{"id":19677,"date":"2025-09-25T16:00:50","date_gmt":"2025-09-25T20:00:50","guid":{"rendered":"https:\/\/www.elteni.com\/?p=19677"},"modified":"2025-09-25T16:00:50","modified_gmt":"2025-09-25T20:00:50","slug":"protecting-investor-data-under-the-updated-regulation-s-p","status":"publish","type":"post","link":"https:\/\/www.elteni.com\/insights\/?p=19677","title":{"rendered":"Protecting Investor Data Under the Updated Regulation S-P"},"content":{"rendered":"<h1>Protecting Investor Data Under the Updated Regulation S-P<\/h1>\n<h2>What changed, what it means, and what we\u2019re doing together<\/h2>\n<h3>Why this matters now<\/h3>\n<p>The SEC\u2019s amendments to Regulation S-P expand what firms must do to <strong>detect, respond to, and recover<\/strong> from any unauthorized access to customer information\u2014and to notify affected individuals promptly.<\/p>\n<h3>What\u2019s new at a glance<\/h3>\n<ul>\n<li><strong>Incident Response Program (IRP).<\/strong> Covered institutions must maintain policies and procedures to detect, respond, and recover from incidents that involve customer information held directly or by service providers.<\/li>\n<li><strong>Customer Notification.<\/strong> If <strong>sensitive customer information<\/strong> was\u2014or is reasonably likely to have been\u2014accessed or used without authorization, firms must notify each affected individual. \u201cSensitive\u201d includes items like SSNs, driver\u2019s licenses, biometrics, and certain account identifiers when combined with security data.<\/li>\n<li><strong>Timing.<\/strong> Notices must be sent <strong>as soon as practicable and no later than 30 days<\/strong> after the firm becomes aware of an incident, with limited exceptions.<\/li>\n<li><strong>Rebuttable presumption.<\/strong> Notice is presumed required unless a <strong>reasonable investigation<\/strong> shows the data <strong>has not been and is not reasonably likely to be used<\/strong> in a way that would cause substantial harm or inconvenience\u2014determined within the 30-day window.<\/li>\n<li><strong>If scope is unclear.<\/strong> When a firm can\u2019t determine exactly which individuals were affected, it must notify <strong>all<\/strong> individuals whose sensitive data resides in the impacted system (unless it reasonably determines a given individual\u2019s data wasn\u2019t accessed).<\/li>\n<li><strong>Attorney General delay.<\/strong> DOJ can request a delay (national security\/public safety), during which notices may be postponed.<\/li>\n<li><strong>Service providers.<\/strong> Providers must notify the covered institution <strong>as soon as possible, but no later than 72 hours<\/strong> after becoming aware of a breach of a <strong>customer information system<\/strong> they maintain; firms may contract for providers to send customer notices, but <strong>ultimate responsibility stays with the firm<\/strong>.<\/li>\n<\/ul>\n<h2>How we\u2019re helping investment advisers comply<\/h2>\n<h3>1) Build and tune a fit-for-purpose Incident Response Program<\/h3>\n<p>We align your IRP to the lifecycle regulators expect: <strong>identify<\/strong> (assets\/data), <strong>protect<\/strong> (controls), <strong>detect<\/strong> (monitoring\/logging), <strong>respond<\/strong>, and <strong>recover<\/strong>\u2014drawing on industry frameworks (e.g., NIST) as <i>guides<\/i>, not prescriptions.<\/p>\n<p><strong>What this looks like in practice<\/strong><\/p>\n<ul>\n<li>Clear playbooks for triage, containment, forensics, notification decisioning, and recovery.<\/li>\n<li><strong>Data mapping<\/strong> across CRM, email, endpoints, cloud, and vendor environments, so the firm can quickly determine who is affected and meet the 30-day clock.<\/li>\n<li>Monitoring\/log aggregation (e.g., SIEM) to support timely detection and investigation.<\/li>\n<\/ul>\n<h3>2) Operationalize the 30-day notification standard<\/h3>\n<p>We implement workflows to:<\/p>\n<ul>\n<li>Start the 30-day clock when the firm becomes aware an incident <strong>has occurred or is reasonably likely<\/strong> to have occurred.<\/li>\n<li>Apply the <strong>rebuttable presumption<\/strong> standard and document the <strong>reasonable investigation<\/strong> that could rebut it; when inconclusive, notify the broader potentially affected population per the rule.<\/li>\n<li>Prepare customer notice content (incident details, data involved, protective steps) in advance.<\/li>\n<\/ul>\n<h3>3) Strengthen third-party oversight and breach intake<\/h3>\n<p>Advisers can\u2019t outsource responsibility. We help build <strong>written policies and procedures<\/strong> requiring oversight of service providers\u2014including due diligence, ongoing monitoring, breach detection expectations, <strong>72-hour<\/strong> provider-to-firm notifications, and (where agreed) provider-issued customer notices.<\/p>\n<p><strong>Key controls we implement<\/strong><\/p>\n<ul>\n<li>Contract clauses for security, breach notification timing, cooperation, and record retention.<\/li>\n<li>Evidence-based assurance (independent attestations\/certifications) instead of relying solely on vendor representations.<\/li>\n<\/ul>\n<h3>4) Recordkeeping and evidence<\/h3>\n<p>We operationalize retention of: IR policies\/procedures (including disposal), detection and response artifacts, customer notices (or determinations that notice wasn\u2019t required), any Attorney General delay letters, and records of provider-issued notices on the firm\u2019s behalf.<\/p>\n<h3>5) Training and table-top testing<\/h3>\n<p>We run targeted trainings so officers and staff understand roles and the new timing standards, and we conduct exercises to validate that procedures work end-to-end.<\/p>\n<h2>What investors can expect if something happens<\/h2>\n<ul>\n<li><strong>Timely notice (\u226430 days)<\/strong> with clear details on what occurred, what information was involved, and steps you can take.<\/li>\n<li>In rare cases, <strong>law-enforcement-requested delay<\/strong> to protect national security or public safety.<\/li>\n<\/ul>\n<h2>Special notes for private fund advisers<\/h2>\n<p>Registered investment advisers\u2014including RIAs to private funds\u2014are <strong>covered institutions<\/strong> under Reg S-P. Safeguarding obligations can extend to <strong>customer information received from other financial institutions<\/strong> even without a direct firm-to-individual customer relationship.<\/p>\n<h2>What exam teams are focusing on (and how we prepare you)<\/h2>\n<p>SEC examiners tailor scope to your services and <strong>data flows<\/strong> across on-prem, cloud, vendors, and partners, looking for evidence that policies match practice. We prepare you for the <strong>initial information request<\/strong>, walkthroughs\/testing, and documentation of your risk program, controls, and IRP.<\/p>\n<h2>Action checklist (we\u2019ll drive this with you)<\/h2>\n<ol>\n<li>Finalize IRP and run a table-top that exercises the <strong>30-day<\/strong> clock and notification decision tree.<\/li>\n<li>Complete <strong>data mapping<\/strong> across CRM, email, endpoints, cloud, and providers.<\/li>\n<li>Update vendor governance: contracts, 72-hour intake, evidence\/attestations.<\/li>\n<li>Pre-draft customer notice templates and internal decision records.<\/li>\n<li>Train staff on roles\/responsibilities and escalation paths.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Protecting Investor Data Under the Updated Regulation S-P What changed, what it means, and what we\u2019re doing together Why this matters now The SEC\u2019s amendments to Regulation S-P [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":19679,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[112,134,113,3,139,102,103,16,25,15,106,137,24,89,115,90,26,127],"tags":[],"class_list":["post-19677","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bec","category-breaches","category-business-email-compromise","category-cyber","category-fraud","category-hedge-fund","category-investment-adviser","category-malware","category-pii","category-privacy","category-private-equity","category-private-funds","category-ransomware-attack","category-regulatory","category-ria","category-sec","category-table-top","category-technology"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Protecting Investor Data Under the Updated Regulation S-P - Insights<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.elteni.com\/insights\/?p=19677\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Protecting Investor Data Under the Updated Regulation S-P - Insights\" \/>\n<meta property=\"og:description\" content=\"Protecting Investor Data Under the Updated Regulation S-P What changed, what it means, and what we\u2019re doing together Why this matters now The SEC\u2019s amendments to Regulation S-P [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.elteni.com\/insights\/?p=19677\" \/>\n<meta property=\"og:site_name\" content=\"Insights\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-25T20:00:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2025\/09\/Protecting-data.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Elteni\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Elteni\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19677#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19677\"},\"author\":{\"name\":\"Elteni\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/e415dfcf12d1dc9ad6eca68055c5e075\"},\"headline\":\"Protecting Investor Data Under the Updated Regulation S-P\",\"datePublished\":\"2025-09-25T20:00:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19677\"},\"wordCount\":793,\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19677#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/Protecting-data.jpg\",\"articleSection\":[\"BEC\",\"Breaches\",\"Business Email Compromise\",\"Cyber\",\"Fraud\",\"Hedge Fund\",\"Investment Adviser\",\"Malware\",\"PII\",\"Privacy\",\"Private Equity\",\"Private Funds\",\"Ransomware Attack\",\"Regulatory\",\"RIA\",\"SEC\",\"Table Top\",\"Technology\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19677\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19677\",\"name\":\"Protecting Investor Data Under the Updated Regulation S-P - Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19677#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19677#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/Protecting-data.jpg\",\"datePublished\":\"2025-09-25T20:00:50+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/e415dfcf12d1dc9ad6eca68055c5e075\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19677#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19677\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19677#primaryimage\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/Protecting-data.jpg\",\"contentUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/Protecting-data.jpg\",\"width\":1024,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19677#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.elteni.com\\\/insights\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Protecting Investor Data Under the Updated Regulation S-P\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/\",\"name\":\"Insights\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/e415dfcf12d1dc9ad6eca68055c5e075\",\"name\":\"Elteni\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"caption\":\"Elteni\"},\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?author=2\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Protecting Investor Data Under the Updated Regulation S-P - Insights","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.elteni.com\/insights\/?p=19677","og_locale":"en_US","og_type":"article","og_title":"Protecting Investor Data Under the Updated Regulation S-P - Insights","og_description":"Protecting Investor Data Under the Updated Regulation S-P What changed, what it means, and what we\u2019re doing together Why this matters now The SEC\u2019s amendments to Regulation S-P [&hellip;]","og_url":"https:\/\/www.elteni.com\/insights\/?p=19677","og_site_name":"Insights","article_published_time":"2025-09-25T20:00:50+00:00","og_image":[{"width":1024,"height":1024,"url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2025\/09\/Protecting-data.jpg","type":"image\/jpeg"}],"author":"Elteni","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Elteni","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.elteni.com\/insights\/?p=19677#article","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19677"},"author":{"name":"Elteni","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/e415dfcf12d1dc9ad6eca68055c5e075"},"headline":"Protecting Investor Data Under the Updated Regulation S-P","datePublished":"2025-09-25T20:00:50+00:00","mainEntityOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19677"},"wordCount":793,"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19677#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2025\/09\/Protecting-data.jpg","articleSection":["BEC","Breaches","Business Email Compromise","Cyber","Fraud","Hedge Fund","Investment Adviser","Malware","PII","Privacy","Private Equity","Private Funds","Ransomware Attack","Regulatory","RIA","SEC","Table Top","Technology"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.elteni.com\/insights\/?p=19677","url":"https:\/\/www.elteni.com\/insights\/?p=19677","name":"Protecting Investor Data Under the Updated Regulation S-P - Insights","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19677#primaryimage"},"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19677#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2025\/09\/Protecting-data.jpg","datePublished":"2025-09-25T20:00:50+00:00","author":{"@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/e415dfcf12d1dc9ad6eca68055c5e075"},"breadcrumb":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19677#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.elteni.com\/insights\/?p=19677"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.elteni.com\/insights\/?p=19677#primaryimage","url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2025\/09\/Protecting-data.jpg","contentUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2025\/09\/Protecting-data.jpg","width":1024,"height":1024},{"@type":"BreadcrumbList","@id":"https:\/\/www.elteni.com\/insights\/?p=19677#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.elteni.com\/insights"},{"@type":"ListItem","position":2,"name":"Protecting Investor Data Under the Updated Regulation S-P"}]},{"@type":"WebSite","@id":"https:\/\/www.elteni.com\/insights\/#website","url":"https:\/\/www.elteni.com\/insights\/","name":"Insights","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.elteni.com\/insights\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/e415dfcf12d1dc9ad6eca68055c5e075","name":"Elteni","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","caption":"Elteni"},"url":"https:\/\/www.elteni.com\/insights\/?author=2"}]}},"_links":{"self":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19677"}],"version-history":[{"count":0,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19677\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/media\/19679"}],"wp:attachment":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19677"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}