Cybersecurity & Data Protection

Written safeguards, an incident response plan, and breach notice within 30 days.

What is Cybersecurity & Data Protection?

Firms must maintain written policies protecting customer records and information. The 2024 amendments to Regulation S-P require an incident response program and notice to affected individuals as soon as practicable, but no later than 30 days, after discovering unauthorized access to sensitive customer information (compliance required by December 2025 for larger firms and June 2026 for smaller ones). Firms must also oversee their service providers' security.

Cybersecurity & Data Protection: a worked example

A stolen laptop with unencrypted client files triggers the firm's incident response plan and client notifications.

More terms in Ethics & Fiduciary Obligations

All Ethics & Fiduciary Obligations terms · Full glossary