In May 2023, the Securities and Exchange Commission substantially amended Regulation S-P, the rule governing how broker-dealers and other financial institutions safeguard customer information. The amendments create explicit incident notification obligations and expand the technical and governance requirements around information security programs. For broker-dealer leadership, the practical question is not whether these rules apply, but who inside the organization has the authority, capability and accountability to ensure compliance.
The amendments do not merely update technical standards. They create executive accountability for security outcomes that many firms have historically treated as operational or IT matters. This article explains what changed, what must now be reported, and how to structure ownership so compliance is measurable rather than assumed.
What Changed in Regulation S-P
Before May 2023, Regulation S-P required broker-dealers to establish safeguards to protect customer information and to provide annual privacy notices. The amendments add two significant requirements: mandatory incident notification to the SEC and affected individuals, and more detailed specifications for what a compliant information security program must include.
The notification requirement applies when a data breach affects the personal information of 500 or more individuals. Firms must notify the SEC within 30 days of determining that a breach has occurred, and must notify affected individuals without unreasonable delay. The amendments define what constitutes 'unauthorized access' and establish that notification obligations are not contingent on whether the firm believes harm has occurred. The determination is objective: if the threshold is met, notification is required.
The safeguard requirements now specify that firms must implement written policies and procedures that include risk assessment, vendor management, access controls, data inventory, incident response planning, and regular testing. The regulation does not prescribe particular technologies or frameworks, but it does require that the program be appropriate to the size and complexity of the firm, the nature and scope of its activities, and the sensitivity of customer information.
How Regulation S-P Intersects with Regulation SCI
Regulation SCI (Systems Compliance and Integrity) applies to certain market infrastructure entities, including some broker-dealers that operate alternative trading systems or perform clearing or settlement functions. Regulation SCI establishes requirements for the integrity, resiliency, and security of critical systems. It includes its own incident notification obligations when SCI events occur—defined as systems disruptions, compliance issues, or intrusions that could affect the operation of critical systems.
The two regulations address different concerns but can create overlapping obligations. Regulation S-P focuses on the confidentiality of customer information. Regulation SCI focuses on the availability and integrity of systems critical to market operations. A single incident—such as a ransomware attack—might trigger notification requirements under both regimes if it compromises customer data and disrupts a critical system. Firms subject to both regulations must determine which obligations apply to each incident and ensure that notification and remediation procedures account for both.
Neither regulation is satisfied by outsourcing alone. Even when technology operations are managed by a service provider, the broker-dealer remains responsible for compliance, for vendor oversight, and for making the determination that an incident meets notification thresholds.
Who Is Accountable and What Adequate Ownership Looks Like
Regulation S-P does not specify who within a firm must own the information security program, but it requires that the program be overseen by qualified personnel and that it be reviewed and approved at an appropriate level. In practice, this means that responsibility cannot rest solely with IT staff or outside vendors. The program must have an executive owner who can make risk decisions, allocate resources, interpret regulatory intent, and report to the board or senior management.
In many broker-dealers, especially smaller firms, there is no full-time security executive. Compliance officers understand regulatory structure but may lack the technical background to evaluate controls or supervise incident response. IT managers understand systems but may not be positioned to make enterprise risk decisions or communicate with regulators. The gap is not capability in either role; it is the absence of a senior security leader who can translate business strategy into security requirements, assess risk in business terms, and own the outcome.
Adequate ownership requires three things: authority to make security and risk decisions without escalating every question, accountability for the program's performance and compliance, and competence in both security and regulatory interpretation. This role is often described as a Chief Information Security Officer (CISO). For firms where a full-time CISO is not economically justified, [virtual CISO leadership](/vciso/) provides the same executive function on a part-time or retained basis. The vCISO owns the security program, reports to the executive team or board, interprets regulatory obligations, and ensures that policies, controls and incident response procedures are in place and tested.
Incident Readiness and Response Planning
The notification requirements under Regulation S-P depend on the firm's ability to detect an incident, assess its scope, determine whether notification thresholds are met, and execute notification within defined timeframes. This is not possible without advance planning. Incident readiness means having documented procedures, defined roles, communication templates, legal and regulatory contact points, and a tested process for making threshold determinations under pressure.
An effective incident response plan addresses detection and containment, but it must also address the decision-making sequence: who assesses the incident, who determines whether notification is required, who drafts the notification, who approves it, and who submits it to the SEC and communicates with affected individuals. These decisions involve legal, compliance, technical and business judgments, and they must be made quickly. Without a clear owner and a rehearsed process, the 30-day notification window becomes a source of legal and operational risk rather than a manageable compliance task.
Testing is not optional. The amendments require regular testing of the information security program, and incident response procedures are part of that program. Tabletop exercises that walk through a breach scenario, assign roles, and identify gaps are a low-cost, high-value form of testing. They reveal whether the firm can actually perform the tasks the plan describes, whether communication paths work, and whether decision-makers understand their authority and obligations.
Practical Next Steps for Broker-Dealer Leadership
First, confirm that your firm has a written information security program that addresses the elements now required by Regulation S-P: risk assessment, access controls, data inventory, vendor oversight, incident response, and testing. If the program exists only as a vendor's generic policy or a compliance document that no one implements, it does not satisfy the regulation.
Second, identify who owns the program. This must be a named individual with the authority to make decisions and the accountability for outcomes. If no such person exists, the firm is operating with a governance gap that the amendments were designed to close. Consider whether the firm needs to appoint an internal CISO, engage a vCISO, or restructure reporting lines so that security decisions are made at an appropriate level.
Third, review your incident response plan to ensure it addresses notification obligations under both Regulation S-P and, if applicable, Regulation SCI. Confirm that the plan defines roles, thresholds, communication paths, and decision authority. Test the plan with a tabletop exercise that includes legal, compliance, IT and executive participants.
Fourth, if your firm relies on third-party service providers for technology or data hosting, ensure that contracts, SLAs and oversight procedures account for your notification obligations. You must be able to detect and assess an incident even when it occurs in a vendor's environment. This requires visibility, contractual rights, and a defined escalation path.
Finally, if you are uncertain whether your current program and governance structure meet the amended requirements, or if you lack the internal expertise to make that determination confidently, consider a confidential consultation with a qualified advisor. Heights Consulting Group provides virtual CISO services to broker-dealers and other regulated firms, offering the executive ownership and regulatory interpretation necessary to close the gap between compliance on paper and compliance in practice. A brief conversation can clarify what you have, what you need, and how to structure ownership so that accountability is clear and measurable. Contact Heights to schedule a consultation.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Incident Readiness and Response Planning
A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.