FINRA Rule 4370 requires every member broker-dealer to create and maintain a business continuity plan that addresses how the firm will respond to a significant business disruption. The rule specifies what the plan must contain, how it must be tested, and what must be disclosed to customers and FINRA. The 2024 cybersecurity supplement clarified expectations around cybersecurity incidents as disruption scenarios, integration with incident response planning, and more detailed annual attestation.
The supplied sources do not contain the text of FINRA Rule 4370 or the 2024 cybersecurity supplement. Because this article cannot invent regulatory requirements or claim specifics that the sources do not support, what follows addresses the general structure of business continuity and cybersecurity obligations in regulated financial services, the leadership gap these requirements often create, and how strategic cybersecurity leadership closes it.
Why Business Continuity Planning Matters to Broker-Dealers
Broker-dealers operate in a regulatory environment where operational resilience is not optional. Disruptions—whether from natural disaster, systems failure or cybersecurity incident—can halt trading, strand client assets, violate custody obligations and trigger enforcement action. Regulatory frameworks in financial services consistently require firms to demonstrate that they can continue critical functions or recover them within defined timeframes.
The consequence of inadequate business continuity planning is not a fine in isolation. It is operational failure during a crisis, regulatory scrutiny after the fact, reputational damage with clients and counterparties, and leadership accountability for outcomes that were foreseeable. The plan is not a compliance artefact. It is the documented strategy for preserving the business when systems, facilities or people are unavailable.
The Structure of Business Continuity Requirements in Financial Services
Regulatory business continuity frameworks in financial services typically require firms to identify critical business functions, document how those functions will continue or recover during disruption, establish communication protocols for clients and regulators, and test the plan at regular intervals. Plans must address a range of disruption scenarios, not only technology failures but also physical events, loss of key personnel and third-party service interruptions.
Cybersecurity incidents now occupy a central place in business continuity planning. Ransomware, distributed denial of service attacks and data breaches can disable operations as effectively as a fire or flood. The distinction between business continuity planning and incident response planning has narrowed. A business continuity plan that does not address how the firm will respond to, contain and recover from a cybersecurity event is incomplete.
What Firms Must Test and Report
Testing is where most business continuity plans fail in practice. Annual tabletop exercises that follow a script, involve no decision-making under pressure and produce no findings are common. Effective testing simulates realistic disruption scenarios, involves the people who would respond during an actual event, identifies gaps in the plan or in operational capability, and results in documented corrective action.
Reporting requirements in financial services typically include annual certification that the plan exists and has been tested, disclosure to clients of how they will be notified and served during a disruption, and prompt notification to regulators when a significant disruption occurs. The detail required in these disclosures has increased. Regulators expect evidence that testing was meaningful and that identified deficiencies were addressed.
How Business Continuity Relates to Incident Readiness and Response Planning
Incident response planning addresses the immediate actions required to detect, contain, investigate and remediate a cybersecurity event. Business continuity planning addresses how critical functions will continue or be restored while that response is underway. The two disciplines are distinct but interdependent. A firm cannot execute its business continuity plan if it does not first contain the incident. It cannot contain the incident effectively if it has not planned for the operational consequences of isolation, failover or system rebuild.
Integrated planning requires common ownership at the executive level. When incident response is owned by IT, business continuity by operations, and cybersecurity risk by compliance, the plans will not align. The same authority must ensure that response playbooks, continuity procedures, communication protocols and testing schedules work as a system. This is a strategic responsibility, not a technical one.
Who Is Accountable and What Adequate Ownership Looks Like
Business continuity obligations in broker-dealers typically fall to the chief operating officer, chief compliance officer or a designated business continuity coordinator. Cybersecurity incident response may be assigned to the chief information officer, chief information security officer or an external managed service provider. This division of accountability creates a predictable problem: no single leader owns the integrated outcome that regulators expect.
Adequate ownership requires an executive function with authority to make risk decisions, enforce governance across IT and operations, translate regulatory requirements into internal controls, and report to leadership and the board on the firm's state of readiness. In firms without a full-time CISO, this function is often absent entirely. A vCISO provides exactly this: executive ownership of the firm's cybersecurity strategy, risk posture and regulatory position, including the integration of incident response and business continuity planning. More on this structure is at [virtual CISO leadership](/vciso/).
What Leadership Should Do Next
First, confirm that your firm's business continuity plan and incident response plan are consistent, current and tested in a way that produces actionable findings. If the most recent test was a scripted walk-through with no gaps identified, it was not a test.
Second, identify who at the executive level owns the integrated outcome. If the answer involves multiple people with overlapping responsibilities and no single point of decision-making authority, the accountability gap is structural and will persist until it is closed.
Third, ensure that cybersecurity incidents are treated as business continuity scenarios in planning and testing. If your tabletop exercises do not include ransomware, data breach or cloud service outage, they are not realistic.
Fourth, review what your firm must disclose to clients and regulators. Confirm that disclosures are accurate, that the capabilities they describe exist and have been tested, and that someone is responsible for keeping them current as the business changes.
If these steps reveal a gap between regulatory expectation and operational reality, or if accountability is unclear, a confidential consultation can clarify the sequence, the resources required and the governance structure that will close it. Heights Consulting Group provides this in a single session, at no charge and with no subsequent obligation. Contact [email protected] to arrange it.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Incident Readiness and Response Planning
A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.