October is Cybersecurity Awareness Month, and it’s a good time to take stock of what you actually know versus what you think you know when it comes to cybersecurity. Not all the advice circulating in the industry is accurate. Some of it has been repeated for so long that it sounds like fact, even when it’s outdated or wrong.
When bad advice goes unchallenged, it creates blind spots — and blind spots are exactly what cybercriminals look for. RIAs are increasingly in their crosshairs, not because they’re careless, but because these knowledge gaps and assumptions make lean-staffed firms easy targets.
The good news: these gaps are simple to close once you know where they are. Here are six myths we hear from RIAs regularly, along with the truth behind each one.
Myth 1: We’re too small for cybercriminals to care about
There’s no such thing as a firm too small for an opportunistic cybercriminal. It doesn’t matter if you’re a solo advisor or a firm with 30 employees. If you have exposed accounts or vulnerable systems, bad actors will take advantage of it. An RIA holds something especially valuable: client data, account access, and a direct line to custodians.
Fact: Hackers choose targets based on opportunity, not size.
Myth 2: My team will recognize a phishing email
The days of obvious phishing emails full of typos are gone. Today’s emails are polished, personalized, and built to convince even a skeptical advisor that they’re from a trusted source — a custodian, a client, even the firm’s own principal.
Thanks to AI, it’s harder to catch a scam from the text alone. Instead, your team needs to think about sender behavior. Ask: would this person actually…
- Make an unusual request
- Change wire or payment instructions
- Request sensitive client information
- Send a new or unusual login link
If anything seems off, verify before clicking or responding.
Fact: A convincing email can still be a scam.
Myth 3: MFA fully protects our accounts
Multi-factor authentication is important, but it’s not invulnerable. Hackers use MFA fatigue to their advantage, counting on a stressed employee approving a request out of habit or annoyance. “Prompt bombing” floods a phone with requests, hoping someone approves access just to make it stop.
MFA is a tool, not a shield. It needs support from the controls around it — which is exactly what SEC examiners expect to see documented in your Written Information Security Policy (WISP).
Fact: MFA should be part of a broader security strategy, not the whole strategy.
Myth 4: Our backups have us covered
Ask yourself: if your firm was hit with ransomware tomorrow, could you restore client data and portfolio records? How long would it take?
A backup is only as good as your last test of it. An untested backup isn’t something you can rely on during an incident — and for an RIA, downtime isn’t just an inconvenience, it’s a client-facing and regulatory problem.
Fact: Having backups is not the same as being able to recover.
Myth 5: Cybersecurity is only IT’s responsibility
Your IT partner does a lot to keep your firm safe, but they can’t control every click an advisor or operations person makes. Cybersecurity decisions happen across the firm — compliance, client service, even the front desk. It takes only one bad click to expose client data.
Ongoing security awareness training matters, and it’s also something the SEC expects to see as part of your cybersecurity program.
Fact: Training your team to make good decisions strengthens your entire firm’s cybersecurity.
Myth 6: We know what to do if something happens
It’s Tuesday morning. Several employees suddenly can’t access their files. Many firms discover in that moment that nobody has answered the basic questions:
- Should employees shut down their computers?
- Who calls IT?
- What happens if communication systems are down?
- When does the insurance company get involved?
- Who communicates with clients, and how?
Don’t rely on memory in the moment — have a documented incident response plan, tested before you need it.
Fact: Your recovery plan shouldn’t debut during an incident.
Cybersecurity awareness starts with the facts
Cybersecurity Awareness Month is about making sure the assumptions guiding your decisions are correct. Myths are comfortable — they let you feel covered without digging deeper. But gaps rarely come from a missing product or procedure. They come from believing you’ve already got it handled when you don’t.
If any of these myths sound familiar, it’s worth taking a closer look at where your firm stands. Schedule a free 60-minute discovery call, and we’ll help you separate what’s actually protecting your firm and your clients from what’s only giving you peace of mind.
Call us at 865-622-9304 or visit our page to schedule yours.

