Endpoint Index
Research / Industry guide

Endpoint Security for Financial Advisers: Buying the Evidence Regulation S-P Asks For

Updated · data as of · 5 min read

Contents
  1. Executive summary
  2. What the amendment changed for a small firm
  3. The investigation is the purchase requirement
  4. Keeping the records long enough
  5. Your endpoint vendor is probably a service provider
  6. Recommendations by firm type
  7. Mistakes advisory firms make
  8. Frequently asked questions
  9. Methodology and caveats
  10. Sources

Executive summary

A small RIA or broker-dealer should buy endpoint security that keeps a searchable record of activity on every adviser's laptop, because amended Regulation S-P lets a firm skip customer notices only when a reasonable investigation shows sensitive information is not reasonably likely to be misused. Without that record the investigation has nothing to examine, and the safe answer becomes "notify everyone", within 30 days (17 CFR 248.30(a)(4)).

Smaller entities have had to comply since 3 June 2026; larger ones, which include advisers with $1.5 billion or more under management, since 3 December 2025 (FINRA). Endpoint detection and response (EDR) is the feature that keeps that record; 8 of 17 products in our dataset (checked 2026-10-02) include it, and the lowest list price among them is $36.00 per user or device per year.

What the amendment changed for a small firm

Three duties in 17 CFR 248.30 fall on an adviser's devices:

  1. An incident response program "reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information", including customer notification procedures (248.30(a)(3)).
  2. Customer notice as soon as practicable and no later than 30 days after becoming aware of unauthorised access, unless the investigation described below clears it (248.30(a)(4)).
  3. Service provider oversight, including a requirement that providers notify you as soon as possible and no later than 72 hours after becoming aware of a breach (248.30(a)(5)).

Detection is where an endpoint product earns its fee. Most advisory firms have a handful of laptops holding account statements, planning files and a mailbox full of client correspondence. That handful is the attack surface.

The investigation is the purchase requirement

The exception in 248.30(a)(4) is worth reading closely. Notice is not required if the firm "determines, after a reasonable investigation of the facts and circumstances of the incident", that sensitive customer information "has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience."

An investigation needs facts. Antivirus tells you it quarantined a file. EDR tells you which process ran, which folders it read, whether anything left the laptop and which account was signed in. That second set of facts is what lets a chief compliance officer write a defensible conclusion instead of sending a letter to every client.

Keeping the records long enough

A laptop compromised in May may not be discovered until August. The record only helps if it still exists, so check how long each product keeps activity data and whether it can send that data to a log store you control. The EDR products differ in which log stores they name as supported connectors:

ProductSIEM integrationNamed integrations
Microsoft Defender for BusinessIncludedMicrosoft Sentinel
ThreatDown EliteIncludedSplunk Enterprise, Microsoft Sentinel, Google Chronicle
ThreatDown AdvancedIncludedSplunk Enterprise, Microsoft Sentinel, Google Chronicle
SentinelOne Singularity ControlIncludedSplunk, IBM Security
Huntress Managed EDRIncludedNone named
CynetIncludedIBM Security QRadar, SolarWinds SEM
SentinelOne Singularity CompleteIncludedSplunk, IBM Security
WatchGuard Endpoint Security 360IncludedAlienVault USM, Fortinet FortiSIEM, HPE ArcSight, IBM QRadar, McAfee Enterprise Security Manager, LogRhythm, SolarWinds Log & Event Manager, Splunk
Named integrations are those the vendor lists by name on its own integration pages. Others may exist through marketplaces or APIs.

For a firm on Microsoft 365, Defender for Business feeding Microsoft Sentinel keeps everything in one tenant. A firm with an outsourced IT provider should ask which log store the provider uses and whether the firm can get its data out if it changes provider.

Your endpoint vendor is probably a service provider

The endpoint vendor's cloud receives telemetry from devices that hold customer information. Treat it as a service provider under 248.30(a)(5) unless counsel concludes otherwise: check that its contract commits it to tell you of a breach within 72 hours, and file that clause with your written policies. The same applies to an IT provider that runs the console for you.

Recommendations by firm type

Solo adviser or two-person RIA buying online today. These EDR products have an online checkout, so a solo adviser can order today:

#ProductPrice at 10 seats24/7 managed responseMin seatsSMB Fit Score
01Microsoft Defender for Business$36.00 /user/yrNot offered175
02ThreatDown Elite$99.00 /endpoint/yrIncluded552
03ThreatDown Advanced$79.00 /endpoint/yrNot offered551
Ranked by SMB Fit Score (fit-v1), then price. Prices are annual list prices per unit at 10 seats, from each vendor's own pricing page; "Min N seats" means the vendor's smallest purchase is larger. Follow a product link for the source and verification date.

Microsoft Defender for Business ($36.00 per user per year) is the natural choice for a firm already on Microsoft 365, and it covers the adviser's phone as well. It sells from a single licence; the ThreatDown store will not take an order below 5 devices, so a one-laptop firm pays for spares there. The endpoint security cost report sets these prices against the rest of the market at 10, 25 and 100 seats.

RIA of 5 to 25 people with outsourced IT. Ask the IT provider to show you, in writing, how an incident would be investigated: who pulls the EDR timeline, how long data is kept, and how fast they will tell you. If nobody watches alerts at night, pay for a product with managed response included, such as ThreatDown Elite ($99.00 per endpoint per year). Its online store stops at 20 devices; a larger firm buys it through ThreatDown sales or a partner.

Adviser affiliated with a broker-dealer or a larger platform. Your affiliate's written supervisory procedures may already specify the endpoint product. Your own laptop still needs to be covered and documented; do not assume the platform's security reaches it.

Mistakes advisory firms make

  • Buying antivirus without EDR. The firm then has nothing to investigate with and loses the benefit of the no-harm exception.
  • Keeping logs for less time than it takes to discover an intrusion. Retention is a purchase question, not an afterthought.
  • Forgetting the vendor contract. A service provider without a 72-hour notice commitment is a gap in your oversight policy.
  • Treating the custodian's security as covering the adviser. The custodian protects its platform; the laptop logging into it is yours.

Frequently asked questions

When did smaller advisers have to comply with amended Regulation S-P?

By 3 June 2026, 24 months after the amendments were published in the Federal Register on 3 June 2024. Larger entities, including advisers with $1.5 billion or more in assets under management, had 18 months, to 3 December 2025.

Can an adviser avoid notifying clients after a breach?

Only if, after a reasonable investigation, it determines that sensitive customer information has not been and is not reasonably likely to be used in a way that would cause substantial harm or inconvenience (248.30(a)(4)). The investigation needs evidence of what was accessed.

Does Regulation S-P require EDR?

No product is named. The rule requires a program reasonably designed to detect, respond to and recover from unauthorised access. EDR is the most direct way to supply the detection and the evidence on laptops.

How quickly must service providers report a breach to an adviser?

As soon as possible and no later than 72 hours after becoming aware of it, under the policies the adviser must maintain (248.30(a)(5)).

Methodology and caveats

We read 17 CFR 248.30 on Cornell's LII, and compliance dates and size thresholds on FINRA's advisory and the SEC's May 2024 press release, all on 30 September 2026. The SIEM table is filtered to products with EDR included; the vendor table adds the filter for products sold through an online store. Each price and capability shown is inserted from our product records when the site is built, and the vendor source sits on the product page.

For compliance decisions, your chief compliance officer and counsel are the authority; this guide covers the buying decision only.

Sources

  1. Legal Information Institute. 17 CFR 248.30, Procedures to safeguard customer information. Checked 30 September 2026.
  2. U.S. Securities and Exchange Commission. SEC Adopts Rule Amendments to Regulation S-P (May 2024). Checked 30 September 2026.
  3. FINRA. Cybersecurity Advisory: SEC Amends Regulation S-P. Checked 30 September 2026.
  4. Endpoint Index records for every EDR product in the SIEM table, vendor-checked 2026-10-02.

Related research

All research ›

Methodology · Report an error · Vendor not listed? Get listed