Resources

SEC Exams and the Safeguards Rule: What Small RIAs Need to Prove on Cybersecurity

Exams, institutional clients, and the Safeguards Rule are three ways of asking whether a small adviser can show a security program, not merely a vendor who keeps the lights on.

Three directions of pressure

A small adviser feels the cybersecurity question from three places at once. An examination asks for the policies, the risk assessment, and the evidence that the firm does what the policies say. An institutional client, or a platform the firm wants to stay on, sends a questionnaire that is really the same request in a different format. The Safeguards Rule, and the state rules that sit beside it, ask the firm to protect customer information with a program that is written down, owned, and adjusted when the firm changes.

None of those audiences is impressed by a tool list. They are asking who is accountable, what was assessed, and what changed because of it. The work with RIAs starts from that question, not from a product catalog.

IT support is not a security function

Most advisers of this size have someone who keeps email running, patches machines, and answers the phone when a laptop dies. That person may be an employee or a managed-service provider. They are necessary. They are not, by themselves, a security program. A program has an owner inside the firm, a written view of the risks that matter to an adviser, and a record of the controls that address those risks.

What examiners and clients actually ask to see

The list is shorter than the folklore. Expect to be asked for a risk assessment that reflects the firm, not a generic template with the name swapped. Expect written policies for access, acceptable use, vendors, and incident response. Expect to show that people have been told, and that access for someone who left was actually removed. Expect a record of the vendors who hold customer information, and some evidence that the firm looked at them.

NIST CSF 2.0 as a frame, not a binder

NIST CSF 2.0 is useful here because it is a way to organize a small program, not because an examiner handed you a scorecard. The six Functions, plus supply chain and AI governance, give a 20-person adviser a place to put each question: who governs, what you have, what you protect, what you would detect, how you respond, how you recover. A firm does not need a control for every informative reference in the Framework. It needs a proportional answer, and a reason the answer fits the data it actually holds.

Scoring, when it is used, is for priority. It is not theater. A maturity assessment in this practice is fixed scope, $3,000 to $8,000, and it produces a ranked view and a 12-month roadmap the firm can show. It does not produce a certificate, and it does not produce a promise about an exam.

A proportional program, in weeks

The engagements that fit a small adviser are measured in weeks, not in a standing army. First the assessment, so the firm stops guessing which gap matters. Then the documents and the remediation that the assessment ranked, typically $3,500 to $7,500 when the scope is the core set: policies, an incident response plan, and the evidence a client or an examiner asks to see. A virtual CISO retainer, from $3,000 a month, is the right shape only when the firm needs someone on the letterhead between exams, not as a substitute for the first two steps.

The free readiness assessment is the directional version. Forty-one questions, about five minutes, organized from Govern through Recover. It will not satisfy an examiner. It will tell the partners whether the firm is about to walk into a review with a vendor list and a hope.

What this note will not claim

Advisory work improves the firm’s ability to explain itself. It does not guarantee an examination outcome, a finding, or the absence of one. Anyone who tells a small adviser otherwise is selling a result they do not control. If you want the work scoped to your next exam or your next institutional questionnaire, the 15-minute intro is the place to start. Bring the letter or the portal login. Do not bring a hope that the conversation will be abstract.

This is advisory writing, not legal advice, and it is not a prediction of how any examination will come out. Outcomes depend on facts TRM does not have until an engagement starts.

Next step

If this is the request on your desk.

The assessment is free and takes about five minutes. The intro is fifteen minutes if you want the work scoped to a date. The document link is there if this week you only need the paper.

TRM Solutions is an independent advisory practice not affiliated with, endorsed by, or sponsored by any current or former employer. Employer names describe professional experience only. Engagements are conducted in a personal capacity and do not involve employer systems, data, clients, vendors, or confidential information. Client engagements are covered by NDA. Assessments and templates provide directional guidance and are not a penetration test, audit, certification, or guarantee of security.