• People

    Advanced Search

  • Services
  • All Services

  • Back to News & Media
    Blog

    RIAs Are in Cybercriminals’ Crosshairs – Prepare to Protect Your Data

     Download as PDF

    Cybercrimes continue to target vulnerable companies globally, and advisers are now in the crosshairs. Recent interviews with cybersecurity professionals, and our team’s experience working with hundreds of advisers on cybersecurity-related subjects, have uncovered rampant attempted cyberattacks on RIAs and their vendors.

    Advisers often maintain sensitive client data as part of their day-to-day operations – high-value financial data like account numbers, non-public personal information like Social Security Numbers and birthdates, and direct access to client assets. As a result, RIAs are in cybercriminals’ crosshairs as they deploy social engineering attacks such as credential compromise (e.g., passwords), multifactor authentication fatigue, and third-party vendor attacks, in an attempt to obtain that data.

    Further, the SEC consistently lists cybersecurity as a top examination priority year after year.

    How Can RIAs Protect Themselves?

    The new wave of social engineering attacks against RIAs can leave firms wondering what they can do to safeguard client information.

    1. Maintain a Cybersecurity Manual. RIAs should maintain written policies as part of a standalone Cybersecurity Manual – separate from the standard written Policies and Procedures Manual – outlining their cybersecurity practices and procedures, including a list of cybersecurity vendors and consultants, and how sensitive information is protected. Your compliance team at Stark & Stark can assist with drafting a customized written Cybersecurity Manual.
    2. Maintain an Incident Response Program. The Regulation S-P Incident Response Program requirement became effective for large advisers ($1.5 billion or more in AUM) in December 2025, and becomes effective on June 3, 2026 for small advisers (under $1.5 billion in AUM). The written Incident Response Program must outline what types of events constitute cybersecurity incidents, how the incident response team should respond, relevant stakeholders, and client and regulator notification when applicable. Your compliance team at Stark & Stark can assist with the preparation of an Incident Response Program before June 3, 2026.
    3. Perform Annual and Ongoing Employee Training. RIAs should train employees on the importance of identifying red flags of social engineering attacks such as suspicious links, questionable information requests, and unusual requests to withdraw assets.
    4. Annually Review Third-Party Vendors. RIAs should conduct due diligence on all third-party vendors’ cybersecurity practices, including requesting SOC 2 reports and assessing vendors’ incident response capabilities.
    5. Maintain Proper Cybersecurity Hygiene. In addition to regular employee training, RIAs should implement measures that require employees to change passwords on a regular basis, maintain a multifactor authentication regime, closely scrutinize all electronic communications from external sources, and ensure sensitive information shared electronically is sent using a secure communication method.
    6. Engage a Third-Party Cybersecurity Consultant. RIAs don’t have to rely solely on internal cybersecurity regimes. Engaging a third-party cybersecurity consultant can help alleviate the burden of ongoing cybersecurity maintenance but does not eliminate the adviser’s obligations altogether.
    7. Review Your Insurance Coverage. RIAs should, at the very least, maintain robust errors & omissions insurance coverage. However, many forget to check whether such coverage also covers cybersecurity incidents. RIAs should review their coverage with an insurance professional to determine whether their existing policy covers cybersecurity incidents or whether a separate, standalone cybersecurity insurance policy should be purchased.

    The convergence of heightened threats from cybercriminals, the upcoming June 3, 2026 Incident Response Program deadline, and increased SEC scrutiny of cyber-related issues make cybersecurity an urgent priority for RIAs in 2026 and beyond.

    Your compliance team at Stark & Stark remains available to assist with the preparation of a written Incident Response Program and a written Cybersecurity Manual. Existing clients can contact their attorney and paralegal team for assistance.

    Key Contacts

    Jeffrey A. Lang
    609.219.7452

    Firm Highlights

    Stark & Stark Joins Growing Coalition of Law Firms in Defense of Constitutional Principles and the Independence of the Legal Profession

    Stark & Stark has joined hundreds of fellow law firms across the country in filing an amicus brief supporting Perkins Coie, WilmerHale, Jenner...

    Stark & Stark Attorneys Recognized as New Jersey “Super Lawyers” and “Rising Stars” in 2026

    Stark & Stark is pleased to announce that 15 of its attorneys have been selected for inclusion in the list of 2026 New Jersey Super Lawyers,...

    Bruce Stern, Esq. Secures $1,000,000 Settlement in Motor Vehicle Collision Case

    Bruce Stern, Esq. recently secured a $1,000,000 settlement in a motor vehicle collision case.* “This case highlights how quickly things can go...

    Deborah Dunn, Esq. Elected to Board of Directors for Angel Flight East

    Stark & Stark is pleased to announce that Deborah Dunn, Esq., Shareholder and Civil Trial Attorney, has been elected to the Board of Directors...

    Michael Jordan, Esq. Joins the Board of the Lawrence Township Community Foundation

    It is our pleasure to announce that Michael Jordan, Esq. has joined the board of the Lawrence Township Community Foundation, an organization...

    Stark & Stark Opens Newtown, Pennsylvania Location

    Stark & Stark announced the relocation of its Yardley, Pennsylvania office to a new location in Newtown, PA. The new office is now open and...

    Joseph Lemkin, Esq. Named to ROI-NJ Influencers: Power List 2026 – Law

    Stark & Stark is proud to share that Joseph Lemkin, Esq., Shareholder, has been named to the 2026 Influencers: Power List in the Law category...

    Jeffrey A. Krawitz, Esq. and Michael C. Ksiazek, Esq. Secure $1,000,000 Settlement in Medical Malpractice Wrongful Death Case

    Jeffrey A. Krawitz, Esq. and Michael C. Ksiazek, Esq. recently secured a $1,000,000 settlement in a medical malpractice wrongful death...

    Joseph Cullen, Esq. and Nicole Durso, Esq. Secure $2,000,000 Settlement in Personal Injury Matter

    Joseph Cullen, Esq. and Nicole Durso, Esq. recently secured a $2,000,000 settlement in a personal injury matter involving a pedestrian who was struck...

    Stark & Stark Welcomes Susan L. Swatski, Esq. to the Firm

    Continuing in its mission to provide its clients innovative legal solutions to meet their needs, Stark & Stark PC, announced today that Susan L....

    Tim Duggan Wins Eminent Domain Challenge – Case Dismissed

    We are pleased to share that Tim Duggan of our Condemnation, Redevelopment, and Eminent Domain Group was successful in protecting the owner of a...

    James Creegan, Esq. Appointed to Board of The 200 Club of Mercer County

    It is our pleasure to announce that James Creegan, Esq. has been appointed to the Board of Directors of The 200 Club of Mercer County, an...