The SEC regulates investment advisers and broker-dealers; FINRA regulates broker-dealers only. Between them, they set the privacy, cybersecurity and recordkeeping rules that shape IT at securities firms, and the SEC's amended Regulation S-P now applies to firms of every size.
The two names get mentioned together so often that people assume they do the same job. They don't. Knowing which one oversees your firm, and which rules actually reach your IT, is the starting point for any sensible compliance program at an advisory firm or brokerage.
What do SEC and FINRA stand for?
SEC: Securities and Exchange Commission. The federal agency that regulates the U.S. securities markets, created by the Securities Exchange Act of 1934. It oversees public company disclosures, registered investment advisers, broker-dealers, exchanges and securities offerings, and it writes and enforces the rules for them.
FINRA: Financial Industry Regulatory Authority. A self-regulatory organization (SRO) overseen by the SEC. FINRA is not a government agency. It was formed in 2007 from the NASD and the regulatory arm of the NYSE. Broker-dealers that do business with the public generally must be FINRA members and follow FINRA's rules.
The simple way to think about it
The SEC sets the federal rules for the whole securities industry and supervises FINRA. FINRA writes and enforces its own rulebook for broker-dealers, examines member firms and disciplines them. An investment adviser that isn't also a broker-dealer deals with the SEC (or its state securities regulator) and generally never hears from FINRA.
For IT purposes, both care about the same questions: Is client information protected? Can you detect and respond to an incident? Are records and communications preserved so an examiner can review them?
Who falls under which regulator?
- Registered investment advisers (RIAs): regulated by the SEC once they reach the federal threshold (generally around $100 million in assets under management); smaller advisers usually register with their state securities regulator. Not FINRA members.
- Broker-dealers: regulated by both the SEC and FINRA.
- Dually registered firms (adviser and broker-dealer): subject to both sets of rules.
- Public companies: subject to SEC disclosure rules, including the cybersecurity disclosure rules described below.
The rules that reach your IT
Neither regulator has one comprehensive cybersecurity rulebook like HIPAA's Security Rule. The requirements come from several rules, plus examination priorities and guidance.
Regulation S-P (privacy and safeguarding of customer information)
Reg S-P is how GLBA's privacy and safeguarding requirements apply to SEC-registered advisers, broker-dealers and investment companies. The SEC amended it in May 2024. The amended rule requires:
- A written incident response program to detect, respond to and recover from unauthorized access to customer information
- Customer notification as soon as practicable, and no later than 30 days after discovering that sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization
- Service provider oversight, including making sure providers notify you of a breach affecting your customers' information
- Recordkeeping that documents compliance
Larger entities had to comply by December 3, 2025, and smaller entities by June 3, 2026. As of now, the amended rule applies to every covered firm, so it is time to make sure your incident response plan and vendor contracts actually reflect it. Our guide to the Regulation S-P amendments walks through each requirement in more detail.
Regulation S-ID (identity theft red flags)
Requires covered firms to maintain a written program to detect, prevent and mitigate identity theft involving customer accounts.
Books-and-records rules
- Investment advisers: Advisers Act Rule 204-2 requires advisers to keep specified books and records, including written communications related to advice, generally for five years. Electronic records must be protected from alteration and be retrievable.
- Broker-dealers: Exchange Act Rules 17a-3 and 17a-4 and FINRA Rule 4511 set what must be kept and for how long (often three to six years depending on the record). Since amendments in 2022, Rule 17a-4 lets firms keep electronic records either in a non-rewriteable, non-erasable format (WORM storage) or in a system with a complete audit trail that can recreate any modified or deleted record.
FINRA rules for broker-dealers
- Rule 4370 (business continuity plans): requires a written plan for operating through a significant business disruption, including data backup and recovery and alternate communications.
- Rule 3110 (supervision): requires supervisory systems, including review of electronic communications. Email and message archiving requirements flow from here and from the books-and-records rules.
What about the SEC's 2023 cybersecurity rules?
The SEC's 2023 cybersecurity disclosure rules (including Form 8-K Item 1.05 for material incidents) apply to public companies, not to private advisory firms. The SEC also proposed a separate cybersecurity risk-management rule for advisers and funds, but withdrew it in June 2025. For most RIAs, amended Reg S-P is the cybersecurity rule that matters, along with examiners' general expectations.
Off-channel communications
From 2021 through 2024, the SEC (along with the CFTC) brought a wave of enforcement cases against firms whose employees discussed business over personal texting and messaging apps that the firm wasn't capturing. Fines in those cases were very large, and they reached firms well beyond Wall Street's biggest names.
The lesson for any adviser or broker-dealer: if staff use personal phones or unapproved apps for business communication, those messages may be records you are required to keep. The fix is part policy and part technology, using approved, archived channels and managed devices.
What examiners ask for
SEC and FINRA examinations regularly cover cybersecurity. Examiners commonly ask for:
- Written cybersecurity policies and the incident response program
- Vendor and service provider oversight records
- Access controls and authentication practices, including MFA
- How client data is classified and protected
- Business continuity and disaster recovery plans and test results
- Records of staff security training
- Electronic communications retention and supervision
Missing documentation tends to produce deficiency letters and follow-up, and serious gaps can lead to enforcement referrals.
How this connects to managed IT services
Securities firms have some of the most demanding IT requirements of any industry. A Managed Service Provider (MSP) supporting them needs to handle:
- Records retention that meets the applicable rule, whether WORM or audit-trail storage for broker-dealers or protected, retrievable archives for advisers
- Email and communications archiving that is searchable and supervisable, typically built around Microsoft 365
- Endpoint protection through EDR on every device that touches firm systems
- MFA across all firm systems
- Audit logging of system access and changes
- Patch management and monitoring through RMM
- An incident response plan that is written and practiced, so the 30-day Reg S-P notification clock doesn't start while you are still figuring out who to call
- Mobile device management to control which apps can reach firm data
- Backup and disaster recovery that supports your business continuity plan
NerdSquad helps advisers and broker-dealers put these controls and their documentation in place and supports them during exams. See how we work with financial advisers and wealth managers.
How SEC and FINRA fit with other frameworks
- GLBA: Reg S-P is how GLBA applies to SEC-registered firms. Non-SEC financial businesses fall under the FTC Safeguards Rule instead.
- SOX: applies to public companies and their auditors (and can reach a broker-dealer through a public parent company). It doesn't apply to a private RIA.
- NIST frameworks: widely used to organize cybersecurity programs that examiners will review.
- State rules: state-registered advisers answer to state securities regulators, and some states have their own cybersecurity requirements. Florida's breach notification law, FIPA, can also apply to an incident.
Quick reference
- SEC: federal regulator for RIAs, broker-dealers and public companies.
- FINRA: self-regulatory organization for broker-dealers. It does not regulate RIAs.
- Reg S-P: amended in 2024; written incident response program, 30-day customer notice and vendor oversight, now in effect for all covered firms.
- Books and records: Rule 204-2 for advisers; Rules 17a-3/17a-4 and FINRA 4511 for broker-dealers (WORM or audit-trail storage).
- Off-channel communications: a major enforcement area; capture business messages on approved channels.
- FINRA Rule 4370: business continuity plans for broker-dealers.
NerdSquad is not a law firm; confirm your obligations with your compliance counsel.
Talk to NerdSquad
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.
Related: IT for financial advisers and wealth managers