The regulatory baseline for RIA cybersecurity shifted materially in 2024 and 2025. The SEC's May 2024 amendments to Regulation S-P — the Safeguards Rule — require all SEC-registered investment advisers to maintain written cybersecurity and incident response policies, notify affected clients within 30 days of a confirmed breach, and ensure that third-party service providers notify the RIA within 72 hours of discovering an incident involving customer information.
In fact, the SEC flagged Regulation S-P compliance as an examination priority for fiscal year 2026 and, in November 2025, settled charges against a registered advisory firm for $325,000 after email account takeovers across its branch offices exposed thousands of client records — the proximate cause being the absence of a written information security program. Against that backdrop, three advisors describe a threat environment that has accelerated faster than the regulation has.
Brian Francetich, shareholder and director of Golsan Scruggs RIA, says his firm's posture is more alert and on defense than at any prior point in his career. The shift, in his reading, is not primarily technical. It is behavioral.
The most successful cyberattacks targeting advisory firms today involve social engineering rather than purely technical exploits — and the tactics have grown more convincing at scale. AI-generated voice cloning and deepfake technology are increasingly being used to impersonate clients in real time, making it harder for advisors to detect fraud through the channels they have historically trusted most: a familiar voice on the phone or a recognizable email tone.
"Cybercriminals are using AI at an alarming scale making their approaches more convincing and their targets more susceptible. Voice cloning and deepfakes are making their way into the mix. We believe RIAs need to spread the word to their clients that they will be slowing down in order to quadruple check and keep funds safe," Francetich said.
Francetich has observed multiple situations where RIAs were thoroughly convinced they were communicating with their client on a money movement request — and were in fact interacting with a cybercriminal. The mechanism is consistent: attackers first compromise a client's email account, then scan for financial correspondence to identify the client's advisory relationship, and then use that intelligence to impersonate the client to the RIA. The RIA is not the initial target; it becomes the target because it sits between the criminal and the client's money. Francetich's core message to advisors is that no firm is too small to be in the path of that sequence. AI has allowed attackers to increase the volume of attacks dramatically, and automated scanning does not discriminate by firm size.
Charles "Chuck" Failla, founder and CEO of Sovereign Financial Group, says his view of cybersecurity has undergone a fundamental reframe. He used to think of it as an IT problem. He now thinks of it as a client trust problem — and the distinction changes where he invests his attention.
In addition to what his IT team is doing at the infrastructure level, Failla now dedicates significant time to educating clients, advisors, and staff on the principles of safe computing: recognizing phishing attempts, using multi-factor authentication, and understanding why verification delays on money movement requests are protective rather than bureaucratic. That education component is, in his view, as important as any technical control.
"Bad security is inconvenient too. It's just inconvenient all at once, later. What people actually hate is the dumb friction — the security 'theater' that isn't stopping anybody. Good controls are mostly invisible," Failla said.
Failla also pushes back on the assumption that smaller RIAs present smaller risks to attackers. The automation driving most current attacks does not prioritize targets by AUM or firm size — it scans for open vulnerabilities. A small advisory firm holds the same categories of sensitive data as a much larger one: Social Security numbers, account numbers, beneficiary designations, estate documents. It typically holds them with a fraction of the defensive infrastructure. The attackers, Failla argues, do not see a small target. They see an easy one.
Kevin Thompson, founder and CEO of 9i Capital Group LLC, frames the primary cybersecurity change at his firm in terms of awareness and explicit policy, not technology investment.
His firm policy now requires that no link received by email be clicked unless it was specifically requested. Any communication that arrives purporting to be from a client — whether it requests information, a document, or a transaction — triggers a direct phone call to a known number before any action is taken. Thompson maintains client contact at the outset and throughout each process rather than relying on digital verification alone.
"Whether you are small or large, the risk is the same. Although it may be easier to handle or put in guardrails for a 2-to-3-member team, the risk is ultimately the same. You are dealing with people's money, and whether it is a small or large asset, reputational and E&O risk remain. There is no risk worth the tradeoff of being fractionally quicker," Thompson said.
Thompson's framing — that a minor inconvenience is always preferable to a major E&O claim — reflects the same cost-benefit logic that drove the SEC's Regulation S-P amendments. The rule is premised on the same insight: the reputational and liability costs of a breach significantly outweigh the operational friction of additional verification controls.
Taken together, the three advisors describe a threat landscape that has outpaced the industry's traditional defenses and is continuing to accelerate. The common thread is not a particular technology or product — it is a posture: deliberate verification, explicit client education, and a willingness to slow down money movement requests even at the cost of short-term convenience.
The mega-RIA's Humanity Labs deal aims to free advisors from back-office work, costing $50,000 per year for each of the 700 bots that make up Mariner's AI workforce.
Washington State plans to fine the firm and its founder a combined $80,000.
The complaint points to a $2 billion firm, unlicensed sellers, and suspended distributions.
Board of Governors picks reflect push for balanced large- and small-firm input
Deal adds investment platform implementation expertise as F2 builds out North American reach.
Northern Trust’s Ken Lassner shows advisors how to convert volatility into after-tax portfolio gains
Dan Biagini of American Equity says the steady decline of pensions, longer lifespans and a reset in interest rates are rewriting how advisors build retirement income