Yes. NerdSquad helps advisory firms, broker-dealers and other financial businesses put the technology controls and documentation in place that Regulation S-P, FINRA rules and the GLBA Safeguards Rule call for, and we support you through examinations. Your compliance officer and counsel decide whether the firm is compliant; we make sure the IT side gives them something solid to work with.
Compliance in financial services is ongoing work. It touches how accounts are set up, who can see client data, how communications are archived, which vendors you rely on and what happens when something goes wrong. The technology side is where we help. Below is how each framework applies and what we do for it.
Getting this right first saves a lot of confusion later.
For a plain-English overview, see our SEC and FINRA explainer.
Regulation S-P is how the SEC applies GLBA's privacy and safeguarding requirements to the firms it regulates. Amendments adopted in May 2024 made it considerably more specific. Firms must now have:
Compliance dates were December 3, 2025 for larger entities and June 3, 2026 for smaller entities, so both are now in effect. Regulation S-ID, the identity theft red flags rule, also applies to many advisers and broker-dealers.
On the IT side, that means monitoring that can spot an incident, a written plan your team has walked through, logs that show what was accessed, and a vendor list with documented reviews. Our incident response plan guide covers what a workable plan contains.
You may also have read about the SEC's 2023 cybersecurity disclosure rules. Those (including Form 8-K Item 1.05 incident reporting) apply to public companies. A separate cybersecurity rule proposed for advisers was withdrawn in June 2025.
Advisers must keep required records, including certain written communications, under Advisers Act Rule 204-2. Broker-dealers keep records under Exchange Act Rule 17a-4 and FINRA Rule 4511. Rule 17a-4 has allowed either write-once, read-many (WORM) storage or an audit-trail alternative since 2022.
In practice, business communications by email, text and chat need to be captured by an archiving system and kept for the required period. The SEC's off-channel communications enforcement in recent years, with substantial fines, centered on business conducted over personal texting and messaging apps that weren't archived. We deploy and monitor archiving systems and check that they're capturing what they should, including from mobile devices and collaboration tools.
The amended Safeguards Rule, with most requirements effective since June 2023, requires covered firms to maintain a written information security program (WISP) that includes:
Since May 13, 2024, covered firms must also notify the FTC within 30 days when unencrypted information of 500 or more consumers is involved in a security event. Our GLBA explainer goes deeper.
Some financial businesses, such as insurance agencies and tax preparers, accept card payments. PCI DSS v4.0.1 is the current version, and since March 31, 2025 it requires MFA for all access into the cardholder data environment. The most effective approach is usually to keep as few systems as possible in contact with card data. We help design payment setups with that in mind.
The technical requirements overlap across these frameworks. For financial clients we implement and maintain:
Security awareness training is a standard part of NerdSquad cybersecurity plans, which helps with the training expectations in each framework.
We manage the technology side. We are not your chief compliance officer, legal counsel or auditor, and we don't certify that a firm is compliant. That determination belongs to your compliance professionals and, ultimately, your regulator. What we provide is an environment that is built and maintained to support your compliance program, plus accurate records your compliance team can rely on during an exam.
NerdSquad is not a law firm; confirm your obligations with your compliance counsel.
Rules in this area have changed a lot since 2023. If your IT controls haven't been reviewed against the amended Regulation S-P or the amended Safeguards Rule, now is a good time. Our IT support for financial services firms starts with that review. For a wider view of other frameworks, see Can you help us meet compliance requirements like HIPAA, PCI and SOC 2?
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.