Case Study
Strengthening Regulatory Compliance: A Case Study of a Wealth Management Firm
The Firm's Profile
This boutique wealth management firm serves high-net-worth individuals, families, and business owners, with a strong emphasis on building lasting relationships and delivering a highly personal client experience. With roughly 15 employees, including seven wealth advisors and financial planning professionals, the firm's small, high-touch team knows its clients personally and is genuinely invested in their goals and long-term financial well-being. Compliance oversight falls to the firm's Chief Operating Officer.
Introduction
Registered investment advisers hold some of their clients' most sensitive financial information, making cybersecurity and data protection a core regulatory expectation rather than an optional safeguard. Amended Regulation S-P expands what the SEC expects of RIAs, adding new obligations around risk assessment, incident response, and customer notification following an incident involving sensitive customer information. This case study examines how a boutique wealth management firm partnered with Fixed Fee IT to evaluate its technology environment, strengthen its security posture, and build the documented, tested controls its Chief Operating Officer needed to meet those obligations with confidence.
Initial Challenges
- Reactive, Generalist IT Support: The firm's longtime IT provider, a small three-person shop, handled day-to-day support well but was primarily reactive and did not specialize in wealth management, cybersecurity, or regulatory compliance.
- Limited In-House Cyber Expertise: Compliance was overseen by the Chief Operating Officer, whose background was in wealth advising rather than technology, creating uncertainty about whether the firm's safeguards were sufficient, documented, and aligned with regulatory expectations.
- An Approaching Regulatory Bar: As the firm prepared for amended Regulation S-P, the COO needed a clear picture of the firm's technology safeguards, cyber risk, incident-response procedures, and vendor oversight, and the firm did not yet have that visibility.
- Outgrowing the Current Relationship: Despite valuing its long-standing IT relationship, the firm recognized that good day-to-day support was no longer enough. It needed a more proactive partner with real experience supporting RIAs and providing cybersecurity and compliance guidance.
The Turning Point. Recognizing that day-to-day IT support could no longer keep pace with its regulatory obligations, the firm's COO began looking for a technology partner with genuine experience serving RIAs, one who could speak fluently to both cybersecurity and compliance. That search led the firm to Fixed Fee IT.
Comprehensive Evaluation
Fixed Fee IT conducted a comprehensive evaluation of the firm's technology environment and security controls, with a specific focus on the firm's readiness for amended Regulation S-P. The assessment reviewed administrative and technical safeguards, risk-management practices, access controls, incident-response capabilities, vendor oversight, and disaster-recovery preparedness, giving the COO, for the first time, full visibility into the firm's actual security posture.
Assessment Findings
Foundational Protections Already in Place
- Multifactor authentication
- Antivirus protection
- Regular system patching
- Basic data backup and recovery systems
Areas of Risk Identified
- Overly Broad File Access: Employees had broader access to company files than their roles required.
- Widespread Administrative Access: Admin rights were not consistently limited to IT accounts.
- Limited Security Monitoring: The firm lacked sufficient detection capability to quickly identify suspicious activity.
- Untested Disaster Recovery: Recovery systems had not been adequately tested, and recovery objectives were not aligned with the firm's actual capabilities.
Based on these findings, the firm could not yet demonstrate that it had the visibility, documented controls, and response capabilities needed to meet amended Regulation S-P's requirements for risk evaluation, detection, response, recovery, and customer notification.
Development of a Tailored Compliance & Security Program
1. Selecting a Technology Partner
As part of its vendor due-diligence process, the firm reviewed Fixed Fee IT's security practices, SOC 2 Type 2 report, and Data Protection Addendum. The independently audited controls and clear written commitments around safeguards, access controls, sub-processors, and incident cooperation gave the COO confidence that Fixed Fee IT could meet the firm's security and reliability expectations, and support its own service-provider oversight obligations under amended Regulation S-P. The firm engaged Fixed Fee IT as its technology and cybersecurity partner, and the two worked together to build a prioritized improvement plan focused on reducing immediate risk, strengthening governance, improving visibility, and building more complete detection, response, and recovery capabilities.
2. Strengthening Governance and Policies
- Updated the firm's information security policies to reflect its current technology environment, regulatory expectations, and the safeguards already in place.
- Strengthened the firm's cyber risk assessment, helping the COO identify technology risks, evaluate existing controls, and prioritize remediation.
3. Reducing Access Risk
- Reviewed and reduced file access so permissions matched each employee's actual responsibilities.
- Restricted and better controlled administrative access, reducing the number of accounts with elevated privileges.
Visibility and Monitoring
Fixed Fee IT implemented BSecured Vulnerability Reporting and BSecured Inventory Reporting to give the firm ongoing visibility into:
- Devices and systems connected to the firm's network
- Installed software and technology assets
- Known vulnerabilities
- Unsupported or outdated systems
- Emerging risks requiring review or remediation
Detection and Response
To improve the firm's ability to detect and respond to cyber threats, Fixed Fee IT implemented:
- BSecured Endpoint Detection and Response: Monitors computers and responds to suspicious activity.
- BSecured Managed Detection and Response for Microsoft 365: Identifies identity, email, and account-based threats.
- BSecured Managed SIEM: Centralizes security activity, improves visibility across the environment, and provides managed review and escalation of potential incidents.
Disaster Recovery and Business Continuity
Fixed Fee IT implemented BSecured Managed Disaster Recovery for more reliable protection and recovery of the firm's critical systems and information.
- Updated Business Continuity Plan: Revised to reflect the firm's current technology environment, critical systems, recovery dependencies, and business priorities.
- Realigned Recovery Objectives: Recovery time and recovery point objectives were reviewed against the firm's operational needs and its actual disaster-recovery capabilities.
- Incorporated New Systems: Systems added or replaced since the previous plan were folded into the updated recovery strategy.
Incident Response Readiness
Fixed Fee IT facilitated realistic tabletop exercises to test the firm's Incident Response and Business Continuity Plans.
These exercises gave leadership and employees the chance to practice their roles, identify gaps, improve coordination, and build confidence well before a real incident occurred.
Outcomes and Benefits
Stronger Regulatory Alignment
- Documented Controls: The firm can now demonstrate the visibility, documented controls, and tested response capabilities that amended Regulation S-P expects for risk evaluation, detection, response, recovery, and customer notification.
- Independent Validation: An independent mock audit of the firm's improved controls and documentation identified no material technology-related findings.
Reduced Risk Exposure
- Tighter Access Controls: File and administrative access now align with each employee's actual role, reducing the risk of misuse or compromise.
- Real-Time Visibility: Ongoing vulnerability and inventory reporting give the firm continuous insight into its technology environment and emerging risks.
Tested Resilience
- Validated Recovery Capabilities: Disaster-recovery systems and the Business Continuity Plan now reflect the firm's actual environment and have been put through realistic tabletop testing.
- Confident Leadership: Tabletop exercises gave leadership and staff hands-on practice and confidence in their incident-response roles.
A Proactive Technology Partnership
- Specialized Expertise: The firm gained a technology partner with genuine experience supporting RIAs, cybersecurity, and regulatory compliance, not just generalized IT support.
- Confidence in Oversight: Fixed Fee IT's SOC 2 Type 2 report and Data Protection Addendum continue to support the firm's ongoing vendor-oversight obligations under amended Regulation S-P.
Conclusion
The partnership between this boutique wealth management firm and Fixed Fee IT shows how RIAs can move from reactive IT support to a documented, tested security and compliance program. By addressing access controls, monitoring, disaster recovery, and incident response together, and validating the results with independent assessments, the firm built the visibility and confidence its COO needed to meet its obligations under amended Regulation S-P, while strengthening its resilience for the long term.
Key Takeaways
- Compliance Requires Documentation, Not Just Good Intentions: Strong day-to-day practices aren't enough on their own; regulators expect documented, tested controls.
- Vendor Due Diligence Works Both Ways: A SOC 2 Type 2 report and a clear Data Protection Addendum can give a firm the confidence it needs to meet its own oversight obligations.
- Access Control Is Foundational: Reviewing and tightening file and administrative access closes one of the most common paths to compromise.
- Testing Builds Confidence: Tabletop exercises and independent mock audits turn a plan on paper into a capability leadership can trust.
- Specialized Expertise Matters: An IT partner who understands RIAs, cybersecurity, and compliance brings a different level of value than generalized support.
By pairing a documented security program with tested recovery and incident-response capabilities, wealth management firms and RIAs can meet amended Regulation S-P requirements with confidence, while building the kind of resilience that protects clients, advisors, and the firm's reputation alike.
Ready to Join Our Happy Clients?
Find out what Protected, Productive and Happy really means for your business.
Let's Talk →