SEC, FINRA and GLBA Compliance IT for Financial Firms

Do You Help Financial Advisors and Firms Stay SEC, FINRA, and GLBA Compliant?

Yes. NerdSquad helps advisory firms, broker-dealers and other financial businesses put the technology controls and documentation in place that Regulation S-P, FINRA rules and the GLBA Safeguards Rule call for, and we support you through examinations. Your compliance officer and counsel decide whether the firm is compliant; we make sure the IT side gives them something solid to work with.

Compliance in financial services is ongoing work. It touches how accounts are set up, who can see client data, how communications are archived, which vendors you rely on and what happens when something goes wrong. The technology side is where we help. Below is how each framework applies and what we do for it.

Who regulates whom

Getting this right first saves a lot of confusion later.

  • SEC-registered investment advisers are overseen by the SEC. Smaller advisers registered only with a state are overseen by that state's securities regulator.
  • Broker-dealers are registered with the SEC and are members of FINRA, a self-regulatory organization that writes and enforces its own rules for member firms. FINRA does not regulate investment advisers.
  • Other non-bank financial institutions, such as tax preparers, mortgage brokers and some financial planners or CPA firms that aren't SEC-registered, generally fall under the FTC Safeguards Rule issued under the Gramm-Leach-Bliley Act (GLBA).

For a plain-English overview, see our SEC and FINRA explainer.

Regulation S-P (SEC-registered advisers and broker-dealers)

Regulation S-P is how the SEC applies GLBA's privacy and safeguarding requirements to the firms it regulates. Amendments adopted in May 2024 made it considerably more specific. Firms must now have:

  • A written incident response program to detect, respond to and recover from unauthorized access to customer information.
  • Notification to affected customers within 30 days of discovering that sensitive customer information was, or was reasonably likely to have been, accessed without authorization.
  • Oversight of service providers that handle customer information, including how they will tell you about a breach.
  • Records that document compliance with these requirements.

Compliance dates were December 3, 2025 for larger entities and June 3, 2026 for smaller entities, so both are now in effect. Regulation S-ID, the identity theft red flags rule, also applies to many advisers and broker-dealers.

On the IT side, that means monitoring that can spot an incident, a written plan your team has walked through, logs that show what was accessed, and a vendor list with documented reviews. Our incident response plan guide covers what a workable plan contains.

You may also have read about the SEC's 2023 cybersecurity disclosure rules. Those (including Form 8-K Item 1.05 incident reporting) apply to public companies. A separate cybersecurity rule proposed for advisers was withdrawn in June 2025.

Books and records

Advisers must keep required records, including certain written communications, under Advisers Act Rule 204-2. Broker-dealers keep records under Exchange Act Rule 17a-4 and FINRA Rule 4511. Rule 17a-4 has allowed either write-once, read-many (WORM) storage or an audit-trail alternative since 2022.

In practice, business communications by email, text and chat need to be captured by an archiving system and kept for the required period. The SEC's off-channel communications enforcement in recent years, with substantial fines, centered on business conducted over personal texting and messaging apps that weren't archived. We deploy and monitor archiving systems and check that they're capturing what they should, including from mobile devices and collaboration tools.

The FTC Safeguards Rule (other financial institutions)

The amended Safeguards Rule, with most requirements effective since June 2023, requires covered firms to maintain a written information security program (WISP) that includes:

  • A designated qualified individual responsible for the program.
  • A written risk assessment.
  • Encryption of customer information in transit and at rest.
  • Multi-factor authentication for anyone accessing customer information systems.
  • Access controls, staff training, vendor oversight and a written incident response plan.
  • A periodic report to the board or senior leadership.

Since May 13, 2024, covered firms must also notify the FTC within 30 days when unencrypted information of 500 or more consumers is involved in a security event. Our GLBA explainer goes deeper.

PCI DSS, if you take card payments

Some financial businesses, such as insurance agencies and tax preparers, accept card payments. PCI DSS v4.0.1 is the current version, and since March 31, 2025 it requires MFA for all access into the cardholder data environment. The most effective approach is usually to keep as few systems as possible in contact with card data. We help design payment setups with that in mind.

What we put in place

The technical requirements overlap across these frameworks. For financial clients we implement and maintain:

  1. Security program documentation. Records of your environment, access controls and vendors in a form your compliance team and an examiner can follow.
  2. Risk assessments. Periodic technology risk assessments that identify gaps and track remediation. See our risk assessment explainer.
  3. Encryption. For data at rest and in transit, including laptops and phones that leave the office.
  4. Multi-factor authentication. On email, remote access, administrative accounts and client data platforms. See MFA explained.
  5. Access control and logging. Least-privilege access with logs of who accessed what, supported by single sign-on (SSO).
  6. Communications archiving. Configured, monitored and checked for gaps.
  7. Endpoint protection. Endpoint detection and response (EDR) on every device, with 24/7 SOC monitoring where your plan includes it.
  8. Backup and recovery. Encrypted, tested and documented through our backup and disaster recovery service.
  9. Incident response. A written plan connected to our monitoring, so there's a clear path from alert to decision.
  10. Vendor oversight records. A list of technology vendors with documented reviews, which Regulation S-P now expects.

Security awareness training is a standard part of NerdSquad cybersecurity plans, which helps with the training expectations in each framework.

What we don't do

We manage the technology side. We are not your chief compliance officer, legal counsel or auditor, and we don't certify that a firm is compliant. That determination belongs to your compliance professionals and, ultimately, your regulator. What we provide is an environment that is built and maintained to support your compliance program, plus accurate records your compliance team can rely on during an exam.

NerdSquad is not a law firm; confirm your obligations with your compliance counsel.

When to review

Rules in this area have changed a lot since 2023. If your IT controls haven't been reviewed against the amended Regulation S-P or the amended Safeguards Rule, now is a good time. Our IT support for financial services firms starts with that review. For a wider view of other frameworks, see Can you help us meet compliance requirements like HIPAA, PCI and SOC 2?


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: IT for financial advisers and wealth managers