Is Your Firm Reg S-P Ready?
Find Out in 5 Minutes.
The SEC’s amended Regulation S-P is now in force for every registered investment adviser. This one-page checklist walks you through the 18 controls examiners expect to see, lets you score your firm, and shows you exactly where your exposure is. No form-fatigue, no sales pressure. Just a clear read on where you stand.
A Common Misconception
Your Platform Defends to the 50-Yard Line. Then It Stops.
Many advisers assume the cybersecurity built into their brokerage or custodial platform covers the firm as a whole. It does not. The platform primarily secures its own environment. While many platforms offer security features you can use, such as SSO, MFA, and device controls, they do not secure your firm’s broader technology environment. Think of it as a strong defense that holds to the 50-yard line and then stands there watching the offense score touchdown after touchdown.
Everything on your side of the field is still exposed:
The local computers in your office
Your email
Your CRM
Your portfolio software
And the everyday devices where client data actually lives.
A phishing email, an unpatched laptop, or a stolen password on your end never touches the platform’s defenses; and that’s exactly where most attackers tend to hit first.
Regulation S-P places responsibility on your firm to safeguard customer information under your control and to oversee the vendors that handle it on your behalf. You cannot outsource that responsibility to your platform provider. The rule requires your firm to maintain safeguards for customer information, keep an incident response program, oversee service providers, and meet applicable notification obligations. Those responsibilities remain yours even when you rely on third-party platforms and vendors. Strong RIA cybersecurity is everything that happens on your side of the field.
Instant .pdf download: Download the Ria Cybersecurity Readiness Checklist Here

What’s Inside The Checklist
18 Controls. One Score. Zero Guesswork.
The checklist turns the SEC’s safeguarding rules into a simple self-assessment you can complete at your desk. Check what your firm already has in place, total your score, and read your readiness level. It covers the six areas examiners scrutinize most:
Governance and written policies, including your WISP and incident response program
How you protect client data: MFA, encryption, and access controls
Detection and recovery, from 24/7 monitoring to tested backups
Reg S-P breach notification, including the 30-day client notice requirement
Vendor and third-party oversight, including the 72-hour vendor breach-notice rule
People and recordkeeping, the evidence your examiner will ask to see
Why Now
The Deadline Already Passed. The Exams Are Next.
As of June 3, 2026, every SEC-registered adviser must maintain a written incident response program, notify affected clients within 30 days of a breach, and oversee the vendors that touch client data. Large advisers have been on the hook since December 2025. Cybersecurity sits at the top of the SEC’s examination priorities, and examiners now ask for documented evidence, not just good intentions. Most firms discover their gaps during an exam. This checklist helps you find them first, while there is still time to fix them.
Who It’s For
Principals and managing partners who sign the firm’s compliance attestations
Chief Compliance Officers preparing for the next SEC exam
Operations and IT leaders who own the firm’s security stack
Any RIA or wealth management firm that holds sensitive client data and cannot afford to find out about a gap the hard way
About TorchLight
Cybersecurity-First Managed IT for Regulated Firms
TorchLight has spent nearly two decades securing IT for organizations in highly regulated, trust-driven industries where a single breach can undo years of client confidence. We pair a 24/7/365 security operations center with documented, audit-ready controls, so your firm is not just protected, it can prove it. Our team’s response times are measured in minutes, and our clients rate us 4.95 out of 5. When the examiner asks how you safeguard client information, we make sure you have the evidence to answer.
Know Your Score – Then Close The Gaps
Download the checklist, score your firm, and see where you stand against Regulation S-P. If you want a second set of eyes on your results, book a 30-minute consult and walk through your gaps with a TorchLight advisor. No cost, no commitment.
Your information stays private. We will never sell your data, and the checklist is yours to keep whether or not we ever speak.
Instant .pdf download: Download the Ria Cybersecurity Readiness Checklist Here
