The SEC Isn't Just Asking Who Your IT Provider Is. It's Asking for Your Regulation S-P Compliance Program.

Your IT provider manages technology. Your investment adviser remains responsible for regulatory compliance.

Last updated: July 2026

Many investment advisers rely on a managed service provider, or MSP, to maintain their technology and protect their systems. A qualified IT provider can be an important part of a firm's cybersecurity strategy.

But having an IT provider does not, by itself, establish compliance with Regulation S-P.

The amended rule requires SEC-registered investment advisers to develop, implement, maintain and document a broader program for protecting customer information. The SEC's requirements include written safeguards, incident response procedures, service-provider oversight, customer notification processes and records demonstrating compliance.

The distinction matters:

Your IT provider manages technology. Your investment adviser remains responsible for regulatory compliance.

Technology Support Is Not the Same as Compliance

Most IT providers are retained to perform technical services such as:

  • Managing computers, servers and networks

  • Installing and maintaining security software

  • Configuring Microsoft 365 or Google Workspace

  • Deploying operating-system and software updates

  • Managing backups

  • Responding to technical support requests

  • Monitoring systems for security threats

These services are valuable, and many of them support a firm's cybersecurity safeguards.

Regulation S-P, however, requires more than the installation and maintenance of technology. It requires a firm to establish and maintain written policies and procedures designed to protect customer information and respond appropriately when unauthorized access or use occurs. Covered institutions must also maintain written records documenting their compliance.

An antivirus subscription, firewall or IT support agreement does not automatically demonstrate that the firm has satisfied those responsibilities.

Your IT Provider May Be One of the Vendors You Must Oversee

The amended Regulation S-P places significant emphasis on service-provider oversight.

Investment advisers must establish, maintain and enforce written policies and procedures reasonably designed to oversee service providers with access to customer information. This includes appropriate due diligence, ongoing monitoring and measures intended to ensure that the firm receives timely notice after a service provider becomes aware of certain security breaches.

An MSP may therefore be part of the firm's security program, but it may also be one of the service providers the firm is required to evaluate and oversee.

The adviser should be prepared to determine and document:

  • What customer information the provider can access

  • What systems and devices the provider manages

  • How the provider safeguards customer information

  • How security incidents will be reported to the adviser

  • Whether the provider is meeting its contractual and security obligations

  • How the adviser conducts and documents continuing oversight

Hiring a vendor does not transfer the adviser's regulatory responsibility to that vendor.

Regulation S-P Requires an Incident Response Program

The amended rule requires covered institutions to develop, implement and maintain written policies and procedures for an incident response program reasonably designed to detect, respond to and recover from unauthorized access to or use of customer information.

The program must address more than the technical repair of a compromised computer or account. It should enable the firm to:

  • Assess the nature and scope of an incident

  • Identify affected systems and customer information

  • Contain and control unauthorized access or use

  • Determine whether customer notification is required

  • Provide required notification as soon as practicable and generally no later than 30 days

  • Document the incident, the firm's response and its notification decisions

An IT provider may assist with investigating or containing an incident. The adviser, however, must still make and document the regulatory decisions arising from that incident.

Examiners Will Look Beyond the IT Agreement

Regulation S-P is now an identified SEC examination priority.

The SEC's Fiscal Year 2026 Examination Priorities state that examinations will assess compliance with Regulation S-P and focus on firms' policies and procedures, internal controls, oversight of third-party vendors and governance practices.

The SEC has also conducted Regulation S-P outreach for firms that included discussion of the amended obligations and what firms should expect when interacting with an examination team.

An adviser should therefore be prepared to produce evidence of an implemented program, which may include:

  • Written safeguards policies and procedures

  • An incident response plan

  • Cybersecurity risk assessments

  • Records of security testing and remediation

  • Service-provider due diligence and monitoring

  • Vendor agreements or other written assurances

  • Employee cybersecurity training records

  • Records of detected unauthorized access

  • Documentation of incident-response decisions

  • Customer notification records

  • Records supporting any determination that notification was not required

These are compliance records. They are not replaced by a statement that the firm uses an IT company.

Written Policies Alone Are Not Enough

A firm may have a written cybersecurity policy and still be unable to demonstrate that its safeguards are operating as intended.

Effective implementation requires the firm to connect its policies to actual practices. For example:

  • Does the firm regularly assess its cybersecurity risks?

  • Are devices and systems being tested against the firm's safeguards?

  • Are deficiencies documented and remediated?

  • Are personnel receiving and completing cybersecurity training?

  • Are service providers evaluated and monitored?

  • Has the incident response plan been tested?

  • Can the firm quickly identify what customer information may be affected by an incident?

  • Can the firm produce organized records during an examination?

The SEC's examination focus on internal controls, governance and vendor oversight reinforces that compliance involves ongoing implementation and evidence—not simply possessing a policy document.

The Right Model: Technology and Independent Compliance Oversight

Investment advisers do not need to choose between an IT provider and a cybersecurity compliance program. They serve different but complementary purposes.

The IT provider maintains and supports the firm's technology.

The cybersecurity compliance program helps the firm establish, assess, document, test and demonstrate its regulatory safeguards.

A complete approach may involve cooperation among the firm's compliance personnel, leadership, technology providers and independent cybersecurity compliance resources.

The goal is not to diminish the importance of the MSP. It is to recognize that technical support is only one part of the adviser's larger regulatory obligation.

The Question Every Adviser Should Be Able to Answer

The question is no longer simply:

"Do we have an IT provider?"

The more important question is:

"Can we demonstrate our Regulation S-P compliance program if the SEC asks for evidence?"

Technology helps protect the firm's systems.

A documented cybersecurity compliance program demonstrates how the firm is fulfilling its regulatory responsibilities.

Investment advisers should have both.

References

  1. U.S. Securities and Exchange Commission, Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information. The SEC's final rule materials describe the written incident-response, notification, expanded safeguards and recordkeeping requirements.

  2. SEC Adopts Rule Amendments to Regulation S-P to Enhance Protection of Customer Information, May 16, 2024. The SEC announcement summarizes the incident-response and 30-day customer-notification provisions.

  3. SEC Division of Examinations, Fiscal Year 2026 Examination Priorities. The priorities identify Regulation S-P as an examination focus and specifically reference policies and procedures, internal controls, third-party vendor oversight and governance.

  4. SEC Compliance Outreach—Regulation S-P. SEC staff discussed the amended obligations and what firms should expect when interacting with examination teams.

  5. Holland & Knight, "Regulation S-P Amendments: Compliance Deadline Approaching for 'Smaller Entities,'" May 7, 2026. The alert discusses incident response, breach notification and service-provider oversight requirements.

  6. Baker Donelson, "Regulation S-P: June 3, 2026 Compliance Deadline for Smaller Investment Advisers," February 24, 2026. The publication addresses policies, training, service-provider oversight, ongoing monitoring and required compliance records.

This article is provided for general educational purposes and should not be considered legal advice. Firms should consult qualified legal or compliance professionals regarding their particular obligations.

Next
Next

Regulation S-P: June 3, 2026 Compliance Deadline for Smaller Investment Advisers