SEC-registered adviser or broker-dealer
Regulation S-P: a written incident response program, customer notice within thirty days, and oversight of your providers.
Financial services
Wealth management, insurance and mortgage firms hold the same kind of client information and answer to different regulators for it. Which rule you owe depends on who registered you. The IT underneath is the same.
Which rule applies
Two firms on the same street, holding the same client information, can owe different duties on different timetables. The first question is not what the rule requires. It is which rule you are under.
Regulation S-P: a written incident response program, customer notice within thirty days, and oversight of your providers.
The FTC Safeguards Rule, the same rule an accounting firm follows.
Your state insurance department, under the NAIC model law where your state has adopted it.
The FTC Safeguards Rule, which names mortgage brokers and lenders directly.
What they all ask
Across the tenant, with a report showing it, so an answer to an examiner or an insurer holds up afterwards.
Enforced and evidenced on every managed laptop and desktop.
Every notification duty begins when you become aware. Identity monitoring around the clock moves that moment earlier.
Including us. We supply what your review needs rather than treating the request as an imposition.
Which plan
Protect+ for a firm with a written program to keep and an examiner or insurer to answer: it adds the documented controls, retained logs, and awareness training those documents describe. Protect where you need managed devices without the compliance layer. Either way it supports your program; it is not a certification. Every plan rate and the add-ons most businesses need are on the pricing page.
Frequently asked
It follows your registration, not your size. Advisers registered with the SEC fall under Regulation S-P. Advisers registered with their state, and mortgage brokers and lenders, fall under the FTC Safeguards Rule. Your Form ADV is the authority on which you are.
Becoming aware that unauthorized access to customer information has happened or is reasonably likely to have happened. It is thirty days from awareness, not from the incident, so how quickly you detect decides how much of the thirty days you have left to use.
Not the platforms themselves; their vendors do that. We manage everything they run on: the identities that sign in to Orion, Redtail or eMoney, the computers, the mail, and the network behind the Schwab or Fidelity portal.
A thirty-minute call where we go through what you run and what is not working. We reply within one business day, and there is no obligation.
Schedule an IT assessment