements. Amended Reg S-P requires oversight of vendors who handle customer information. Pull your processor, cloud backup, and practice management system contracts. Do they address breach notification? Do they allow you to audit their controls? If the answer is no, you have a gap that needs addressing.
  3. Brief your principal. A 15-minute conversation about Reg S-P and incident response beats scrambling when you get a breach notice or facing an examiner with nothing to show.

If you want help building or reviewing your incident response plan against SEC expectations, or if you want to stress-test it against realistic scenarios, TorchLight offers a no-cost 30-minute consultation to scope what your firm needs.

The Bottom Line

When we published our first look at the amended Reg S-P rules, the deadline was eight weeks out and the question was whether firms would be ready. The deadline is now in the rearview mirror, the breach listings are not slowing down, and the exams are coming. All three are running in parallel for small RIAs, and the firms that built their incident response program before they needed it will come out cleaner on the other side.

Frequently Asked Questions

What is Regulation S-P?

Regulation S-P is the SEC rule, first adopted in 2000, that governs how financial firms protect customer information. The 2024 amendments added required written incident response programs, customer breach notification, and oversight of service providers who handle customer data.

When did amended Reg S-P compliance become required for smaller RIAs?

June 3, 2026. Registered investment advisers with less than $1.5 billion in assets under management had until that date to comply. Larger advisers had to comply by December 3, 2025.

How quickly must an adviser notify customers after a breach?

As soon as practicable, and no later than 30 days after becoming aware that sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. Service providers must notify the adviser within 72 hours of becoming aware of a breach.

What will SEC examiners ask for in a 2026 exam?

The Division of Examinations’ 2026 priorities flag amended Reg S-P compliance. Expect examiners to request your written incident response program, customer notification procedures, vendor oversight documentation, and the records showing they were in place before any incident.

What happened to Gold Peak Wealth Management?

Gold Peak Wealth Management, a US wealth management firm, appeared on breach trackers on July 28, 2026, attributed to the threat actor CRPxO. Two other advisory-sector firms were listed the same day, with two more before the end of July. These listings reflect threat actor claims tracked by breach monitoring services.


About TorchLight

TorchLight is a Secured & Managed IT provider focused on making cybersecurity an enabler of every next opportunity. Our team delivers 24×7 monitoring, detection and response, virtual CISO services, and incident response for regulated mid-market organizations. Our tagline: Risk Aligned. Reward Defined.

Sources

  1. SEC: SEC Adopts Rule Amendments to Regulation S-P (May 16, 2024)
  2. SEC: Division of Examinations Announces 2026 Priorities
  3. Paul Hastings: SEC Division of Examinations Announces 2026 Priorities
  4. Breachsense: Gold Peak Wealth Management Data Breach
  5. Breachsense: Data Breaches in July 2026