IT Compliance for Financial Services: SEC, FINRA and GLBA

Last updated: 09/24/2026
Compliance
IT Compliance for Financial Services: SEC, FINRA and GLBA

If you run a broker-dealer, an advisory firm, or any business that holds consumer financial data, your IT obligations come from three regulators who don't coordinate with each other. The SEC writes the privacy and recordkeeping rules. FINRA examines how you supervise them. The FTC covers the financial firms neither of them watches. A working IT compliance program treats all three as one set of controls with three audiences.

FINRA IT compliance means meeting SEC Regulation S-P and S-ID, SEC recordkeeping Rules 17a-3 and 17a-4, and FINRA Rules 3110 and 4370. Financial firms outside SEC oversight follow the FTC's GLBA Safeguards Rule instead.

Firms rarely get fined for a missing firewall. They get fined for the paperwork around it. The written policy nobody wrote, the vendor nobody checked, the branch office that never turned on multi-factor authentication (the second login step, usually a code on your phone).

In November 2025 the SEC censured a broker-dealer with 120 branch offices for exactly that pattern. The order reads less like a hacking story and more like an audit of good intentions.

Compliance doesn't equal security. But in financial services, a security program that isn't written down doesn't count as compliance either. You need both. And you need to prove both.

A financial firm building protected by a security shield and padlock, with stacks of compliance documents beside it

Which Rules Apply to Your Firm?

Your registration decides it. SEC-registered broker-dealers and investment advisers follow Regulation S-P and usually S-ID, and broker-dealers add FINRA's rules on top. State-registered advisers, lenders, mortgage brokers, and tax preparers fall under the FTC Safeguards Rule.

GLBA, the Gramm-Leach-Bliley Act of 1999, is the parent law. It told each financial regulator to write its own rule for protecting customer information. So there's no single GLBA checklist. The SEC wrote Regulation S-P. The FTC wrote the Safeguards Rule. The banking agencies wrote their own guidelines. Same law, four rulebooks, and a firm with an affiliated lending arm can owe two of them at once.

Table matching financial firm types to the regulator and IT compliance rules that apply to each

Not in finance at all, and wondering whether the FTC rule still reaches you? It might. Our breakdown of compliance requirements by industry covers the firms that get caught by surprise.

Wait, Didn't the SEC Pass a Cybersecurity Rule?

Not one that applies to your broker-dealer or advisory firm. Two proposals would have. The SEC withdrew both on June 12, 2025.

March 2022 brought the first. It would have required advisers and funds to adopt written cybersecurity policies and report significant incidents to the SEC. The second, proposed in March 2023 and usually called Rule 10, would have required broker-dealers and other market entities to notify the Commission immediately after a significant cyber incident. Both appear in the SEC's withdrawal notice covering 14 proposals, which says the Commission doesn't intend to finalize them and would start over with a new proposal if it ever returns to the topic.

So what did pass? The July 2023 public company rule, which requires issuers to file a Form 8-K within four business days of deciding a cyber incident is material. That's a disclosure rule for companies with stock on an exchange. A 40-person RIA isn't one.

You'll still find vendor pitch decks and compliance guides describing the withdrawn proposals as current law. Check the date on anything that tells you to report incidents to the SEC within 48 hours.

None of this means the SEC backed off. Enforcement just runs through a privacy rule written in 2000 and rewritten in 2024. Account takeovers didn't stop in June 2025 either.

What Does Regulation S-P Require Now?

Amended Regulation S-P requires a written incident response program, customer breach notice within 30 days, vendor oversight that gets your providers to report breaches to you within 72 hours, and written records showing you did all of it.

The SEC adopted these amendments in May 2024. Per its fact sheet, they apply to broker-dealers (including funding portals), investment companies, registered investment advisers, and transfer agents, and they widen coverage to customer data you receive from other financial institutions, not just your own clients.

The four obligations that changed

The four amended Regulation S-P obligations, what the rule requires, and what each looks like in practice

Notice is owed for sensitive customer information, which the final rule defines as anything whose compromise could create a reasonably likely risk of substantial harm or inconvenience. Social Security numbers, driver's license and passport numbers, biometric records, and account credentials all qualify.

There's an exception. You can skip customer notice if you determine the information hasn't been and isn't reasonably likely to be used in a way that causes substantial harm. Firms lean on that exception too hard. Write it down. Make the call fast, too, because if it turns out wrong you've missed a 30-day deadline with nothing to show for your reasoning.

72 hours. That's your vendor's clock. Your policy has to make it happen. The SEC dropped a proposed requirement for written contracts and instead requires policies reasonably designed to get providers to take appropriate measures, which in practice still means contract language, because what else would get a cloud provider to call you on a Saturday? A third-party risk management program is where that clause lives.

A financial firm's office connected to its cloud vendors, with an alert bell sounding

Larger or smaller, the deadline has passed

Larger entities had until December 3, 2025. Smaller ones had until June 3, 2026, per FINRA's compliance reminder. For RIAs, larger means $1.5 billion or more in assets under management. For broker-dealers, it's anyone who isn't a small entity, and small means total capital under $500,000 with no larger affiliate. The SEC estimated about 77% of broker-dealers and 23% of RIAs land in the larger group.

Either way, you're live. No grace period left. The SEC's fiscal 2026 exam priorities name the Regulation S-P amendments directly.

What Do FINRA Examiners Actually Ask For?

For FINRA IT compliance, there's no standalone cybersecurity rule. Examiners test cybersecurity through Rule 3110 supervision, Rule 4370 business continuity, SEC recordkeeping Rules 17a-3 and 17a-4, and Regulations S-P and S-ID, as the 2026 oversight report lays out.

Rule 3110 requires a supervisory system reasonably designed to achieve compliance. It's the rule that pulls your IT provider, your CRM vendor, and your custodian's portal into scope, because supervising the firm includes supervising what you've handed off. Delegation isn't a defense. Rule 4370 requires a written business continuity plan that covers data backup and recovery and every mission-critical system, reviewed every year and approved by a senior manager who's also a registered principal. If your backups run through an outside provider, the plan has to say so.

FINRA's 2026 cybersecurity findings list ransomware, account takeovers, new account fraud using stolen identities, imposter websites and social profiles, and GenAI-driven fraud, including polymorphic malware (malicious code that rewrites itself to slip past antivirus). The practices FINRA calls effective are unglamorous. MFA on logins. Watching for wire requests to third-party accounts. BYOD rules for personal phones. Phishing training that repeats.

FINRA's third-party risk section is blunter. Vendors are the soft spot. FINRA saw more cyberattacks and outages at firms' vendors, asked members in January 2025 to update information on vendors behind mission-critical systems, and launched a program called FINRA CORE to share cyber risk intelligence with affected firms. Its effective practices include keeping an inventory of which firm data each vendor touches, least-privilege access (each account gets only what it needs), destroying firm data when a contract ends, and barring vendors from feeding sensitive data into GenAI tools.

Put that together and the evidence an examiner can reasonably expect looks something like this.

  • Written supervisory procedures whose IT sections name actual systems, like Microsoft 365, Redtail or Salesforce, and your custodian portal, not a vague line about firm systems.
  • A vendor inventory. Which vendors touch customer data, and which ones could take you offline?
  • Your business continuity plan with last year's review date and a senior manager's sign-off
  • MFA coverage at 100%, or a written exception list with a reason next to every name
  • Phishing training records by rep and by date

Recordkeeping, 17a-4, and the texting problem

Old rule, new flexibility. The SEC amended Rule 17a-4 in October 2022, with compliance required by May 2023. Broker-dealers can now keep electronic records on a system with a full audit trail that can recreate any record after it's modified or deleted, instead of only WORM storage (write once, read many, a format that can't be altered after it's saved). WORM is still allowed. It's just not the only option anymore.

Off-channel texting costs more. In August 2023 the SEC charged 11 firms a combined $289 million for business conversations on WhatsApp, iMessage, and Signal that were never captured. No hacker. No malware. Just a rep's personal iPhone.

That's an IT control, not a training memo. If your reps text clients, you need a capture tool and a mobile device policy that actually enforces it.

How Does the FTC Safeguards Rule Apply Under GLBA?

If you're a financial institution the SEC and banking agencies don't oversee, the FTC Safeguards Rule applies. It requires a written security program with specific controls, including MFA, encryption, regular testing, and FTC notice for breaches affecting 500 or more people.

Its reach is wider than the name suggests. Much wider. The FTC's own list includes mortgage lenders and brokers, payday lenders, finance companies, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions, and investment advisers who aren't required to register with the SEC.

Where Regulation S-P says "reasonably designed" and leaves the details to you, the FTC rule spells things out. Section 314.4 requires, among other things:

  • A Qualified Individual who runs the program. That person can be an employee, an affiliate, or a service provider, but if you outsource the role you still name a senior person at your firm to oversee them.
  • A written risk assessment
  • MFA for anyone accessing any information system, unless your Qualified Individual approves an equivalent control in writing
  • Encryption of customer information in transit over external networks and at rest
  • Disposal of customer information within 2 years of its last use, with exceptions for legal retention and legitimate business need
  • Annual penetration testing and vulnerability scans at least every 6 months, unless you run continuous monitoring. Not sure which one you're buying? Penetration testing and vulnerability scanning aren't the same thing.
  • Security awareness training, vendor oversight, and a written incident response plan
  • A written report to your board at least once a year, or to a senior officer if there's no board

Since May 13, 2024, the notification requirement has been in effect too. If unencrypted customer information for 500 or more consumers is acquired without authorization, you notify the FTC within 30 days of discovering it.

Firms with customer information on fewer than 5,000 consumers get a partial pass. They skip the written risk assessment, the testing schedule, the written incident response plan, and the board report. MFA, encryption, and a Qualified Individual still apply. Small doesn't mean exempt. It means fewer documents. If MFA is the gap, start with how multi-factor authentication works across your email and client portals.

One Control Set, Three Rulebooks

Build each control once and map it to every regulator that asks for it. Running three separate compliance projects means three versions of the same MFA policy, and sooner or later they disagree with each other in front of an examiner.

Control crosswalk mapping MFA, encryption, incident response, vendor oversight, testing, training, breach notice, and leadership reporting across Reg S-P, FINRA, and the FTC Safeguards Rule

Look at the FTC column. It's the most prescriptive of the three, so a firm that builds to it first has already covered most of what Regulation S-P's looser language implies. What it won't cover is S-P's own additions, the 30-day customer notice, the 72-hour vendor clause, and the records requirement. Add those and a broker-dealer is most of the way to what FINRA tests.

A crosswalk proves coverage on paper. It says nothing about whether the controls work at 4 p.m. on the Friday before a holiday weekend, which is when a wire fraud attempt tends to show up. Test the incident response plan before you need it.

What Do SEC Enforcement Cases Have in Common?

Recent Regulation S-P cases weren't about clever attackers. They punished policies that were never written, never enforced at the branch level, or never updated while account takeovers kept happening.

Nothing exotic. Take M Holdings Securities, the Portland broker-dealer and adviser the SEC settled with in November 2025. It ran 120 branch offices. Before September 2020 it had no written information security policy governing them at all. When it adopted one, the policy told each branch to write its own, and the SEC found that a significant number, including branches hit by email account takeovers, still lacked MFA, annual security training, and written incident response policies through March 2024. Records on roughly 8,500 people were exposed. The penalty? $325,000, plus a censure.

120 branches. 120 separate IT setups.

That's growth outpacing IT structure, and it's the most predictable compliance failure there is. Robinhood's $45 million settlement in January 2025 covered a wide set of violations, but the safeguards rule and the identity theft rule (Reg S-ID) were both on the list, next to the recordkeeping failures.

How many of your branches or reps could show you their MFA settings by Friday?

Where Does Outside IT Help Fit?

An outside provider can build and run the controls and keep the evidence. It can't take over your supervisory obligation. FINRA and the SEC hold the firm responsible for its vendors, and that includes whoever runs your IT.

If you have a full-time CISO, an in-house compliance team, and a vendor management program that already tracks 72-hour notice terms, you probably don't need outside help here. An internal gap review against the crosswalk above will do.

Everyone else is usually somewhere in the middle. A managed IT provider handles the laptops and the Microsoft 365 tenant, a compliance consultant shows up once a year, and nobody owns the space between them where the evidence is supposed to live.

Consilien runs compliance as its own service, separate from managed IT. For businesses nationwide, the compliance team runs the risk assessment and gap analysis, writes the policies and procedures, maps controls across frameworks, and keeps audit documentation current between exams. The usual first step is a cybersecurity risk assessment scoped to where your customer data actually lives.

Holding three rulebooks and one set of controls? Speak to a compliance expert about building one control set across the rules that apply to your firm.

One Control Set, Three Rulebooks

An incident response plan nobody has tested. A vendor contract with no breach-notice clause. A branch office that never turned on MFA. Each one is cheaper to fix before an exam than after one.

Consilien runs compliance as its own service, separate from managed IT, for businesses nationwide. Bring your written policies and your vendor list, and walk through the crosswalk with someone who builds these programs.

Questions Compliance Officers Ask

Does FINRA have its own cybersecurity rule?
Not a standalone one. That surprises people. FINRA examines cybersecurity through Rule 3110 supervision, Rule 4370 business continuity, and the SEC's Regulations S-P and S-ID, which is why a weak vendor file can become a supervision finding.
We're a state-registered RIA. Does GLBA apply to us?
Through the FTC, it does. The FTC lists investment advisers who aren't required to register with the SEC among the businesses its Safeguards Rule covers. Your state securities regulator may add its own requirements, and if you hold data on fewer than 5,000 consumers, four of the documentation requirements drop away.
Realistically, how fast do we have to notify customers after a breach?
30 days at the outside, counted from when you become aware of unauthorized access, under amended Regulation S-P. The rule says as soon as practicable, so 30 days is the ceiling, not the target. FTC-covered firms owe the FTC notice within 30 days when 500 or more consumers are affected. State breach laws set their own timelines on top of both, so check every state where you have clients.
Do we really need an annual penetration test?
Under the FTC rule, it's the default unless you run continuous monitoring. Regulation S-P and FINRA don't prescribe one. Still, a pen test report (a hired team actually trying to break in) is the cleanest evidence that your controls work rather than just exist, and it tends to answer examiner questions before they're asked.
Is WORM storage still required under Rule 17a-4?
Short answer, no. Since May 2023, broker-dealers can use an electronic recordkeeping system with a complete audit trail instead. WORM remains a valid option.
Our IT provider handles security. Are we covered?
Only on paper. And only if the paper exists. Rule 3110 makes you responsible for supervising outsourced work, and Regulation S-P requires you to oversee service providers and get breach notice from them within 72 hours. M Holdings is a useful warning here, even though it's about branches rather than vendors. It handed the security job to its member firms and assumed the job got done. The SEC didn't accept that. Ask your provider for the evidence behind each control on the crosswalk (MFA coverage, encryption status, backup tests, training records), and if they can't produce it quickly, you've found your gap before an examiner does.

Related Articles

Stay ahead with expert tips, industry trends, and actionable strategies.