Texas Compliance and Cybersecurity for RIAs and Financial Advisors

Which rules reach your firm depends on how you’re registered — SEC advisers answer to Regulation S-P, state-registered firms to the Texas State Securities Board, and advisers outside SEC registration to the FTC Safeguards Rule. Texas layers its own requirements over all three. No document can tell you which set is yours; that’s what the Compliance Readiness Review determines. Briggs IT reviews what you have against what you need to be able to produce, plans what has to change, implements those changes or guides your internal IT team through them, and builds the documentation that stands when someone asks to see it.

The regulatory stack got heavier.
And it’s already in effect.

Which regime governs your firm turns on how you’re registered, not on how big you are. An SEC-registered adviser answers to Regulation S-P: written policies safeguarding customer records, an incident response program that detects, responds to, and recovers from unauthorized access, customer notification as soon as practicable and no later than 30 days after you become aware, oversight of service providers with those providers reporting a breach within 72 hours, and written policies for proper disposal of consumer and customer information. State-registered and exempt reporting advisers fall outside Reg S-P. An adviser not required to register with the SEC falls under the FTC Safeguards Rule instead — a written information security program with a designated Qualified Individual, encryption of customer information at rest and in transit, multi-factor authentication, access controls, secure disposal, vendor oversight and contracts, security-awareness training, logging of user activity, and notice to the FTC within 30 days of discovering an event affecting 500 or more consumers.

If your firm is state-registered, the Texas State Securities Board is your primary regime. Thirteen categories of records must be kept current — each client’s financial profile among them — and preserved five years, three for financial and correspondence records, with the first two years in an easily accessible place. Records kept electronically must be stored in a non-rewriteable, non-erasable format with automatic quality verification and time-dating. You also need a written supervisory system, written policies preventing misuse of material nonpublic information, and a written system addressing suspected financial exploitation of vulnerable adults. The Commissioner may inspect without notice and require records at a Board office within 48 hours, and any cybersecurity incident that triggers another notification triggers notice to the Commissioner at the same time.

Texas layers its own requirements over whichever federal regime is yours. SB 2610, in effect since September 1, 2025, is an opt-in safe harbor: a qualifying program in place at the time of a breach shields your firm from punitive damages — the program has to exist beforehand. TITEPA requires reasonable procedures to protect sensitive personal information, notice to affected Texans without unreasonable delay and no later than the 60th day, and notice to the Texas Attorney General no later than the 30th day when a breach involves at least 250 Texas residents; the TDPSA adds data-privacy duties but exempts firms and data covered by Gramm-Leach-Bliley. And TRAIGA, in effect since January 1, 2026, sets AI governance expectations if you use AI in research, client communications, or operations.

What an advisory firm
actually needs

A defensible program is a set of pieces that work together — and, just as important, the written evidence that each one exists.
For most advisory firms, that looks like things such as:

The point isn’t to assemble all of this the week before an examination. It’s to have it already in place, documented, and ready to hand over.
So an exam is a file you pull, not a fire you fight.

What happens when
the examiner shows up

Who shows up depends on how you’re registered. For an SEC-registered adviser it’s a cybersecurity-focused examination. For a state-registered firm it’s the Texas State Securities Board — and the Commissioner may inspect without notice and require your records at a Board office within 48 hours. Either way the request list is predictable.

Expect to produce your Written Information Security Program and the written policies under it, the name of your Qualified Individual, your written risk assessment and incident response plan, your breach-notification records against every clock that applies, training records for each staff member, your vendor agreements including the 72-hour breach-reporting term, proof that multi-factor authentication is actually enforced, your access controls and encryption, your activity logs, and your disposal policies. A state-registered firm should also expect the thirteen record categories current and preserved on schedule, electronic records stored non-rewriteable and time-dated, the written supervisory system, the policies preventing misuse of material nonpublic information, and the written system addressing suspected financial exploitation of vulnerable adults.

A firm that’s ready opens the file and hands it over. A firm that isn’t spends the next several weeks assembling it under pressure — and examiners notice the difference.

Briggs IT can’t rewrite your history. No one can produce records for work that was never done. What we can do is start building the record properly from day one and keep it current, so the history accumulates as we go — dated and real. The firm that begins now is the firm that, a year or two from now, simply pulls the file when a request arrives.

How we work with
advisory firms

First, we gather and review

We gather what you already have — policies, records, systems, vendor agreements — and review it against what your registration actually requires you to be able to produce. You get a written report of where the firm stands. It’s yours to keep.

Then we get it fixed — before any recurring billing

From the report we build a plan for what has to change. If you have internal or outside IT, we guide them through the changes and verify each one. If you don’t, we do the work ourselves in a scoped, defined, and billable remediation and implementation phase — a phase with an end, not us becoming your IT. Either way the gaps close to a clean baseline, and the documentation gets built as the work happens.

Then we maintain it

Recurring keeps the built program current: a review cadence, and documentation that stays current as rules, staff, and vendors change. We can’t maintain a mess — which is why the fixing comes first, and why maintenance starts once there’s something clean to maintain.

The two things every advisory
firm says first

“Our custodian handles our cybersecurity.”

Your custodian secures its own systems. It does not secure yours — the workstations your team works on, the email carrying client communications, the system where client records live, the cloud storage holding financial plans. That is the firm’s responsibility.

The obligation follows the adviser, not the institution holding the assets. Whether it arrives as Regulation S-P, the FTC Safeguards Rule, or the Texas State Securities Board’s rules depends on how you are registered — none of them route to your custodian. When an examiner asks to see your program, the custodian is not part of the answer.

“We’re a small firm.”

There is no small-firm exemption. The smaller-firm compliance date under Regulation S-P extended the time, never the obligation, and neither the FTC Safeguards Rule nor the Texas State Securities Board’s recordkeeping rules scale down for headcount. A two-person firm still owes a written program, a designated Qualified Individual, and records it can produce on demand.

Size does not lower your profile either. An advisory firm holds financial profiles, account numbers, and identity documents for every client — a rich target at any headcount, and the attacks that find you are automated, not selective. SB 2610’s safe harbor is open to smaller firms, but only if the program is documented before anything happens. Size isn’t cover. Preparation is.

See where your firm stands

The Compliance Readiness Review is a working session built for advisory firms. We gather what you already have and review it against the rules that actually reach your firm, then hand you a written report — the specific documentation, policies, and controls you’re missing, in plain English. No sales pressure. The report is yours to keep, whether or not you ever hire Briggs IT.