Financial Services Cybersecurity: SEC, FINRA, Insurers

Cybersecurity for Financial Services: What the SEC, FINRA, and Your Insurance Carrier All Agree On

Regulators and cyber insurers ask financial firms for largely the same core controls: multi-factor authentication, endpoint protection, tested backups, tight access control, a written incident response program, email security and archiving, vendor oversight and a regular risk assessment. Build your program around those and you address most of what each of them looks for.

Which rules apply depends on what kind of firm you are. SEC-registered investment advisers and broker-dealers fall under the SEC's Regulation S-P. Broker-dealers are also FINRA members and follow FINRA's rules. Non-bank financial institutions that aren't SEC-registered, such as some tax preparers, mortgage brokers and financial planners, fall under the FTC Safeguards Rule issued under the Gramm-Leach-Bliley Act (GLBA). Cyber insurance carriers set their own underwriting requirements on top. This article covers the controls those sources have in common and what each looks like in practice.

The controls they share

Multi-factor authentication (MFA)

The FTC Safeguards Rule requires MFA for anyone accessing customer information systems. SEC and FINRA examiners routinely ask about it, and cyber insurance applications almost always do. MFA should cover email, remote access, administrative accounts and any platform that holds client data.

Endpoint detection and response (EDR)

Many insurance applications now ask specifically whether you run EDR rather than traditional antivirus, and examiners look at how endpoints are protected and monitored. Endpoint detection and response watches for suspicious behavior and can isolate a compromised computer while it's investigated. Our EDR explainer covers how it differs from antivirus.

Encrypted backups with tested recovery

Regulators expect firms to protect customer records and be able to recover them, and insurers increasingly ask whether backups are isolated from the main network and tested. A backup only proves its value when it has actually been restored. See our backup and disaster recovery explainer and our backup and disaster recovery service.

Access control and least privilege

Each person should have access to what their job requires and nothing more, and a departing employee's access should end on their last day. Single sign-on (SSO) and centralized identity management make that practical to maintain.

Written incident response program

The amended Regulation S-P requires SEC-registered advisers and broker-dealers to maintain a written incident response program and to notify affected customers within 30 days of discovering unauthorized access to sensitive customer information. The FTC Safeguards Rule requires a written incident response plan, and since May 2024, notice to the FTC within 30 days when unencrypted information of 500 or more consumers is involved. Insurers usually ask whether a plan exists and has been tested. Our incident response plan guide covers what a good one contains.

Email security, training and archiving

Phishing remains one of the most common ways attackers get in. Email filtering, link scanning and regular security awareness training reduce that risk; training is a standard part of NerdSquad cybersecurity plans. See also how to spot a phishing email. Archiving is a separate obligation: advisers keep required records under Advisers Act Rule 204-2, and broker-dealers under Exchange Act Rule 17a-4 and FINRA Rule 4511. Since 2022, Rule 17a-4 allows either write-once storage or an audit-trail alternative.

Vendor oversight

Regulation S-P now requires covered firms to oversee service providers that handle customer information, including how those providers will notify you of a breach. The FTC Safeguards Rule has a similar requirement. Insurers ask about it as well. Keep a list of significant technology vendors, a record of how each was assessed and evidence of periodic review.

Risk assessment

The FTC Safeguards Rule requires a written risk assessment. For SEC-registered firms, a periodic assessment is the practical basis for the written policies Regulation S-P requires, and examiners expect to see one. Insurers use your answers to price coverage. Our risk assessment explainer describes the process.

A note on SEC disclosure rules

The SEC's 2023 cybersecurity disclosure rules, including Form 8-K Item 1.05 reporting of material incidents, apply to public companies. A separate rule the SEC proposed for advisers' cybersecurity risk management was withdrawn in June 2025. For most advisers and broker-dealers, the current obligations come from amended Regulation S-P, with compliance dates of December 3, 2025 for larger entities and June 3, 2026 for smaller ones, along with Regulation S-ID for identity theft red flags.

The IT implication is the same either way. You need monitoring that can detect an incident, such as remote monitoring and management (RMM) and EDR, a way to classify what happened, and a clear path to get the facts to the people who decide on notification within the deadline.

NerdSquad is not a law firm; confirm your obligations with your compliance counsel.

Why smaller firms are targeted

Financial firms hold money, personal information and access to other accounts, which makes them attractive regardless of size. A small advisory practice is not too small to notice. FINRA and SEC examination observations point to familiar weaknesses: stolen credentials from phishing, unpatched systems and loose access controls. These are basics, and they are fixable.

Zero Trust in practice

Zero Trust is an approach to architecture rather than a single product. It assumes no user or device is trusted by default and verifies each access request: who the user is, whether the device is known and healthy, and whether the request fits normal behavior. For firms with remote advisers, more than one office and cloud platforms such as a CRM and portfolio management system, it matches how work actually happens.

Cyber insurance

Cyber insurance is available through NerdSquad's licensed insurance partner. Separately, we help clients put in place the controls insurers ask about and complete security questionnaires accurately. For more, see cyber insurance requirements: what your policy requires.

How NerdSquad helps

Firms that handle this well aren't doing anything exotic. They have MFA everywhere, EDR on every endpoint, encrypted and tested backups, documented access control, an incident response program they've reviewed, archiving that captures what it should, a current risk assessment and vendor records. NerdSquad Managed IT Services, a Managed Service Provider (MSP) based in Naples, helps financial firms across Southwest Florida put those cybersecurity controls in place, document them and keep them maintained. Your compliance officer owns the program; we help build and run the technical side.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: IT for financial advisers and wealth managers