Skip to content

Managed IT and Cybersecurity for Columbus Investment Advisers

Your firm runs on a portfolio accounting system, a CRM holding every client household, a custodian portal, an e-signature tool, and a mailbox that carries wire instructions. All of it holds Social Security numbers, dates of birth and account numbers that belong to individual people. Which cybersecurity rules govern an advisory firm turns on one question most owners can answer in a sentence: is the firm registered with the SEC, or with the Ohio Division of Securities? The two answers lead to almost entirely different obligations, and the federal set stopped having a grace period on June 3, 2026.

Which advisory firms does Regulation S-P reach, and which do Ohio's adviser rules cover?

Which regulator applies is the first question, because the two rule sets barely overlap. Registration turns on assets under management. Below $25 million an adviser is barred from SEC registration and registers with the Ohio Division of Securities instead. Between $25 million and $100 million the firm is a "mid-sized adviser": Ohio's examination authority under OAC 1301:6-3-15.1(E) means an Ohio-based mid-sized adviser is required to register there rather than with the SEC. From $100 million up to $110 million federal registration is permitted but not required; at $110 million the option closes and registration becomes mandatory. A handful of carve-outs put an otherwise state-sized adviser back with the SEC regardless of AUM: advisers to registered investment companies register under the Advisers Act itself (15 U.S.C. 80b-3a(a)(1)(B)), and pension consultants, internet advisers, and firms that would otherwise register in 15 or more states are carved back in at 17 CFR 275.203A-2.

Crossing the line carries a deadline either direction. Where an annual Form ADV amendment reports a firm is now SEC-eligible, the application to the Commission is due within 90 days of that filing (17 CFR 275.203A-1(b)(1)); where it reports the firm is no longer eligible, Form ADV-W to withdraw is due within 180 days of the fiscal year end (275.203A-1(b)(2)).

For an SEC-registered adviser, Regulation S-P subpart A binds in full. 17 CFR 248.1(b) applies it to advisers registered with the Commission, and there is no assets-under-management floor and no employee-count floor inside the rule itself, so a two-person RIA owes the same written program as a firm with a compliance department. Most of the subpart is limited to nonpublic personal information about individuals who obtain services for personal, family or household purposes, so a firm advising only pensions and corporations holds little customer information in the rule's sense. The disposal rule at 248.30(b) is the exception. It is expressly excepted from that limit and reaches consumer-report-derived records about people who were never the firm's clients.

An Ohio-registered adviser sits outside Regulation S-P subpart A, and a different stack applies. OAC 1301:6-3-15.1(E)(1)(u) requires written cybersecurity policies covering five functions (identify, protect, detect, respond, recover), reviewed no less than annually. Paragraph (E)(1)(v) requires written business continuity and succession procedures, and paragraph (H) requires a privacy policy delivered on engagement and annually thereafter. OAC 1301:6-3-44(H)(1) separately makes it unlawful to provide investment advice at all without written compliance policies, reviewed for adequacy no less than annually, administered by a designated supervised person. One duty reaches advisers on either side of the line: Ohio's breach notification statute at ORC 1349.19.

What does Regulation S-P require of an SEC-registered adviser today?

All of it, with no remaining grace period. The Commission adopted the amendments on May 16, 2024. They were published in the Federal Register on June 3, 2024 and took effect August 2, 2024, and the compliance periods ran from that publication date: 18 months for larger entities, 24 months for smaller ones. The adopting release set the larger-entity threshold, for advisers, at $1.5 billion or more in assets under management, which put the compliance dates at December 3, 2025 and June 3, 2026. Both have passed. Every SEC-registered adviser of every size has been fully subject to the amended rule since June 3, 2026, and the tier distinction is now history. If something you read in 2024 or 2025 left the impression that this is still upcoming, it is not.

Two duty sets sit inside subpart A. The older one is the privacy notice: a clear, accurate initial notice delivered when the client relationship begins, which for an adviser is when the advisory contract is entered into (17 CFR 248.4, 248.4(c)(3)(iii)), and again not less than annually thereafter (248.5(a)(1)). The newer one is the safeguards program. Every covered institution must develop, implement and maintain written administrative, technical and physical safeguards reasonably designed to protect customer information (17 CFR 248.30(a)(1)-(2)). A practice everyone follows but nobody wrote down does not satisfy a written-policy rule. That program must include an incident response program covering three procedures: assess the scope of an incident and which systems and information were affected, contain and control it, and notify affected individuals (248.30(a)(3)).

The customer notice runs on a paired clock: as soon as practicable, but not later than 30 days, after becoming aware that unauthorized access to customer information has occurred or is reasonably likely to have occurred (17 CFR 248.30(a)(4)(iii)). Thirty days is the ceiling. The clock starts on awareness of unauthorized access to customer information generally, so the investigation into whether sensitive customer information was involved has to finish inside the 30 days. It cannot wait to start until that is confirmed. Sensitive customer information is a defined list at 248.30(d)(9): some elements, like a Social Security number, stand alone; others, like a date of birth, are sensitive only in combination with a name or account identifier. The boundary in 248.30(d)(9) is what settles a given exposure, because it decides who gets notified. Where a firm cannot identify which specific individuals were affected, the rule directs notice to everyone whose sensitive information resided in the affected system (248.30(a)(4)(ii)). Thin logging turns a contained incident into a mailing to an entire book.

Two more duties round it out. Section 248.30(b) requires written policies for proper disposal of consumer and customer information, reaching retired laptops, servers and drives as much as paper. And the Regulation S-P records (the safeguards policies, service-provider policies, and documentation of any detected access and the response to it) live at 17 CFR 275.204-2(a)(25), preserved for not less than five years from the end of the fiscal year of the last entry, with the first two years kept in an appropriate office of the adviser. The only notice the rule sends outward is to affected individuals. Nothing in Regulation S-P requires an adviser to report an incident to the SEC itself.

When a custodian or software vendor reports a breach, what does the rule require, and when?

The incident response program must require oversight of service providers and require them to notify the adviser as soon as possible, but no later than 72 hours, after becoming aware of a breach affecting a customer information system they maintain (17 CFR 248.30(a)(5)(i)). Seventy-two hours is the ceiling on the vendor, paired with "as soon as possible," the same structure as the adviser's own 30-day clock to customers. "Service provider" is defined broadly at 248.30(d)(10): the custodian, portfolio accounting and CRM platforms, cloud and email hosting, document vault, e-signature tool and outsourced IT all qualify. A firm may contract with a provider to send customer notices on its behalf, but 248.30(a)(5)(iii) keeps the underlying obligation with the adviser regardless. And because the 30-day clock runs from the adviser's awareness, a vendor using its full 72 hours consumes that notice window rather than extending it.

Ohio's breach statute layers on top. The federal rule does not displace it (17 CFR 248.17). ORC 1349.19(B) requires notice to affected Ohio residents in the most expedient time possible and no later than 45 days following discovery or notification of a breach. The financial-institution exemption at 1349.19(F)(1) is narrower than its name suggests. It reaches only a financial institution, trust company or credit union, or an affiliate of one, and only where it is both required by federal law to notify customers and examined by a federal regulator for compliance with that law. An advisory firm is chartered as none of those, so on the face of the text the exemption does not reach it. Practically, an Ohio-registered adviser owes the Ohio notice alone. An SEC-registered adviser owes two notices off one incident, on different clocks, and the Regulation S-P analysis comes first, since its clock is tighter, with Ohio layered on top. The statute also reads from the other side: where a firm holds personal information on behalf of another firm, as a sub-adviser or shared back office, ORC 1349.19(C) casts it as the vendor in that relationship and requires notice to that firm of a breach.

An advisory book is made of individual people, so a few hundred client families and their beneficiaries can pass a thousand affected Ohio residents on a single incident. Past that threshold, ORC 1349.19(G) adds a second notice, to every nationwide consumer reporting agency, without unreasonable delay. It does not extend the 45-day resident deadline. None of this is survivable on a 30-day clock without a clear account of what actually happened. The evidence that scopes an incident, instead of notifying everyone in the affected system by default, has to exist before the incident: retained logs, endpoint and mailbox telemetry, alerting on mailbox-rule changes, and a record of which vendors touch which data. That is ordinary Managed IT Services and Cyber Security Solutions work, and it is the difference between a written determination that holds up to an examiner and a mailing to an entire book.

Who can move client money, and how do you prove that list is current?

Moving client money is never one system. The instruction arrives by email. The bank detail it points at lives in the CRM. The authority to send it lives in the custodian portal. The authorization gets signed in the e-signature tool, and the account numbers that tie it all together sit in portfolio accounting. That is five user lists, five sets of admin roles and five separate multifactor settings, and usually only the mailbox is joined to your Microsoft tenant. So the answer to a plain question (who at this firm can start a transfer today) has to be assembled by asking people rather than read off a list. The failure that follows is ordinary. Someone leaves, their email is shut off that afternoon, and the custodian login, the CRM seat and the e-signature account keep working, because no one owned them.

The work starts at hire. Onboarding and offboarding get handled as a per-person, per-system list: every account a role needs, written down when it is created, then run in reverse on the last day with a date and a name against each line. Multifactor authentication goes on every account that can reach client data or start a transfer, including logins held by contractors and an outside bookkeeper. Where a platform cannot enforce it, that becomes a written exception with a named owner, a compensating control and a review date, instead of a gap nobody has looked at. Authority gets split on purpose: the person who can change standing bank instructions in the CRM is not the person who releases the wire, and a changed instruction is confirmed by calling a number already on file rather than the number in the message. Managed IT covers the onboarding and offboarding side and cloud IT services the identity and mailbox side. A callback step becomes a habit rather than a paragraph in a manual.

What makes any of it defensible is the review. On an interval you set and can defend, each system’s user list gets exported and read name by name by someone who knows what those people actually do, with removals and exceptions recorded and dated. That record answers two audiences at once. It is the evidence behind whichever written program applies, the safeguards program under Regulation S-P or the five-function policies under OAC 1301:6-3-15.1(E)(1)(u). It is also what a cyber insurance renewal is reaching for when the questionnaire asks whether multifactor authentication is enforced on email and remote access, and whether access is removed when someone leaves. Answering those questions means producing the current export showing enforced state, the exception list with owners and dates, and termination records that line up with your HR dates. An attestation with no export behind it is an assertion. Building that evidence and keeping it current is Compliance-as-a-Service and virtual CISO work: evidence tracking, control maintenance and renewal support on a schedule.

What else has to be in place before an examiner asks?

Regulation S-ID predates the 2024 changes and hinges on SEC registration plus financial-institution or creditor status. 17 CFR 248.201(a)(3) reaches an adviser registered or required to register under the Advisers Act. An Ohio-registered firm sits outside it by definition, since section 203A bars it from SEC registration, and owes the FTC's Red Flags Rule at 16 CFR 681.1 instead, with matching duties at 681.1(c), (d) and (e). Either way the hinge is whether the firm holds a transaction account for a client: an adviser with authority to direct transfers or payments from a client account generally qualifies (15 U.S.C. 1681a(t)). An adviser with no money-movement authority may not.

The first duty is the determination itself, owed even by a firm that concludes the answer is no: a periodic determination of whether the firm offers or maintains covered accounts, including a risk assessment of how accounts are opened and accessed (17 CFR 248.201(c)). The rule sets no fixed interval. The interval is the firm's to set and defend in writing, and a firm with nothing on paper has failed the rule regardless of the answer. Where the answer is yes, the rule calls for a written Identity Theft Prevention Program to detect, prevent and mitigate identity theft, sized to the firm, that identifies relevant Red Flags, detects them, responds to them, and gets updated periodically (248.201(d)). Approval is its own requirement and where small firms slip: the initial Program needs board or board-committee approval, with a designated senior-management employee substituting where there is no board (248.201(e), (b)(2)(ii)).

Ohio offers a shield rather than a duty: ORC 1354.02 gives an affirmative defense to a tort claim alleging a security failure caused a data breach, to an entity whose written program reasonably conforms to a named framework, or (the adviser-specific route) to the entirety of GLBA Title V under ORC 1354.03(B)(1)(b). Our professional-services page sets out the full framework list, the revision clock, and the limits of the defense. The short version for an adviser is the same: it is elective, it does not excuse the ORC 1349.19 notice, and it binds no regulator.

What every one of these instruments has in common is that each rests on a written assertion that controls exist. An examiner, eventually, tests whether the sentence is true. That is what the Security Analysis is built to find out first: a $349 independent engagement mapped to 38 compliance frameworks at https://outreach.ttscyber.com/analysis. Have the finding in hand before you sign the next annual review or name a framework in your written program.

Start here

Find out where you actually stand

The Security Analysis is a fixed-scope review of your environment, run independently and mapped to 38 compliance frameworks. It is the fastest way to replace an assumption about your posture with a finding.

Questions we get asked

Does the federal 30-day breach notice rule apply to an Ohio-registered adviser?

Not Regulation S-P subpart A. 17 CFR 248.1(b) applies that subpart to advisers registered with the Commission, and an Ohio license does not make a firm a covered institution under 248.30(d)(3). So the incident response program, the 30-day customer notice and the 72-hour vendor-notification policy sit outside that firm's stack. A different stack applies: OAC 1301:6-3-15.1(E)(1)(u) requires written cybersecurity policies covering identify, protect, detect, respond and recover, reviewed no less than annually; paragraph (E)(1)(v) requires business continuity procedures; paragraph (H) requires a privacy policy on engagement and annually thereafter; and OAC 1301:6-3-44(H)(1) requires written compliance policies reviewed for adequacy no less than annually. On top of that, ORC 1349.19 requires notice to affected Ohio residents in the most expedient time possible and no later than 45 days, and the FTC's Red Flags Rule requires a periodic determination of whether a firm maintains covered accounts and a written Identity Theft Prevention Program if it does. State registration means a different set of duties. It does not mean fewer of them. TTS Cyber is not a law firm; this is not legal advice.

When an investigation concludes no customer notice is owed, what does Regulation S-P still require?

Documentation, and the right test. Notice is the default under Regulation S-P: each affected individual is notified unless the firm determines, after a reasonable investigation, that the sensitive customer information has not been and is not reasonably likely to be used in a way that causes substantial harm or inconvenience (17 CFR 248.30(a)(3)(iii), (a)(4)(i)). Silence is not that determination, and the investigation has to fit inside the 30-day window. The clock starts on awareness of unauthorized access generally. It does not wait for confirmation that sensitive information was involved. The documentation duty is separate: 17 CFR 275.204-2(a)(25)(iii) requires written documentation of any investigation and determination regarding whether notification was required, including the basis for it and a copy of any notice sent, preserved for not less than five years. A decision not to notify with nothing in the file is a recordkeeping violation sitting next to the incident. Ohio's notice duty under ORC 1349.19 runs on its own trigger and its own 45-day clock, so clearing the federal test does not clear that one. TTS Cyber is not a law firm; this is not legal advice.

Do you work with advisory firms outside Columbus?

Support is delivered remotely nationwide, and onsite work can be arranged in any of the 50 states. The office is at 1733 W Lane Ave in Columbus, and the bulk of onsite work is across Central Ohio, so advisory firms in and around Franklin County are closest to it.

Does the Red Flags Rule require anything in writing from an RIA with no custody and no authority to move client money?

Yes. The first duty the rule imposes is the determination itself, and it is owed even by a firm whose answer is no. 17 CFR 248.201(c) requires an SEC-registered adviser to periodically determine whether it offers or maintains covered accounts, including a risk assessment of how accounts are opened and how they are accessed. An Ohio-registered firm sits outside that section and owes the FTC’s Red Flags Rule at 16 CFR 681.1(c), (d) and (e) instead, with matching duties. There is no fixed interval, so the interval is the firm’s to set and defend in writing, and a firm with nothing on paper has failed the rule regardless of which way the answer came out. The hinge is transaction-account authority under 15 U.S.C. 1681a(t). An adviser with authority to direct transfers or payments from a client account generally qualifies. Where the answer is yes, the rule calls for a written Identity Theft Prevention Program approved by a board, a board committee, or a designated senior-management employee where there is no board (17 CFR 248.201(d), (e) and (b)(2)(ii)). TTS Cyber is not a law firm; this is not legal advice.

Primary sources

Read the rules yourself

Everything on this page rests on the text below. Where a section is named above, it is worth reading in the instrument rather than taking a summary for it, including this one.

Reference

Explained in full elsewhere on this site

TTS Cyber is an IT and cybersecurity company, not a law firm, and nothing on this page is legal advice. This page summarises published rules and cites them so they can be read directly; where this page and the source differ, the source governs. Whether a particular rule reaches a particular business, and what it requires of that business, are legal questions for that business's own attorney.

Page last updated .

Let’s Get in Touch!

Security Analysis

Find out where you actually stand.

Most businesses do not discover a gap until something goes wrong. This is a fixed-scope analysis of your environment, run independently, so you get an answer rather than an opinion.

What the analysis covers