
Estimated Reading Time: 10–12 Minutes
Quick Answer
Many cybersecurity deficiencies identified during SEC examinations are preventable. In our experience working with Registered Investment Advisors (RIAs), the most common issues aren’t sophisticated cyberattacks—they’re gaps in documentation, inconsistent security practices, incomplete vendor oversight, and failure to regularly review and update cybersecurity programs.
Most firms can significantly improve their cybersecurity readiness in 30–90 days by addressing these foundational issues before an examination begins. The goal isn’t perfection; it’s demonstrating that your firm has a documented, risk-based cybersecurity program that is actively maintained.
This article covers ten common mistakes we see and practical steps your firm can take to strengthen its cybersecurity posture.
Mistake #1: Treating Cybersecurity as an IT Problem Instead of a Business Responsibility
Many firms assume cybersecurity belongs exclusively to their IT provider.
In reality, firm leadership is responsible for overseeing cybersecurity as part of overall business risk management.
Better Approach
- Assign clear cybersecurity ownership.
- Review cybersecurity at leadership meetings.
- Document annual reviews.
- Include cybersecurity in business planning.
Mistake #2: Policies That Haven’t Been Updated in Years
One of the first things examiners may review is your documentation.
Policies that reference outdated technology, former employees, or practices your firm no longer follows can undermine confidence in your cybersecurity program.
Better Approach
Review all cybersecurity policies at least annually and whenever significant operational changes occur.
Policies should reflect what your firm actually does—not what it intended to do years ago.
Mistake #3: Incomplete Risk Assessments
Many RIAs perform vulnerability scans but never complete a formal cybersecurity risk assessment.
These are not the same thing.
A vulnerability scan identifies technical weaknesses.
A risk assessment evaluates how cybersecurity risks affect the business and what controls are appropriate.
Better Approach
Conduct and document a comprehensive risk assessment on a regular basis and use the results to prioritize improvements.
Mistake #4: Weak Identity and Access Controls
Compromised credentials remain one of the most common ways attackers gain access to business systems.
Common issues include:
- Shared accounts
- Weak passwords
- Missing multifactor authentication
- Excessive administrative privileges
- Former employees still having access
Better Approach
Implement strong identity management practices, require multifactor authentication where appropriate, review user access regularly, and promptly remove access when employees leave.
Mistake #5: Poor Vendor Oversight
Many RIAs rely on third-party vendors for custodial platforms, cloud services, CRM systems, and communications.
However, vendor relationships should be managed—not assumed.
Better Approach
Maintain a documented vendor management process that includes:
- Due diligence before onboarding
- Periodic security reviews
- Contract reviews
- Documentation of vendor risk
- Annual reassessments for critical vendors
Mistake #6: No Tested Incident Response Plan (IRP)
Having an incident response plan is important.
Knowing whether it actually works is even more important.
If a ransomware attack occurred tomorrow, would everyone know their responsibilities?
Better Approach
Develop a written incident response plan and conduct periodic tabletop exercises to practice how the firm would respond to different scenarios.
Lessons learned should be documented and incorporated into future updates.
Mistake #7: Employee Security Training Is Inconsistent
Technology alone cannot prevent phishing attacks or social engineering.
Employees remain one of the strongest—and weakest—parts of a cybersecurity program.
Better Approach
Provide recurring cybersecurity awareness training throughout the year rather than relying on a single annual session.
Document participation and reinforce key topics such as phishing, password security, and handling sensitive information.
Mistake #8: Backups Are Never Tested
Many firms assume backups are working because backup software reports success.
Unfortunately, a successful backup doesn’t guarantee a successful recovery.
Better Approach
Test restoration procedures regularly and document the results.
A backup strategy should answer:
- How quickly can systems be restored?
- What data could be lost?
- Who is responsible for recovery?
- How are results documented?
Mistake #9: Waiting Until an SEC Examination Is Scheduled
Cybersecurity shouldn’t become a priority only after receiving an examination notice.
Trying to update documentation, implement new controls, and organize evidence under a tight deadline creates unnecessary stress and increases the likelihood of overlooking important details.
Better Approach
Treat cybersecurity readiness as an ongoing business process with scheduled reviews throughout the year.
Small improvements made consistently are generally more effective than large efforts completed under pressure.
Mistake #10: Choosing an IT Provider Without RIA Experience
Not every managed IT provider understands the operational and cybersecurity expectations of Registered Investment Advisors.
A provider unfamiliar with RIAs may deliver excellent technical support but lack experience with compliance documentation, regulatory expectations, or the workflows common in advisory firms.
Better Approach
When evaluating providers, ask questions such as:
- How many RIAs do you support?
- What cybersecurity documentation do you help maintain?
- How do you assist firms preparing for SEC examinations?
- What cybersecurity reporting do you provide?
- How do you approach vendor management and risk assessments?
Industry experience can make a significant difference when technology and compliance intersect.
CyberSecureRIA’s SEC Ready Checklist
Before your next examination, ask yourself:
- Have we completed a recent cybersecurity risk assessment?
- Are our policies current and reviewed annually?
- Is multifactor authentication implemented consistently?
- Do we maintain documented vendor reviews?
- Have we tested our incident response plan?
- Is employee cybersecurity training documented?
- Have we tested our backups?
- Are user access reviews performed regularly?
- Can we quickly locate our cybersecurity documentation?
- Are we continuously improving our cybersecurity program?
If you answered “no” to several of these questions, your firm may benefit from a structured cybersecurity readiness review.
Frequently Asked Questions
Do SEC examinations have a “pass” or “fail” result?
SEC examinations are not generally characterized as pass/fail. Examiners may identify deficiencies, request additional information, or recommend corrective actions depending on their findings.
What is the biggest cybersecurity mistake RIAs make?
There is no single mistake, but outdated documentation and inconsistent implementation of security practices are common issues that can complicate an examination.
How often should cybersecurity documentation be reviewed?
At a minimum, annually and whenever there are significant changes to your business, technology, or regulatory requirements.
Should small RIAs perform cybersecurity risk assessments?
Yes. Every RIA should understand its cybersecurity risks and document how those risks are evaluated and addressed, regardless of firm size.
Final Thoughts
Cybersecurity readiness isn’t about avoiding every possible issue—it’s about demonstrating that your firm has a thoughtful, documented, and continuously improving approach to protecting client information.
For most RIAs, the biggest opportunities aren’t found in buying more technology. They’re found in strengthening governance, documentation, employee awareness, vendor oversight, and ongoing operational discipline.
By addressing these common mistakes before your next SEC examination, you’ll be in a stronger position to respond confidently to examiner requests and better protect your clients and your business.
About CyberSecureRIA
CyberSecureRIA provides managed IT, cybersecurity, and compliance-focused technology services specializing in Registered Investment Advisors. We help firms build practical cybersecurity programs, maintain documentation, and prepare for SEC examinations with confidence.

