Blog / US compliance
US compliance
Regulation S-P Six Months In: The 30-Day Clock Runs While You Wait for the Mailbox Export
Regulation S-P six months in: where the 30-day customer notice actually goes wrong for smaller advisers, and the four records that shorten the clock.
Friday, 4:10 p.m., a forwarding rule nobody set
The chief compliance officer of a 14-person registered investment adviser off Madison Avenue gets a message from the outsourced IT provider at ten past four on a Friday. An adviser's mailbox has a forwarding rule sending copies of anything containing the words wire, statement or invoice to an address at a domain the firm has never used.
She asks the only question that matters: how long has it been there, and what went through it?
The answer arrives nineteen days later.
In between, the firm does everything a good firm does. The password gets changed within an hour. Multi-factor authentication goes on the whole tenant by Monday. Counsel is on the phone Tuesday. The custodian is told. What nobody can produce is a list of which clients' information passed through that mailbox during the eleven weeks the rule was active, because mailbox audit logging had a 30-day retention setting that came with the license and nobody had raised it.
The clock did not wait for the list. Under the Regulation S-P amendments the firm had 30 days from becoming aware to notify affected customers, and the awareness date was that Friday afternoon, not the day the forensic report arrived. On day 24, with an incomplete picture, the firm sent notice to 412 households instead of the 60 or so it believed were actually involved.
Every one of those letters cost a phone call. Some cost a relationship.
What the heck does this mean
Regulation S-P is the SEC's customer information rule for broker-dealers, investment companies and registered advisers. It has existed since 2000. The 2024 amendments added the parts everyone is now living with, and they reached smaller entities on 3 June 2026.
Sensitive customer information: the nonpublic personal information that could be used to cause harm or inconvenience to a customer. Account numbers, Social Security numbers, statements, account-opening paperwork.
Incident response program: a written program covering how you detect, respond to and recover from unauthorized access to customer information. Written means a document with names in it, not a shared understanding among three partners.
The 30-day notice: once you become aware that sensitive customer information was, or was reasonably likely to have been, accessed without authorization, affected customers get notice within 30 days. The clock is tied to awareness, and awareness comes early in an incident, when you know the least.
Service provider oversight: your custodian, portfolio accounting tool, CRM and outsourced IT hold your customers' information, and the rule expects you to have arrangements that get you told promptly when something happens at their end.
Here is the practical lesson from the first half-year of this rule. It is not a documentation exercise. It is an evidence exercise, and the evidence has to exist before the incident, because a mailbox does not retroactively grow logs.
The numbers that matter
The Regulation S-P amendments became applicable to smaller advisers and broker-dealers on 3 June 2026, per the SEC's 2024 adopting release, bringing the written incident response program, the 30-day customer notice and service provider oversight into scope for firms with a compliance department of one.
Third parties were involved in 48% of breaches in the Verizon 2026 Data Breach Investigations Report, an increase of 60% over the prior year. For an advisory firm, the third parties in question are the ones that hold client statements.
Credential abuse was the initial access route in 13% of breaches in the Verizon 2026 DBIR. A stolen password and a quiet forwarding rule is the most common shape of an advisory-firm incident, and it produces the hardest notification question, which is whose information was in that mailbox.
What to do this week
- Fix your log retention before you touch anything else. Mailbox, document vault, CRM and portfolio system, access logging switched on with at least a year of retention. This is the single change that decides whether your notice covers 60 households or 412. (CIS 8 Audit Log Management)
- Put an awareness line in the incident response program: the named person who records the date and time the firm first became aware, where that record is kept, and the instruction that the count starts then rather than when the facts are complete. Print it. (CIS 17 Incident Response Management)
- Draft the customer notice now, while nothing is happening. Two pages, with blanks for the facts, reviewed by counsel once at a calm hourly rate. Firms that had a draft sent notice on day 12; firms that started drafting on day 20 sent it on day 29. (CIS 17 Incident Response Management)
- Run a 30-minute tabletop with the partners and whoever answers the IT phone, using the scenario above: a forwarding rule found on a Friday afternoon. Write down where you got stuck. That list is your remediation plan and your exam evidence at the same time. (CIS 17 Incident Response Management)
- Read every service provider contract for a notification clause with a number of days in it. Custodian, RIA platform, CRM, outsourced IT, the marketing firm with your client list. Send a one-page addendum to the ones that have none, and keep the signed copies with the vendor list. (CIS 15 Service Provider Management)
- Enforce multi-factor authentication on every mailbox in the tenant, including shared and service accounts, and set an alert for new forwarding rules. Eleven weeks of undetected forwarding is a detection failure before it is a notification problem. (CIS 6 Access Control Management)
Where AccuSights fits
Our assessment reads your firm the way an examiner does, then fixes what an attacker would use. We map your systems against Regulation S-P and the rest of the obligations an adviser carries, and hand you a ranked plan with dates on it. Our team implements the controls at a reasonable rate, from logging and data loss prevention to scanning and protection of the assets that hold client information. We do a lot of this work with advisers around New York. The Cyber Hygiene Test takes three minutes; a call with an engineer takes fifteen.
Questions people ask
When does the 30-day Regulation S-P clock start? It starts when the firm becomes aware that sensitive customer information was, or was reasonably likely to have been, accessed or used without authorization, not when the investigation finishes. That distinction is what catches smaller advisers, because the natural instinct is to wait until the facts are clean before starting the count. Log the date and time you first became aware, in writing, on the day it happens, and run the calendar from there.
What if we cannot identify which customers were affected? Then the notice goes to everyone whose sensitive customer information reasonably may have been affected, which is usually a much larger group than the one you would have identified with better logs. The size of your notice is decided by the quality of your records, not by the size of the incident. Firms that turned on mailbox and document-vault access logging with a year of retention have been able to send a short, specific list instead of a firm-wide letter.
Does the rule cover breaches at our vendors? Yes, and this is the part smaller advisers underestimate. The amendments require oversight of service providers, including arrangements designed to get you notice of an incident at the provider promptly, because the customer notice obligation stays with you when your custodian, portfolio tool or CRM is the one that was breached. Check that every contract naming your customer information has a written notification clause with a deadline in days.
The rule gives you 30 days. Your logging settings decide how many of them you get to spend on the letter instead of the guesswork.
Controls this post maps to
CIS Controls v8.1. These are the same controls our assessment scores and the console watches.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
The 2027 Cybersecurity Calendar for US Small Business: The Dates That Are Real, and the One Everybody Is Guessing About
A US cybersecurity regulatory calendar for 2027: the confirmed dates from January to December, which ones apply to a 40-person company, and what to do first.
US complianceSEC Regulation S-P for the Small RIA: 30 Days to Tell Clients, and a Program to Prove You Could
Regulation S-P amendments reached smaller advisers on 3 June 2026: incident response program, 30-day client notice and vendor oversight. What the exam asks.
US complianceThe NYDFS Annual Certification: What to Have Ready in March So the 15 April Filing Takes an Afternoon
The NYDFS annual certification is due 15 April. The evidence a covered entity should collect in March for Part 500, from asset inventory to MFA and logs.
