The GLBA Safeguards Rule (16 CFR Part 314) requires most state-registered RIAs to run a written information security program, and even the small-firm exception for under 5,000 clients only waives four of ten required elements, not the rule itself.
Two different federal regulators enforce cybersecurity rules on investment advisors. Which one has authority over a given firm comes down to a single number: assets under management. Get that number wrong, and the whole compliance program gets built against the wrong law.
Which Rule Actually Applies to Your Firm
SEC-registered advisors, generally firms managing $100 million or more, answer to SEC Regulation S-P. Everyone below that line answers to a different regulator. State-registered advisors and exempt reporting advisors, which make up most small RIA practices, fall under the FTC instead. The FTC’s own rule text names the category directly. “Investment advisors that are not required to register with the Securities and Exchange Commission” sit on the same list as mortgage brokers, check cashers, and tax preparers. Same rule. Stranger neighbors than you’d expect.
That distinction isn’t academic. Reg S-P and the FTC Safeguards Rule share a common ancestor in the Gramm-Leach-Bliley Act, but they diverge in the details, the enforcement posture, and the paperwork a firm has to keep on file. A firm that builds its security program around whatever SEC guidance shows up first in a search is building around the wrong document. It happens more than you’d think, usually because “GLBA” gets treated as one rule instead of two parallel ones split by regulator.

What Actually Counts as a “Financial Institution” Here
16 CFR 314.1 defines a financial institution broadly as any business engaged in an activity that’s financial in nature under the Bank Holding Company Act. The rule’s definitions section spells out the examples by name: an investment advisory company is a financial institution because providing financial and investment advisory services is itself a listed financial activity.
No ambiguity there. No carve-out for firm size built into the definition, either. Firm size shows up later, in the exceptions. Not here.
The Small-Firm Exception, and What It Doesn’t Cover
A real exception exists for firms holding customer information on fewer than 5,000 consumers, and most solo and small-team RIAs clear that bar without trying. But the exception only waives four specific requirements out of ten, and getting precise about which four matters more than most compliance summaries bother to explain.
| Requirement | Under 5,000 Consumers | 5,000+ Consumers |
|---|---|---|
| Written risk assessment | Waived | Required |
| Continuous monitoring or annual penetration testing | Waived | Required |
| Written incident response plan | Waived | Required |
| Annual board or senior-officer report | Waived | Required |
| Access controls, encryption, MFA | Required | Required |
| Qualified Individual designation | Required | Required |
| FTC breach notification | Required | Required |
Everything in that bottom half of the table applies at any size. A two-advisor shop with 40 clients owes the FTC the same access controls, the same encryption, and the same multi-factor authentication as a firm with 4,000. The exception trims paperwork. It doesn’t touch the technical core.

The Parts of the Rule a Small Practice Actually Has to Build
Start with the Qualified Individual. Someone has to own the information security program by name, and that person doesn’t have to be a full-time employee. A service provider or an affiliate can hold the role, provided the firm keeps ultimate responsibility and assigns a senior staffer to oversee that outside person. A full-time security hire isn’t the only path here. Outsourcing the role to an IT provider is explicitly allowed under the rule, and it’s usually the more realistic option for a firm with a handful of advisors.
Multi-factor authentication is not optional and not vague. The rule defines it as two of three factor types: something you know, something you have, something you are. A password by itself never counts, no matter how strong.
Encryption covers customer information both in transit and at rest. If encrypting something turns out to be genuinely infeasible, the rule allows a documented, Qualified-Individual-approved alternative instead. That’s an exception with a paper trail attached, not a free pass.
Data disposal gets a specific number most firms never hear until an examiner brings it up: two years. Dispose of customer information within two years of the last time it’s used for that client’s product or service. That’s the default. A legitimate business or legal reason can justify keeping it longer, but the default itself surprises most firms. A filing cabinet full of decade-old client statements isn’t a compliance program. It’s a liability with a lock on it.
Vendor oversight rounds out the technical core. Whoever handles your CRM, your portfolio management platform, your document storage, has to be vetted for adequate safeguards, bound to those safeguards by contract, and periodically reassessed. A vendor’s own SOC 2 report is a reasonable starting point. It isn’t the whole job.
The Notification Deadline Almost Nobody Budgets For
A newer piece of the rule, effective since May 13, 2024, requires notifying the FTC directly when a “notification event” affects 500 or more consumers. The clock starts the day anyone at the firm, other than the person responsible for the breach, becomes aware of it. Thirty days. Not thirty business days.
The trigger is unauthorized acquisition of unencrypted customer information. Properly encrypted data that gets accessed but never decrypted generally doesn’t trigger the clock, which is one more reason the encryption requirement above isn’t a box to check and forget.

Where a Small RIA Actually Starts
- Confirm whether your firm is SEC-registered or state-registered. That single fact determines which rule you’re actually reading.
- Count your customers. If you’re under 5,000, know exactly which four requirements you’re exempt from, and don’t assume the rest follow.
- Check MFA coverage account by account, not department by department. Every system touching customer information needs it.
- Name a Qualified Individual in writing, even if that person works for your IT provider rather than your firm.
- Pull your document retention policy and check it against the two-year disposal standard.
Questions Advisors Actually Ask About This
Our firm is SEC-registered. Does any of this still matter to us?
What actually counts as customer information under this rule?
Do we need to hire a full-time cybersecurity person?
What happens if we miss the 30-day notification window after a breach?
Our compliance consultant already handles our ADV filings. Isn’t that the same thing?
Getting this right is less about any single control and more about being able to show your work. VJNetworks has helped small businesses across the Tri-State area build and document security programs like this one for over 20 years, through cybersecurity work built around VJNetworks’ managed IT services, not generic advice written for a $2 billion wirehouse. RIAs share more compliance ground with other regulated small businesses than most owners assume. VJNetworks covered a similar small-firm exemption structure in the NY SHIELD Act, and the documentation habits that satisfy an examiner tend to overlap across both.
Further reading: the FTC’s Safeguards Rule guidance covers the full requirements directly from the source.
A free assessment walks through the ten Safeguards Rule elements against your actual setup, not a generic template built for a bank. No obligation, no sales pitch.
