Form ADV cybersecurity: making the disclosure true, not just prettier
How an RIA closes the gap between what its Form ADV Part 2A brochure says about cybersecurity and the controls actually running, and why an overstated disclosure is worse than a modest accurate one.
· Jake Schaaf, Founder of Atticus Rowan
A registered investment adviser writes in its Form ADV Part 2A brochure that the firm “maintains robust cybersecurity controls to protect client information.” Then you look at the environment. There is one shared admin password taped inside a desk drawer. Email has no multi-factor authentication. Nobody can say who has access to the portfolio accounting system or when that was last reviewed. The disclosure reads well. The reality behind it does not exist.
That gap is the exposure. An SEC examiner can hold the firm to what it wrote. So can a plaintiff’s lawyer after an incident. The brochure is a public representation, and a representation that does not match the running controls is not a compliance win, it is a liability the firm created for itself.
This post is about making the disclosure true. It is not about writing prettier disclosure language. The wording belongs to the firm’s Chief Compliance Officer and its counsel. The control substance behind the wording is where an IT and security partner earns its keep, and it is where most of the risk lives.
The disclosure is a promise the firm has to keep
Form ADV Part 2A is the brochure an RIA delivers to clients. It describes the business, the fees, the conflicts and, increasingly, how the firm protects client data. The SEC has increasingly focused on cybersecurity as a matter of both operational risk and disclosure. Advisers are expected to have reasonable policies and procedures, and where they describe those policies to clients, the description has to be accurate and not misleading.
Two ideas sit underneath that expectation:
- Regulation S-P frames the adviser’s obligation to protect and properly dispose of client records and information. The safeguards and disposal expectations are the operational floor.
- The Marketing Rule governs how an adviser presents itself. A cybersecurity claim in a client-facing document is a statement about the firm. If it overstates what the firm does, that is the kind of misleading representation the rule exists to prevent.
The practical takeaway does not depend on the current status of any single proposed rule. The SEC’s direction of travel is consistent. Advisers should assume that a cybersecurity statement in the brochure will be read as a commitment, and that an examiner will ask to see the controls that back it up.
Why an overstated disclosure is worse than a modest one
There is a strong temptation to write the aspirational version. It sounds better to prospects. It feels like table stakes. But the brochure is not marketing copy in the ordinary sense. It is a regulated disclosure, and the standard for it is accuracy.
Consider the two failure modes:
- A modest, accurate disclosure. The firm describes a reasonable set of controls it actually operates. If an incident happens anyway, the firm was truthful. The examination question becomes whether the controls were reasonable, which is a defensible position.
- An overstated disclosure. The firm claims “robust” or “enterprise-grade” controls it does not have. Now an incident is not just a security failure, it is a disclosure failure. The firm told clients something untrue. That is a second, independent problem, and it is the one that turns an unfortunate event into an enforcement matter or a lawsuit.
Say less than you could. Then do more than you said. That order is the safe one. A firm that runs strong controls and describes them plainly is in a far better position than a firm whose brochure outruns its environment.
What regulators expect behind a cybersecurity disclosure
When a brochure says the firm protects client information, the controls that make that credible are not exotic. They are the ones an examiner will look for and the ones an RIA in this position needs in place and evidenced.
Multi-factor authentication and access controls
MFA on email, on remote access and on any system holding client data is the single most load-bearing control. Most adviser breaches trace back to a compromised credential with no second factor. Alongside MFA, the firm needs real access controls: named accounts instead of shared logins, least-privilege access to the portfolio accounting and CRM systems and a documented, periodic access review. A shared admin password is the opposite of everything a cybersecurity disclosure implies.
Vendor and third-party risk
An RIA runs on vendors. The custodian, the portfolio accounting platform, the CRM and the outsourced back office all touch client data. Regulation S-P style obligations do not stop at the firm’s own perimeter. The firm needs to know which vendors hold client data, what their security posture is and what the contracts say about safeguards and breach notification. A brochure that promises protection while ignoring the vendors that hold the data is describing a firm that does not exist. Our customer security questionnaire walkthrough covers the mirror image of this, the questions the firm itself will get asked.
Incident response
The firm needs a written incident response plan that names roles, defines escalation and describes how client and regulator notification would happen. This does not have to be elaborate for a small adviser. It has to exist, it has to be tested and it has to be something the firm could execute under pressure rather than a document nobody has read.
Encryption and logging
Encryption of client data at rest and in transit is expected. So is logging: the firm should be able to answer who logged in, from where and what they touched. When an incident happens, the absence of logs turns a contained question into an open-ended one. You cannot prove what did not happen if you were never recording.
Aligning the compliance team and the security partner
Here is the division of labor that keeps a firm honest. The CCO and counsel own the disclosure. They decide what the brochure says and how it says it. The IT and security partner owns the substance. It builds, operates and documents the controls those words describe.
The failure pattern is these two tracks running in isolation. Counsel drafts a strong-sounding cybersecurity paragraph without knowing the environment has no MFA. Or IT quietly changes a control without anyone updating the brochure. Either way the document and the reality drift apart, and drift is exactly what an examiner finds.
The fix is a simple, recurring reconciliation. The brochure’s cybersecurity language and the actual control set get compared on a defined cadence, ideally as part of the firm’s annual review of Form ADV. For every claim in the disclosure, the security partner should be able to point to the control that makes it true and the evidence that proves the control is running. Where a claim has no control behind it, one of two things has to change: the firm builds the control or the CCO revises the language. Both are legitimate. Silence is not.
In our experience with firms across the financial-services scope, closing the most consequential gap, no MFA on email, tends to take a single working session rather than a quarter. That is the pattern worth internalizing. The controls behind a credible cybersecurity disclosure are largely achievable on a short timeline. The reason firms carry an overstated brochure is rarely cost. It is that no one connected the words to the controls.
Evidence is the point
A disclosure is a claim. An examination is a request to substantiate the claim. The firm that survives is the one whose brochure, policies and running controls all say the same thing, and which can hand over the artifacts that prove it: the MFA enforcement records, the access review logs, the vendor inventory, the incident response plan, the encryption configuration.
This is the same logic that governs formal attestation work. Our post on SOC 2 readiness versus audit walks through the difference between describing controls and evidencing them, and the discipline transfers directly to a Form ADV cybersecurity disclosure.
Where Atticus Rowan fits
Atticus Rowan is the IT and security partner that builds, operates and documents the technical controls behind an RIA’s cybersecurity disclosure. We are not the firm’s compliance consultant, we are not legal counsel and we do not draft or file Form ADV. The CCO and counsel own the disclosure language and the filing. We make the substance real: MFA and access controls, vendor risk visibility, incident response, encryption and logging, plus the evidence trail that lets the firm stand behind what its brochure says.
If your brochure describes cybersecurity controls you are not certain are fully in place, the right move is to reconcile the words with the environment before an examiner does it for you. Explore our solutions to see how we build and evidence the controls that make a Form ADV cybersecurity disclosure true.
Related insights
More on Compliance frameworks →May 29, 2026
Accounting firm cybersecurity, IRS Pub 4557 and the FTC Safeguards Rule
What the IRS expects in a Written Information Security Plan, the nine elements the revised FTC Safeguards Rule actually requires and how the new 30-day breach notification rule changed the operational picture for tax preparers and accounting firms.
May 28, 2026
HIPAA breach notification, the 60-day clock and what trips it
When the 60-day breach notification clock actually starts under the HIPAA Breach Notification Rule, the four-factor Risk of Compromise analysis and the timing failures that turn an incident into an OCR enforcement action.
May 27, 2026
HIPAA risk analysis vs risk assessment, what OCR actually scores
Why HHS Office for Civil Rights settlements keep citing the same Security Rule risk analysis failure, and how the formal risk analysis differs from the general risk assessments most practices think satisfy it.