ArmourIQ LogoArmourIQ

For US Registered Investment Advisers

Security your clients can trust

Under the amended Regulation S-P, every adviser is now expected to run a written information security program, an incident response plan, and real oversight of the vendors that touch client data. We help RIAs put those in place, keep them current, and explain them to a board, without the overhead of building a large security team in-house.

Regulation S-P

What Regulation S-P now requires

The SEC's amended Regulation S-P is now in effect. Under it, an adviser is expected to:

  • Maintain a written incident response program covering how you detect, respond to, and recover from unauthorised access to client information.
  • Keep written information-security and privacy policies, with documented safeguards for client records.
  • Notify affected clients as soon as practicable, and no later than 30 days after discovering a breach.
  • Oversee your service providers in writing, with contracts that require them to report an incident to you within 72 hours.

This is what examiners look for, and what your own investors ask about in their due-diligence questionnaires. Having the documents is one thing. Being able to show they work is another.

Services

Where we help

We work across the areas an adviser is now expected to cover. You can start with the one that is most pressing and add others as you need them.

Information security program (WISP)

Build or refresh the written program the SEC expects, mapped to a recognised framework such as NIST CSF, and sized to your firm rather than copied from a bank.

Incident response plan

A written plan your team can actually follow, with the roles, steps, and the 30-day client-notification process Regulation S-P requires, then tested with a tabletop exercise so it holds up under pressure.

Vendor and third-party risk

A practical process for assessing the providers that touch your data, and the 72-hour incident-reporting terms your contracts now need. We also help you answer the security questionnaires your clients and allocators send you.

Cloud and email security

Reviews of how your core platforms are configured and secured, including Microsoft 365, Google Workspace, your CRM, and custodial connections. The focus is identity, access, multi-factor authentication, and the account settings attackers exploit, such as weak logins and malicious mailbox forwarding rules. We assess how the environment is secured, not the contents of your email.

Risk assessment

A clear read of where you stand against the SEC's expectations and a recognised framework, with findings ranked by real impact and a remediation order you can work through.

Penetration testing

Web, application, and infrastructure testing when you need technical assurance, delivered as risk-ranked findings and fixes rather than raw scanner output.

Security awareness

Training built for an adviser's staff, focused on the phishing and wire-fraud attempts that target the industry.

Ongoing security leadership (vCISO)

Senior security guidance on a continuing basis: keeping your program current, preparing updates for your board and committees, and being the person your team calls when something looks wrong. This is a relationship, not a one-time report.

Our approach

How we work with advisers

Ongoing, not one and done

Compliance expectations do not reset each year, and neither should your security. Most of our work with advisers is a continuing arrangement: we keep your program current as your firm and the rules change, rather than handing you a report and moving on.

Practitioner-led

The person who scopes your work is the person who does it. You deal directly with a senior practitioner.

Plain language, board-ready

Findings and updates are written so your compliance, operations, and leadership can all act on them, and so you can put them in front of your board or produce them when asked.

Scoped to your firm

We size the work to an adviser your size. You pay for what reduces your risk and meets the expectation, not for a program built for a bank.

Questions

What advisers usually ask

Get Started

Start with a scoping call

Tell us where your firm is today: what you already have in place, what an examiner or investor has asked for, and what is worrying you. We will come back with a clear next step and an honest view of what you actually need. No sales pitch.