Cybersecurity & Data Protection
Written safeguards, an incident response plan, and breach notice within 30 days.
What is Cybersecurity & Data Protection?
Firms must maintain written policies protecting customer records and information. The 2024 amendments to Regulation S-P require an incident response program and notice to affected individuals as soon as practicable, but no later than 30 days, after discovering unauthorized access to sensitive customer information (compliance required by December 2025 for larger firms and June 2026 for smaller ones). Firms must also oversee their service providers' security.
Cybersecurity & Data Protection: a worked example
A stolen laptop with unencrypted client files triggers the firm's incident response plan and client notifications.
More terms in Ethics & Fiduciary Obligations
Form ADV Part 2 Brochure Delivery
Deliver 48 hours before the contract, or at signing with a 5-business-day exit.
Advisory Contract Requirements
Written, specific about fees, no assignment without consent, no waiver of rights.
Assignment of an Advisory Contract
Transferring a client contract requires the client's consent - including by change of control.
Performance-Based Fees & Qualified Clients
Allowed only for qualified clients: $1.4M with the adviser or $2.7M net worth (from June 29, 2026).
Prepaid Fees & Financial Requirements
Prepayment over $500, six months ahead, triggers net worth and balance sheet rules.
Custody
Holding, or having authority to obtain, client funds or securities.
Discretionary Authority
Deciding the asset, the amount, or buy versus sell - without asking first.
Third-Party Trading Authorization
Anyone other than the owner needs written authority to trade the account.