As of October 2024, the SEC requires registered investment advisers to make public cybersecurity disclosures in Form ADV Part 2A. This is not a filing sent only to regulators. It is a client-facing document that describes your cybersecurity risks, governance, incident history, and the adequacy of your controls. Your chief compliance officer, general counsel, or chief executive will sign a certification that these statements are accurate.

The regulation assumes someone inside the organization can answer questions such as: What are our material cybersecurity risks? How do we decide what controls are adequate? What incidents have occurred, and how were they managed? For many advisers, no single person owns those answers, and there is no repeatable process for reaching them. Leadership is accountable for a security outcome without a clear owner, a documented sequence, or a way to measure progress.

This creates a governance problem, not a technical one. The question is not whether your systems are secure. The question is whether you can describe your approach, defend your decisions, and demonstrate that someone with authority is overseeing the entire program. That is an executive function, and it is what [virtual CISO leadership](/vciso/) is designed to provide.

What the Amendments Require

The amendments add new disclosure requirements to Item 8 of Form ADV Part 2A, the brochure delivered to clients and prospective clients. Advisers must now describe:

  • Cybersecurity risks that could materially affect the adviser's business or its clients
  • The governance structure for managing those risks, including who is responsible and how decisions are escalated
  • The processes and controls in place to detect, respond to, and recover from cybersecurity incidents
  • Whether the adviser has experienced a significant cybersecurity incident within the past five years, and if so, the nature and impact of that incident
  • Whether the adviser uses third-party service providers for critical functions, and how cybersecurity risk from those providers is managed

These are not checkbox questions. The SEC expects advisers to provide meaningful, client-relevant information. A generic statement that you take cybersecurity seriously does not satisfy the requirement. Nor does delegating the entire answer to your IT provider or compliance consultant.

The disclosure must reflect your actual practices. If you state that a named executive is responsible for cybersecurity risk decisions, that person must have the authority, knowledge, and documentation to support that role. If you describe an incident response process, you must be able to produce the plan, the decision record, and evidence that it has been tested.

Why This Matters to Leadership

The amendments make cybersecurity a disclosure obligation, not just an operational matter. That shifts accountability upward. Your compliance officer may draft the language, but the chief executive, general counsel, or CCO must verify that the statements are accurate and that the governance structure described actually exists.

If an examiner asks how you determined that a particular incident was not material, or how you assessed the adequacy of your third-party vendor controls, the answer must come from a documented decision process owned by someone with authority. It cannot come from an IT vendor's assurance or a consultant's template.

This creates three practical problems for advisers that have not formalized cybersecurity governance:

  • There is no single person with visibility across technology, risk, compliance, and vendor relationships who can answer the questions the disclosure requires
  • Decisions about what controls are adequate, what incidents are reportable, and what risks are material are made informally, without documentation or a consistent standard
  • Leadership cannot verify the accuracy of the disclosure because the governance structure described in the document does not exist in practice

The business consequence is not a fine. It is the erosion of trust with clients, regulators, and insurers when your disclosures cannot be defended, your incident response is improvised, or your governance is revealed to be delegated entirely to vendors.

Who Owns Verification and What Adequate Ownership Looks Like

The regulation does not specify who must own cybersecurity governance, but it assumes someone does. In practice, that means a person who can:

  • Identify and document material cybersecurity risks in business terms, not technical jargon
  • Establish the standard for what controls are adequate, proportionate to the risk, and defensible to an examiner
  • Make or advise on risk decisions, including incident materiality, vendor acceptability, and control priorities
  • Maintain the documentation and evidence needed to support the statements in Form ADV Part 2A
  • Serve as the point of accountability when regulators, auditors, or leadership ask how a decision was reached

For many advisers, this role does not exist. The CCO has compliance expertise but not cybersecurity authority. The IT provider has technical knowledge but not governance responsibility. The general counsel has oversight but not operational involvement. The result is diffused accountability, which the amendments do not accommodate.

Adequate ownership means a person or function that integrates strategy, governance, risk decisions, regulatory position, and reporting. That is the function [Heights provides as a virtual CISO](/vciso/): not outsourced IT management, but executive cybersecurity leadership accountable to the CEO, board, or CCO.

How This Relates to Regulatory and Framework Readiness

The Form ADV amendments are one expression of a broader regulatory expectation: that cybersecurity risk is managed as an enterprise risk, with governance, documentation, and executive accountability. The same expectation appears in state data breach notification laws, SEC Regulation S-P, and the reporting requirements under the federal CIRCIA statute.

Frameworks such as the NIST Cybersecurity Framework provide a common structure for organizing that work. The framework is not a checklist. It is a vocabulary for describing what you do, why you do it, and how you know it is working. When properly implemented, it gives you the evidence and decision record needed to support regulatory disclosures, respond to examiner questions, and demonstrate that governance is real rather than aspirational.

Regulatory readiness means having the governance structure, documentation, and repeatable processes that allow you to produce accurate disclosures without starting from scratch each time. It means knowing, before the examiner asks, how you determined that an incident was not material, or why you accepted a vendor's security posture, or what standard you used to decide that your controls were adequate.

Heights specializes in building that readiness for regulated organizations. We do not implement frameworks as a compliance exercise. We use them to structure decision-making, align security with business risk, and create the governance foundation that makes regulatory disclosure straightforward rather than speculative.

What Leadership Should Do Next

If you are preparing to file or update Form ADV Part 2A, start by answering these questions:

  • Who inside the organization can describe our material cybersecurity risks in business terms, and what evidence supports that assessment?
  • Who decides whether a cybersecurity incident is significant, and what documentation exists to show how that decision was reached?
  • Who is accountable for determining whether our controls are adequate, and what standard or framework are we using?
  • If an examiner asks how we manage cybersecurity risk from third-party vendors, who can answer, and what records can we produce?
  • Can the person or people responsible for these answers defend them to the CEO, the board, or a regulator?

If the answer to any of these questions is unclear, the problem is not your technology. It is your governance structure. The amendments assume you have someone who owns cybersecurity risk decisions at an executive level. If you do not, you are preparing disclosures that you cannot verify.

The immediate next step is to establish or clarify that ownership. For organizations that do not have a full-time chief information security officer, that typically means engaging a virtual CISO who can provide strategy, governance, risk decisions, and regulatory reporting on a retained basis.

Heights works with registered investment advisers to build and maintain the governance structure the SEC now assumes you have. We serve as the executive cybersecurity function accountable to your CCO, general counsel, or board. We document risk decisions, maintain the evidence needed for regulatory filings, and ensure that your disclosures reflect your actual practices rather than aspirational statements.

If you are uncertain whether your current governance structure can support the Form ADV disclosures you are preparing, or if you need an executive-level owner for cybersecurity risk decisions, we offer a confidential consultation to assess your readiness and outline what adequate governance looks like in practice. This is not a sales process. It is a structured conversation about accountability, evidence, and regulatory position. Contact Heights to schedule that discussion.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Regulatory and Framework Readiness

Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.

Read about Regulatory and Framework Readiness