Why Financial Services Firms Are High-Value Targets

Accountants and financial advisors hold tax returns, bank account numbers, investment portfolios, Social Security numbers, and business financial statements. A breach exposes your clients to identity theft and financial fraud — and exposes you to regulatory action and malpractice claims.

Regulatory Obligations After a Data Breach

  • Gramm-Leach-Bliley Act (GLBA): Financial institutions (including RIAs) must implement a written information security program and notify regulators of breaches.
  • SEC Regulation S-P: Registered investment advisers must report significant breaches to the SEC within 30 days.
  • State Data Protection Laws: 49 states have breach notification laws with varying timelines and requirements.
  • IRS Publication 4557: Tax preparers must implement data security plans under the FTC Safeguards Rule.