A: RIAs must follow SEC guidelines that mandate written security policies, vendor oversight, and customer data protection. Starting June 3, 2026, smaller investment advisers (managing under $1.5B AUM) must adhere to new amendments under Regulation S-P, which include formal incident response planning and security incident disclosure to customers.
