Table of Contents

New York’s Cybersecurity Rules for Financial Firms: What Small RIAs and Funds Must Have in Place

Picture of CyberDuo
CyberDuo

If you run a small investment adviser or fund in New York, you are living inside three overlapping cybersecurity rulebooks at once, and most firms your size only know about one of them. That gap is where enforcement actions come from. Here is the plain-English map: which rules actually apply to you, what they require in practice, and the control set that satisfies all of them at once.

One caveat up front: this is a practical technology guide, not legal advice. Your compliance counsel decides which rules bind you. Our job, and this post’s, is making sure the controls those rules demand are genuinely in place.

Rulebook one: NYDFS Part 500 (and why it may or may not be yours)

New York’s Department of Financial Services cybersecurity regulation, Part 500, is the most famous state cyber rule in the country and the one everyone assumes applies to them. It binds DFS-licensed “covered entities”: banks, insurers, mortgage lenders and servicers, money transmitters, and virtual currency businesses, among others. It does not automatically cover an SEC-registered investment adviser or a private fund, which are federally supervised.

That said, plenty of firms in the fund ecosystem are DFS-licensed or affiliated with entities that are, so check. If Part 500 applies, the amended rule that finished phasing in on November 1, 2025 is demanding: multifactor authentication for essentially everyone accessing your systems, a maintained asset inventory, a written cybersecurity program and policies, annual risk assessments, penetration testing and vulnerability scans, encryption, access privilege reviews, an incident response plan, cybersecurity training, notification to DFS within 72 hours of a qualifying cybersecurity event and within 24 hours of any extortion payment, and an annual compliance certification signed by senior leadership. Limited exemptions exist for very small firms, but they narrow, not eliminate, the obligations.

Rulebook two: the SEC (this one is yours)

For SEC-registered advisers and funds, the operative rules are federal. The amended Regulation S-P now requires a written incident response program with policies for detecting, responding to, and recovering from unauthorized access to customer information, plus notification to affected individuals as soon as practicable and no later than 30 days after becoming aware of a breach. Smaller entities had to comply by June 3, 2026, which means if you are reading this in late 2026 without a written incident response program, you are already behind. Layer on Regulation S-ID’s identity theft program requirements, the SEC’s ongoing exam focus on cybersecurity, and the safeguarding obligations under the Advisers Act, and the federal expectations are every bit as concrete as New York’s.

Rulebook three: the SHIELD Act (everyone’s)

New York’s SHIELD Act applies to any business holding the private information of New York residents, which is every firm with New York clients. It requires “reasonable” administrative, technical, and physical safeguards and sets breach notification duties. It has no licensing trigger, so it catches firms that Part 500 misses, and the Attorney General enforces it.

The control set that satisfies all three

Here is the useful part. Strip away the jurisdictional differences and the three rulebooks converge on the same practical controls. Build these and you are substantially covered regardless of which regulator is asking.

Identity and access. MFA on everything, including email, remote access, and admin accounts, enforced through Conditional Access rather than user goodwill. Least-privilege access with periodic reviews. We covered the licensing behind this in our Entra ID P1 vs P2 guide.

A written program and a real risk assessment. Documented policies, an annual risk assessment, and a named person accountable. Regulators read documents first and systems second.

Incident response you have rehearsed. A written plan that names who does what, how you detect and contain, and how you meet the 72-hour DFS clock, the 30-day SEC client-notice clock, or the SHIELD notice duties. Tabletop it once a year.

Monitoring and logging. You cannot notify within 72 hours of an event you never detected. Continuous monitoring with retained logs is the difference between a compliant response and a regulator learning about your breach from a client.

Encryption, backups, and vendor oversight. Encrypt data at rest and in transit, keep tested and isolated backups, and document how you vet the third parties that touch client data.

Training. Annual cybersecurity training is explicitly required by Part 500 and expected by everyone else, and it is also your best defense against the wire-fraud schemes that target firms moving client money, which we detailed in our business email compromise guide.

Where a technology partner fits

Your counsel interprets the rules. We implement and evidence the controls: the MFA and access architecture, the monitoring through our in-house 24/7 SOC, the encryption and backup posture, the logging that makes 72-hour notification possible, and the documentation trail your annual certification and your next SEC exam will lean on. That is the work behind our cybersecurity services and our practice serving financial services firms.

We opened in New York City precisely for firms like this, with the same security-first model we run for Los Angeles and Orange County advisory firms. If you are unsure whether your controls would survive a DFS certification or an SEC exam, reach out and we will assess them against all three rulebooks.

Talk to our team