Legal Cyber Academy
All insights

Regulation S-P: The Incident Response Obligations Advisers Keep Missing

By the Legal Cyber Academy editorial team ·

What amended Regulation S-P actually requires

Amended Regulation S-P (17 CFR 248.30) requires broker-dealers, funding portals, investment companies, SEC-registered investment advisers, and registered transfer agents to maintain a written incident response program and to notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. Notice must go out as soon as practicable and no later than 30 days after the firm becomes aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred.

The compliance dates have passed, and the clock starts before the investigation closes

The Commission adopted the amendments on May 16, 2024, published them at 89 FR 47688 on June 3, 2024, and made them effective August 2, 2024. The release gives larger entities 18 months from publication and smaller entities 24 months — December 3, 2025 and June 3, 2026. Table 3 of the release defines "larger entity" as investment companies with net assets of $1 billion or more as of the end of the most recent fiscal year, counted together with other investment companies in the same group of related investment companies; registered investment advisers with $1.5 billion or more in assets under management; and broker-dealers and transfer agents that are not small entities under the Exchange Act for Regulatory Flexibility Act purposes.

The trigger is where programs drift. Rule 248.30(a)(4)(iii) starts the 30 days when the firm becomes aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred — not when it concludes that sensitive customer information was involved, and not when the investigation closes. Commenters asked the Commission to run the clock from the completion of a reasonable investigation, and one asked that it run from the point the firm determines an incident involved sensitive customer information rather than customer information; the Commission adopted the proposed trigger unchanged. The reasonable investigation happens inside the 30 days — the release describes the rule as "allowing covered institutions up to 30 days to conduct a reasonable investigation after becoming aware of an incident."

The release is blunt that a firm "may still be working towards remediating the breach after the 30-day timeframe" and must notify anyway. It also answers the ransomware objection directly: a comment that notice may be logistically impossible where an attack has denied the firm access to its systems "does not account for the fact that" firms must now have a response program, so they "will need to anticipate and prepare for the possibility that they may be denied access to a particular system" and have procedures for complying with the notice requirements. See ransomware response and legal obligations.

Deciding not to notify is a determination, and it produces a file

Notice is the default and the exception is narrow. Under 248.30(a)(4)(i), notice is required unless the covered institution determines, after a reasonable investigation of the facts and circumstances, that the sensitive customer information "has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience."

Two things follow. First, the standard is keyed to use causing substantial harm or inconvenience. The Commission's own survey of state law in the release found that 43 states have some no-harm exception and that the harms they reference are most commonly harm generally (13 states), identity theft or other fraud (10), or misuse of personal information (8); eight states, including California and Texas, have no no-harm exception at all. Second, the release states that the rule "does not permit a covered institution to rebut the presumption of notification without conducting a reasonable investigation," and that policies and procedures "generally should be designed to include revisiting notification determinations whenever the covered institution becomes aware of new facts that are potentially relevant to the determination." The release's own example is a determination resting on encryption, where the encryption is later compromised or the decryption key turns out to have been taken.

The recordkeeping amendments then require written documentation of that investigation and determination, "including the basis for any determination made." A decision not to notify is therefore a documented determination resting on an evidentiary basis, often a forensic finding — which is why the underlying report matters as much as the conclusion drawn from it; see how to read a forensic report.

When forensics cannot name the affected individuals

Rule 248.30(a)(4)(ii) resolves the scoping problem against the firm. If unauthorized access to or use of customer information occurred or is reasonably likely to have occurred but the firm is unable to identify whose sensitive customer information was reached, it must notify all individuals whose sensitive customer information resides in the customer information system that was, or was reasonably likely to have been, accessed or used without authorization — less any individual the firm reasonably determines was not affected.

System design and logging quality therefore bear directly on the size of the notice population. The Commission expected as much: it said the provision should incentivize firms to establish procedures giving robust protection to sensitive customer information and that, for example, it "may encourage covered institutions to employ a principle of least privilege," limiting access rights to what users strictly require. The controls that narrow a notice list — segmentation, access limits, and telemetry good enough to exclude individuals afterward — are in place before the incident or not at all.

The notice itself: eight elements, in writing, no substitute notice

Rule 248.30(a)(4)(iv) prescribes eight contents: a general description of the incident and the type of sensitive customer information involved; the date, estimated date, or date range, if reasonably possible to determine at the time notice is given; contact information sufficient to permit the individual to inquire, including a telephone number (which should be toll-free if available), an email address or equivalent method, a postal address, and the name of a specific office; for individuals who have an account with the firm, a recommendation to review account statements and immediately report suspicious activity; an explanation of what a fraud alert is and how to place one; a recommendation to obtain credit reports periodically from each nationwide credit reporting company and to have information relating to fraudulent transactions deleted; how to obtain a credit report free of charge; and information about the availability of online guidance from the FTC and usa.gov, a statement encouraging the individual to report identity theft to the FTC, and the FTC's website address.

Firms may add information but may not omit any of it, and additional content may not prevent the required content from being presented clearly and conspicuously. The notice must be clear and conspicuous within the meaning of 17 CFR 248.3(c)(1) and transmitted "by a means designed to ensure that each affected individual can reasonably be expected to receive actual notice in writing." There is no substitute-notice provision. The Commission observed that all states allow substitute notice under certain conditions — generally email, a website posting, and notification to major statewide media — and said the final amendments "do not provide for such substitute notice and instead have the same notice requirements in all cases." The writing requirement can be met on paper or, for customers who have agreed to receive information electronically, by electronic means consistent with the Commission's existing electronic-delivery guidance at 61 FR 24644 (May 15, 1996) and 65 FR 25843 (May 4, 2000). One change from the proposal cuts drafting time: the final rule dropped the proposed requirement that the notice describe what the firm has done to protect the information from further unauthorized access or use.

Delay is narrow, and it is not the firm's to grant

The only delay mechanism runs through the Attorney General, who must determine that the notice required under the rule poses a substantial risk to national security or public safety and notify the Commission in writing. That buys a period specified by the Attorney General of up to 30 days beyond the date notice was otherwise required, plus a further 30 days on a renewed determination, plus — in extraordinary circumstances, and only where the Attorney General determines the notice continues to pose a substantial risk to national security — a final period of up to 60 days. Beyond that, if the Attorney General indicates further delay is necessary, the Commission will consider additional requests and may grant delay through exemptive order or other action. There is no general law-enforcement delay of the kind many state statutes provide, and nothing in 248.30 lets a firm extend the deadline itself.

Note also that rule 248.30 requires no notice to the SEC itself; the Commission enters only through the Attorney General's written determination. Public-company issuers face a separate and differently triggered obligation — see the SEC cybersecurity disclosure rules. The Regulation S-P release draws the contrast itself, noting that its "becoming aware" standard "differs from the reporting trigger in the Public Company Cybersecurity Rules," which run four business days from an issuer's determination that an incident is material, and that covered institutions under Regulation S-P are not required to make a materiality determination at all.

Service providers: 72 hours in, oversight in your policies, obligation stays with you

The final rule dropped the proposed contractual mandate. As the Commission put it, the amendments "will no longer require covered institutions to have a written contract with its service providers mandating that service providers take appropriate measures to protect against unauthorized access to or use of customer information, but will instead require covered institutions to establish written policies and procedures reasonably designed to oversee, monitor, and conduct due diligence on service providers."

So 248.30(a)(5)(i) requires the response program to include the establishment, maintenance, and enforcement of written policies and procedures reasonably designed to require oversight — "including through due diligence and monitoring" — of service providers, including to ensure the covered institution notifies affected individuals under (a)(4). Those policies and procedures must be reasonably designed to ensure service providers take appropriate measures to protect against unauthorized access to or use of customer information and to notify the covered institution "as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider."

Read the scope carefully. The 72-hour report is keyed to unauthorized access to a system, not to confirmed access to customer information, and it is not limited to sensitive customer information. The Commission declined to narrow it on either point, stating that it is "not limiting the scope of incidents to be reported to covered institutions to only those involving 'sensitive customer information' or alternatively to breaches that result in unauthorized access to 'customer information' maintained by the service provider rather than those that result in unauthorized access to a service provider's 'customer information system.'" It also kept the "becoming aware" trigger, rejecting proposed "reasonable basis to conclude" and "determining" standards. On receipt of such notification, the covered institution "must initiate its incident response program." The rule permits a written agreement under (a)(5)(ii) delegating notice to the provider, but (a)(5)(iii) leaves the obligation to ensure affected individuals are notified with the covered institution. Where a provider misses the 72 hours, the release says the firm generally should reevaluate the policies and procedures governing that relationship and make adjustments as necessary.

One asymmetry is easy to miss. The notice duty under (a)(4)(i) covers incidents at the covered institution or at a service provider "that is not itself a covered institution." Where the vendor is itself a covered institution, that firm carries the notice obligation for its own incident — and, per the release, if a covered institution is acting as a service provider it must also notify the other covered institution under (a)(5)(i). The Commission made the change to avoid duplicative notices to the same individuals, and acknowledged that a notifying institution "may not have access to the contact information for some customers," in which case "it can coordinate with the covered institution that has a customer relationship to receive contact information as needed for the notices." On vendor notification terms and notification-cost coverage, see what attorneys should advise on cyber insurance.

Whose information counts

For every covered institution other than a registered transfer agent, "customer information" under 248.30(d)(5)(i) reaches any record containing nonpublic personal information — as defined in 17 CFR 248.3(t) — about a customer of a financial institution, in paper, electronic or other form, that is in the covered institution's possession or that is handled or maintained by it or on its behalf, regardless of whether the information pertains to individuals with whom it has a customer relationship or to the customers of other financial institutions where that information has been provided to it. An adviser holding a custodian's file, or a servicer holding another firm's records, is holding covered information. Transfer agents work from a separate definition at (d)(5)(ii), keyed to natural persons who are securityholders of an issuer for which the transfer agent acts or has acted.

Entity scope has its own traps. Regulation S-P applies to investment companies as defined in section 3 of the Investment Company Act whether or not registered with the Commission, so a business development company — an investment company not required to register as such — is subject to it, as are employees' securities companies, including those not required to register. Because they are not registered under section 8 of the Investment Company Act, those companies keep their records under 248.30(c) itself rather than the fund recordkeeping rules. Issuers excluded from the investment company definition, such as private funds relying on section 3(c)(1) or 3(c)(7), are not subject to Regulation S-P, though their SEC-registered adviser is. Transfer agents are covered where registered with the Commission or another appropriate regulatory agency as defined in section 3(a)(34)(B) of the Exchange Act. Funding portals are not "covered institutions" under 248.30(d)(3) at all; they are pulled in by Regulation Crowdfunding, which requires a funding portal to comply with part 248 "as [it applies] to brokers" (17 CFR 227.403(b)).

What the file has to hold, and for how long

Six categories of records: the safeguards policies and procedures under (a)(1); documentation of any detected unauthorized access to or use of customer information and the response to and recovery from it under (a)(3); documentation of any investigation and determination whether notification is required under (a)(4), including the basis for any determination made, any written documentation from the Attorney General related to a delay, and a copy of any notice transmitted; the service provider oversight policies and procedures under (a)(5)(i); any contract or agreement entered into under (a)(5); and the disposal policies and procedures under (b)(2).

Retention differs by registrant type, and within a single rule the clocks differ:

  • Broker-dealers (17 CFR 240.17a-4(e)(14)) and transfer agents (240.17ad-7(k)): three years, in an easily accessible place — but policies and procedures and any (a)(5) agreement run until three years after the termination of their use or of the agreement, while incident documentation and investigation/determination records run three years from the date the records were made.
  • Registered investment advisers (275.204-2(a)(25)): five years in an easily accessible place from the end of the fiscal year during which the last entry was made, the first two years in an appropriate office of the adviser (275.204-2(e)(1)).
  • Registered funds (270.31a-1(b)(13)): six years, the first two in an easily accessible place, under 270.31a-2(a)(8), which separately requires a copy of the policies and procedures in effect, or in effect at any time within the past six years, in an easily accessible place.
  • Unregistered investment companies (248.30(c)): the same six-year period and policies-and-procedures treatment, set out in 248.30(c)(2).
  • Funding portals: not subject to 17a-4. Under Regulation Crowdfunding Rule 404(a)(5) they already preserve records demonstrating compliance with, among other things, Regulation S-P for five years, the first two in an easily accessible place; the release says portals "generally should look to make and preserve the same scope of records" as brokers keep under the amendments.

The Division of Examinations, in its fiscal year 2026 priorities, said it will engage firms during examinations about their progress in preparing incident response programs and that "[a]fter the applicable compliance dates, the Division will examine whether firms have developed, implemented, and maintained policies and procedures in accordance with the rule's new provisions that address administrative, technical, and physical safeguards for the protection of customer information," with examinations focused on "firms' policies and procedures, internal controls, oversight of third-party vendors, and governance practices." Examination priorities are a staff statement that, by its own terms, "has no legal force or effect," but they describe what gets requested.

How this sits with state breach law

Regulation S-P is a federal floor, not a ceiling. GLBA's relation-to-state-law provision, 15 U.S.C. 6807(a), provides that the subchapter does not supersede, alter, or affect state law except to the extent of an inconsistency, and then only to the extent of the inconsistency. Under 6807(b), a state provision is not inconsistent if the protection it affords any person is greater than the federal protection — a determination the statute assigns to the Consumer Financial Protection Bureau, after consultation with the functional regulator, on its own motion or on petition.

Some states relieve GLBA-compliant firms of individual notice while keeping a separate regulator obligation. The District of Columbia does so at D.C. Code § 28-3852(g), but only for an entity that both maintains procedures for a breach notification system under GLBA Title V and "provides notice in accordance with such Acts, and any rules, regulations, guidance and guidelines thereto, to each affected resident"; even then, the entity "shall, in all cases, provide written notice of the breach of the security of the system to the Office of the Attorney General for the District of Columbia as required under subsection (b-1)," which applies where 50 or more District residents are affected.

New York works similarly but preserves two obligations, not one. Under N.Y. Gen. Bus. Law § 899-aa(2)(b), where notice is made to affected persons under the breach notification requirements of enumerated laws — including regulations under Title V of the Gramm-Leach-Bliley Act (15 U.S.C. 6801 to 6809) — "nothing in this section shall require any additional notice to those affected persons, but notice still shall be provided to the state attorney general, the department of state and the division of state police pursuant to paragraph (a) of subdivision eight of this section and to consumer reporting agencies pursuant to paragraph (b) of subdivision eight." Subdivision 8(a) also reaches the department of financial services where the entity is a covered entity as defined in 23 NYCRR 500.1. New York's individual-notice deadline is thirty days after the breach "has been discovered," subject to the legitimate needs of law enforcement under subdivision 4 — a discovery trigger with a law-enforcement delay, where the SEC uses an awareness trigger with none. A firm can satisfy 248.30 in full and still owe state officials and consumer reporting agencies a filing, on a clock that started at a different moment. The state matrix and the federal analysis run off the same incident timeline.

Learn more

Legal Cyber Academy faculty teaching in adjacent areas — privacy enforcement, vendor and third-party risk, incident response, and cyber insurance — include David Shonka, Partner and General Counsel at Redgrave LLP and a three-time Acting General Counsel of the FTC; Aaron Tantleff, Partner at Foley & Lardner; Roland Cloutier, former Global Chief Security Officer of TikTok; Sean Zadig, SVP and CISO at Yahoo; and Tamara Snowdon, Head of Cyber Risk Wordings at Beazley.

This article is general information about published rules and is not legal advice.

Go deeper — courses on this

Keep reading

Get the next one by email

Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.