10 Cybersecurity Mistakes That Can Create SEC Examination Findings for RIAs (And How to Avoid Them)

Estimated Reading Time: 10–12 Minutes

Quick Answer

Many cybersecurity deficiencies identified during SEC examinations are preventable. In our experience working with Registered Investment Advisors (RIAs), the most common issues aren’t sophisticated cyberattacks—they’re gaps in documentation, inconsistent security practices, incomplete vendor oversight, and failure to regularly review and update cybersecurity programs.

Most firms can significantly improve their cybersecurity readiness in 30–90 days by addressing these foundational issues before an examination begins. The goal isn’t perfection; it’s demonstrating that your firm has a documented, risk-based cybersecurity program that is actively maintained.

This article covers ten common mistakes we see and practical steps your firm can take to strengthen its cybersecurity posture.

Mistake #1: Treating Cybersecurity as an IT Problem Instead of a Business Responsibility

Many firms assume cybersecurity belongs exclusively to their IT provider.

In reality, firm leadership is responsible for overseeing cybersecurity as part of overall business risk management.

Better Approach

  • Assign clear cybersecurity ownership.
  • Review cybersecurity at leadership meetings.
  • Document annual reviews.
  • Include cybersecurity in business planning.

Mistake #2: Policies That Haven’t Been Updated in Years

One of the first things examiners may review is your documentation.

Policies that reference outdated technology, former employees, or practices your firm no longer follows can undermine confidence in your cybersecurity program.

Better Approach

Review all cybersecurity policies at least annually and whenever significant operational changes occur.

Policies should reflect what your firm actually does—not what it intended to do years ago.

Mistake #3: Incomplete Risk Assessments

Many RIAs perform vulnerability scans but never complete a formal cybersecurity risk assessment.

These are not the same thing.

A vulnerability scan identifies technical weaknesses.

A risk assessment evaluates how cybersecurity risks affect the business and what controls are appropriate.

Better Approach

Conduct and document a comprehensive risk assessment on a regular basis and use the results to prioritize improvements.

Mistake #4: Weak Identity and Access Controls

Compromised credentials remain one of the most common ways attackers gain access to business systems.

Common issues include:

  • Shared accounts
  • Weak passwords
  • Missing multifactor authentication
  • Excessive administrative privileges
  • Former employees still having access

Better Approach

Implement strong identity management practices, require multifactor authentication where appropriate, review user access regularly, and promptly remove access when employees leave.

Mistake #5: Poor Vendor Oversight

Many RIAs rely on third-party vendors for custodial platforms, cloud services, CRM systems, and communications.

However, vendor relationships should be managed—not assumed.

Better Approach

Maintain a documented vendor management process that includes:

  • Due diligence before onboarding
  • Periodic security reviews
  • Contract reviews
  • Documentation of vendor risk
  • Annual reassessments for critical vendors

Mistake #6: No Tested Incident Response Plan (IRP)

Having an incident response plan is important.

Knowing whether it actually works is even more important.

If a ransomware attack occurred tomorrow, would everyone know their responsibilities?

Better Approach

Develop a written incident response plan and conduct periodic tabletop exercises to practice how the firm would respond to different scenarios.

Lessons learned should be documented and incorporated into future updates.

Mistake #7: Employee Security Training Is Inconsistent

Technology alone cannot prevent phishing attacks or social engineering.

Employees remain one of the strongest—and weakest—parts of a cybersecurity program.

Better Approach

Provide recurring cybersecurity awareness training throughout the year rather than relying on a single annual session.

Document participation and reinforce key topics such as phishing, password security, and handling sensitive information.

Mistake #8: Backups Are Never Tested

Many firms assume backups are working because backup software reports success.

Unfortunately, a successful backup doesn’t guarantee a successful recovery.

Better Approach

Test restoration procedures regularly and document the results.

A backup strategy should answer:

  • How quickly can systems be restored?
  • What data could be lost?
  • Who is responsible for recovery?
  • How are results documented?

Mistake #9: Waiting Until an SEC Examination Is Scheduled

Cybersecurity shouldn’t become a priority only after receiving an examination notice.

Trying to update documentation, implement new controls, and organize evidence under a tight deadline creates unnecessary stress and increases the likelihood of overlooking important details.

Better Approach

Treat cybersecurity readiness as an ongoing business process with scheduled reviews throughout the year.

Small improvements made consistently are generally more effective than large efforts completed under pressure.

Mistake #10: Choosing an IT Provider Without RIA Experience

Not every managed IT provider understands the operational and cybersecurity expectations of Registered Investment Advisors.

A provider unfamiliar with RIAs may deliver excellent technical support but lack experience with compliance documentation, regulatory expectations, or the workflows common in advisory firms.

Better Approach

When evaluating providers, ask questions such as:

  • How many RIAs do you support?
  • What cybersecurity documentation do you help maintain?
  • How do you assist firms preparing for SEC examinations?
  • What cybersecurity reporting do you provide?
  • How do you approach vendor management and risk assessments?

Industry experience can make a significant difference when technology and compliance intersect.

CyberSecureRIA’s SEC Ready Checklist

Before your next examination, ask yourself:

  • Have we completed a recent cybersecurity risk assessment?
  • Are our policies current and reviewed annually?
  • Is multifactor authentication implemented consistently?
  • Do we maintain documented vendor reviews?
  • Have we tested our incident response plan?
  • Is employee cybersecurity training documented?
  • Have we tested our backups?
  • Are user access reviews performed regularly?
  • Can we quickly locate our cybersecurity documentation?
  • Are we continuously improving our cybersecurity program?

If you answered “no” to several of these questions, your firm may benefit from a structured cybersecurity readiness review.

Frequently Asked Questions

Do SEC examinations have a “pass” or “fail” result?

SEC examinations are not generally characterized as pass/fail. Examiners may identify deficiencies, request additional information, or recommend corrective actions depending on their findings.

What is the biggest cybersecurity mistake RIAs make?

There is no single mistake, but outdated documentation and inconsistent implementation of security practices are common issues that can complicate an examination.

How often should cybersecurity documentation be reviewed?

At a minimum, annually and whenever there are significant changes to your business, technology, or regulatory requirements.

Should small RIAs perform cybersecurity risk assessments?

Yes. Every RIA should understand its cybersecurity risks and document how those risks are evaluated and addressed, regardless of firm size.

Final Thoughts

Cybersecurity readiness isn’t about avoiding every possible issue—it’s about demonstrating that your firm has a thoughtful, documented, and continuously improving approach to protecting client information.

For most RIAs, the biggest opportunities aren’t found in buying more technology. They’re found in strengthening governance, documentation, employee awareness, vendor oversight, and ongoing operational discipline.

By addressing these common mistakes before your next SEC examination, you’ll be in a stronger position to respond confidently to examiner requests and better protect your clients and your business.

About CyberSecureRIA

CyberSecureRIA provides managed IT, cybersecurity, and compliance-focused technology services specializing in Registered Investment Advisors. We help firms build practical cybersecurity programs, maintain documentation, and prepare for SEC examinations with confidence.