The SEC’s May 16, 2024, adoption of enhancements to Regulation S‑P (Reg S‑P) has significantly broadened the obligations of registered entities following the detection of a cyber breach that has, or is reasonably likely to have, compromised sensitive customer data. Larger entities faced a compliance deadline of December 3, 2025, while smaller ones have until June 3, 2026.
In addition to the strict requirements that Reg S‑P already imposed with regard to cybersecurity policies and procedures, fund managers must have policies and procedures in place that are reasonably designed to notify customers as soon as practicable, and not more than 30 days, after detection of a breach. As bad actors grow ever more sophisticated and resourceful, the cyber threat facing the private funds sector has never been more acute, as the SEC recognized when the agency devoted a large section of its new 2026 Examination Priorities (Priorities) to Reg S‑P compliance.
This article summarizes the amendments to Reg S‑P; sets forth practical steps that fund managers should take upon discovery of a cyber incident; outlines best practices with regard to customer notification, including what to mention and what to exclude; and provides expert legal analysis.
See “SEC Staff Discuss Regulation S‑P Amendments and Related Examination Process” (Oct. 23, 2025).
Expansion of Existing Requirements
Adopted in 2000, Reg S‑P, in its original form, imposed a number of “safeguards” requiring registered investment advisers to adopt written policies and procedures designed to protect customer records and information. As cyber threats have evolved, and criminals have used ever more sophisticated tools and methodologies in the hope of breaching systems’ defenses, the Commission responded by proposing amendments to Reg S-P in March 2023 that would require covered entities to adopt and implement written policies and procedures around an incident response program.
The final version of that proposal took effect on May 16, 2024, giving larger entities with at least $1.5 billion in assets under management a December 3, 2025, compliance deadline and smaller entities below that threshold until June 3, 2026, to comply. Now, under Reg S‑P, a fully compliant cyber incident response program must:
- detect any breach that has occurred;
- respond to the breach;
- recover from the breach;
- notify individuals whose sensitive data was, or was reasonably likely to have been, accessed without authorization; and
- create and maintain required compliance records.
As to the notification requirement, a fund manager must notify all individuals that have been, or could reasonably be expected to have been, impacted by a data privacy incident as soon as practicable but no more than 30 days after the incident’s discovery. If the manager is unable to determine which individuals were impacted by the incident, it should notify all individuals who could have been impacted. Reg S‑P requires such notices to include details about the incident, the breached data and how affected individuals can respond to the breach to protect themselves.
No fund manager should wait until an intrusion in its systems has been detected to begin taking cybersecurity seriously, emphasized Adam S. Aderton, partner at Simpson Thacher & Bartlett LLP and former senior official in the SEC’s Division of Enforcement. Ideally, fund managers will have adopted and implemented policies and procedures well before the latest amendments to Reg S‑P, in keeping with their fiduciary and legal obligations, he stressed.
Now that the December 3, 2025, deadline for larger entities to comply with the amendments has come and gone, those fund managers over the $1.5‑billion threshold should have effective customer notification protocols and procedures in place. For those under the threshold, the June 3, 2026, deadline is fast approaching, continued Aderton. “For those entities not yet in compliance, this is the time to get the incident response plan up and running,” he advised. The fact that the topic figures prominently in the agency’s Priorities, underscores the urgency of the issue, he said.
See “Six Steps to Address the SEC’s Trump Era Cyber Enforcement Priorities” (Oct. 9, 2025); and “A Checklist to Help Fund Managers Assess Their Cybersecurity Programs” (Jul. 14, 2022).
Immediate Steps to Take After a Breach
Following detection of a cyber breach, there are certain steps that an entity needs to take straightaway. These steps are not only necessary on their own terms – to ensure the entity’s survival – but also as preconditions for the entity to be in a position to assess whether the circumstances require investor notification in accordance with Reg S‑P.
1) Mitigate Damage
As soon as a fund manager becomes aware of a breach in cyber defenses, it must take swift action to limit and contain the breach, whether that means shutting down systems, activating antivirus software or calling in specialists with more advanced incident response methodologies. Fast action can often mean the difference between a relatively insignificant incident and an existential threat to the entity’s continued livelihood.
One of the best practices for fund managers is to have an incident response plan in place that will entail notifying fund personnel swiftly to enable it to marshal internal resources, noted Louis Bruno, partner at regulatory compliance consultancy EisnerAmper. “Usually, within an incident response program, there is a defined governance structure and an escalation procedure, and within that governance structure, there is an incident response team who can evaluate the impact of the breach,” he explained. That team should be equipped and authorized to conduct internal IT investigations and report its findings.
“You’ll need to take immediate steps, consistent with that incident response plan, to contain and control any further unauthorized access, which sounds like an obvious first thing to do – stop the bleeding as soon as you know where it is happening,” Aderton affirmed.
However, given the growing variety and sophistication of cyberattacks, even the best-prepared manager needs to be cognizant of the possibility that a breach may happen of a nature and on a scale that it has not seen or heard of before and that internal IT resources are inadequate to counter, noted David S. Slovick, partner at Kopecky Schumacher Rosenburg. Hence, figuring out the scope of the breach – in order to assess what further steps may be required under Reg S‑P – can sometimes require outreach to external service providers.
“The first order of business is to get your arms around where the breach occurred and what the extent of it was,” Slovick affirmed. “That may involve retaining an outside consultant specializing in forensic accounting to trace funds or information trails. A consultant can often tell, based on computer clues, where information went when it left the system.” He added, “The response may also involve employee interviews and email reviews to identify whether there was a human source for the problem, which there often is. It will also involve remediation efforts, not only to fix the breach but also to prevent breaches in the future.”
Managers may wonder whether they should proceed differently under Reg S‑P in the case of an internal breach, as opposed to an external one, such as a breach of a service provider with access to information on the manager’s investors. The short answer to that question is no, Aderton said. “The regulation doesn’t call for a difference in response between those two categories,” he noted. “It may sometimes be easier to ‘get your arms around’ an internal breach, although not in every case. But, either way, managers should respond to both kinds of breaches in the same manner – contain and control; assess; and notify.”
However, one exception, Aderton acknowledged, would be an extreme circumstance in which a bad actor had undertaken a cyberattack of such magnitude and severity that it might pose a danger not only to the fund manager but also to national security. “If your initial assessment finds that this is potentially a nation-state threat actor, that situation may warrant a response that includes outreach to the FBI and other relevant criminal authorities,” he noted.
See “Managing Cybersecurity, Incident Response Planning and Vendor Risk” (Dec. 4, 2025).
2) Identify Affected Parties
Next, the manager must move swiftly to determine, through a reasonable investigation of the facts and circumstances, the scope of the breach and whether it has caused or is likely to have caused “substantial harm or inconvenience” to the customers whose sensitive data was improperly accessed. As part of that process, it is essential to figure out what specific kind of customer information may be involved, whether it is something as sensitive as an investor’s bank account information or simply a contact person’s name. That determination will be important to any assessment of whether the incident meets the “substantial harm or inconvenience” threshold.
Err on the Side of Caution
In amending Reg S‑P, the SEC has framed the question of the seriousness of a breach in terms of whether a reasonable investigation by the fund manager determines that customers have suffered or are likely to suffer “substantial harm or inconvenience.” If they have, they must be notified within the specified time frame. But the SEC’s terminology here does not provide a particularly useful standard in any and all situations that one can envision, according to Aderton.
“The use of those terms presents us with a bit of a challenge, because what one person thinks of as substantial harm or significant inconvenience may not look the same to someone else,” Aderton reflected. “And it is the kind of thing you could see a particularly aggressive regulator assessing in hindsight and making its own determination.” In that scenario, what the impacted entity considered a relatively minor incident, without serious consequences for its investors, could lead to regulatory trouble and potentially an enforcement action for Reg S‑P violations.
“The meaning of substantial harm or inconvenience is, of course, going to depend on the facts and circumstances of the conduct that has come to light,” Slovick concurred. “The SEC’s definition is totally unhelpful for firms trying to make a good-faith assessment of their obligations.”
To avoid second-guessing, managers may decide to automatically notify investors of any breach in an effort to avoid violating Reg S‑P. But what if the breach turns out not to have serious consequences for them? “You don’t want to call investors and say, ‘Hey, your data has been breached,’ only to have to call them again a week later and say, ‘It wasn’t really that big of a deal. Don’t worry about it.’ That’s terrible for investor relations,” Slovick observed.
However, that does not change the reality that the SEC has made Reg S‑P enforcement a centerpiece of its 2026 examination priorities and that, without further guidance, it is unwise to assume the regulators will err on the side of leniency.
“The only thing we can say for sure is that the SEC’s Enforcement Division will take the most expansive view of what ‘substantial harm or inconvenience’ means,” Slovick stated. “And, until we get the first few settlement orders under the new Reg S‑P, it is anybody’s guess what the SEC’s interpretation is going to be.” He concluded, “All of which is to say that you should be careful in your estimation about what may trigger your reporting obligation under the new regulation. Don’t be too cavalier about it.”
“Cyber incidents span a huge spectrum, so any response should be driven by facts on the ground,” stated David L. Hirsch, partner at McGuireWoods and former head of an SEC enforcement unit. “If firms have reason to believe there has been an incident that could have compromised customer information – either information that would allow the attacker to identify the customer or to gain access to customer accounts or authorization – then there’s going to be a notification requirement.”
Refer to the Proposal’s Release
In general, it really is best to err on the side of caution, Aderton agreed. What fund managers and compliance personnel fortunately do know is that the initial proposal for amending Reg S‑P clearly listed a number of factors the SEC did understand to constitute substantial harm or inconvenience, he noted. Although not included in the final adopting release, those criteria can still be useful in post-incident assessments of a breach’s severity and scope. Those consequences include investors’ experiencing personal injury, financial loss and/or more than a trivial expenditure of time and effort related to any of the following:
- theft;
- fraud;
- harassment;
- physical harm;
- impersonation;
- intimidation;
- damage to reputation;
- impaired credit eligibility; and
- misuse of someone’s information to obtain a financial product or service, or otherwise misuse a customer account.
Any investor who suffers one or more of the above consequences is unlikely to be persuaded that no serious harm or inconvenience has occurred, Aderton noted. In the end, SEC staff contemplating how to word the adoptive release may have not wanted to “pin themselves to an enumerated list” and exclude other potential categories of harm or inconvenience, he reasoned. The agency has left the door open to the identification of further consequences, reserving some latitude for itself when it comes to Reg S‑P enforcement.
“So, for now, [all we have is] the enumerated list, plus some factors that we’re not really sure about yet and may not be sure about until we get additional guidance from the SEC,” concluded Aderton.
3) Determine Who Will Make Any Required Notifications
If the fund manager has determined that the “substantial harm or inconvenience” threshold has been met, it must move swiftly to notify the affected investors. The question arises as to who, within the organization, should handle such a sensitive task. It is essential to be clear about which divisions and personnel are integral to that effort. For example, the IT department plays a crucial role in detecting and remedying the breach. However, that role typically does not extend to customer outreach, Aderton noted.
The fund manager’s compliance department will play a vital role, often in consultation with the IT department, in examining the scope of the breach and making a determination as to whether the incident triggers Reg S‑P’s notification requirement. “You want to have your compliance and legal teams involved, whether that means in-house lawyers or outside counsel, because you want to ensure your process complies with Reg S‑P,” Slovick concurred. “And you should also ensure that you’re properly recording the steps that you have taken, so that you can show your work down the road if the SEC ever asks you about it.”
But when it comes to who will actually conduct the outreach – typically by sending emails to affected investors – the role is likely to fall squarely within the domain of the investor relations (IR) team, Aderton argued. “If the IR team is regularly making contact with your investors, then it makes the most sense for that team to make the outreach,” he said.
Of course, that does not mean the IR team is operating within a silo, continued Aderton. It will utilize findings from IT, and send out the message, which will be vetted – or, in some cases, drafted – by the compliance department and, in the event of a highly serious incident, will include input from the leadership of the firm, he said.
In Slovick’s view, the question of who should do the actual investor notifications turns largely on “what the normal chain of communication is within a firm.” Here, managers need to use common sense and think about who the public-facing individual or team has typically been. “If I’m used to hearing from the head of IR, or I receive a letter from the CEO, CFO or the chief portfolio manager monthly or quarterly, and then all of a sudden I get a letter from a lawyer I’ve never heard from before,” he hypothesized, “that might make me panic. So, the messaging should go through whatever the normal chain is, backed up by and supervised by compliance and legal.”
4) Determine Scope of Notifications
Whether to notify all of a fund manager’s investors, or just those definitively known to have had their information compromised in the breach, is another critical question. Managers may be naturally concerned with minimizing any potential investor relations and reputational harm, especially given the risk of a chain reaction in which investors unaffected by the breach rush for the exits, acknowledged Slovick. Once again, best practices revolve around making the most transparent disclosures that a manager can based on the information it has – but not going further.
“It all comes down to what you know at a given time. As in any other disclosure situation under the federal securities laws, you can’t be liable for failing to accurately predict the future,” Slovick said. “What you can be liable for is making misrepresentations or disclosing half-truths about the information you do have already.”
How to proceed will depend largely on what the reasonable investigation has uncovered, Slovick explained. If a manager knows that, say, one third of its investors were definitely affected and one third were definitely not, and it is uncertain about the remaining third, then it should err on the side of caution and notify those definitely affected and those who may have been – fully two thirds of its total investor base, he reasoned.
“If you can say definitively that certain clients were not affected, then they don’t need to be notified,” continued Slovick. “There is a very serious issue here of investor relations and perceptions. If you start telling people that they might have been affected but you don’t know, then you just look incompetent and you may well end up triggering a fire sale,” he warned.
“But, at the end of the day, it’s going to be the SEC’s enforcement staff that gets to judge whether the firm guessed the future use of that stolen data correctly,” Slovick conceded. “The takeaway here is that firms should err on the side of notifying more rather than fewer customers if there has been a wide data breach.”
See “Enforcement Actions Highlight Advisers’ Duty to Accurately and Honestly Communicate With Investors” (Oct. 10, 2024).
5) Make Notifications
Timing of the Notification
The language of Reg S‑P is quite clear: notification should go out to customers as soon as practicable but no more than 30 days after discovery of the breach. In other words, the clock starts ticking as soon as the fund manager becomes aware of the issue.
A further consideration involves notification of insurance providers, pointed out Hirsch. “You likely should notify quite quickly if you have cyber insurance or if you have just broad insurance,” he said. “You want to notify your carrier immediately. They tend to impose deadlines, written into their policies, about when notification has to be provided to ensure you’re going to be covered. So check those policies carefully and follow them to the letter.”
See “Avoiding Pitfalls in Cyber Insurance Applications and Claims” (Apr. 11, 2024); and “Tips for Working With Cyber Insurance Carriers Following a Ransomware Event” (Oct. 26, 2023).
What to Include
Reg S‑P requires the notification to include:
- general information about the breach;
- the types of sensitive customer information involved; and
- steps affected individuals may take to protect themselves.
Receiving this notification from a fund manager can be highly upsetting to investors who trusted the manager to safeguard that data. One of the keys to such communications is to avoid fanning the flames by appearing evasive. Put simply, transparency is of the essence, Aderton said.
“The first principle is to be accurate with respect to what you are disclosing to investors,” Aderton explained. “Candidly, investors in general understand that these breaches have the potential to happen all the time nowadays. Your best practice is to be transparent about the nature of the breach and be clear about the types of information affected.” He recommended that fund managers “provide sufficient information so that, at least at a high level, the individuals whose information has been compromised can generally understand what has happened – to the extent possible within the notification period – as well as the type of information accessed.”
See “New Pressures Shift Best Practices for Ransomware Crisis Communications” (Nov. 10, 2022).
What to Exclude
At the same time, it is important to exclude any information that has not yet been verified and exists only as rumor or supposition, Aderton added. Not only will including such information not help the situation, but it can cause still more embarrassment and confusion later if it turns out to be inaccurate and add to already significant damage to investor relations and reputation.
“It is a better course to say that ‘We’re continuing to evaluate,’ as opposed to speculating about what might have happened,” Aderton commented. “You are better advised to reserve judgment on those things rather than make a statement you’re not wholly confident about in a notification to your investors.”
Even if fund managers have what they believe to be an exact figure for investors affected – say, 100 investors or 10 percent of the total number in the fund – that specific data does not need to be in the notification. “It is fine to say, ‘We understand that some customers have been affected,’” Aderton clarified. “At the time of the notification, this is another area where you may not have all the information you need to give a number with any precision.”
Finding the perfect language to include in such communications can be especially challenging when the manager is still trying to get to the bottom of how and why the breach occurred, Slovick agreed. When drafting such communications, it is crucial to exclude any language that might give investors the wrong impression and even potentially incur legal penalties, if it is construed to discourage them from exercising their legal rights in the situation, he cautioned.
“You don’t want to word your instructions in such a way that they can be interpreted to have told your investors that they can’t cooperate with the SEC. That’s a real no-no,” Slovick observed. “Definitely don’t tell people that they should not participate in an enforcement investigation.”
However, from a legal standpoint, Slovick said he sees nothing wrong with wording a communication in a manner that emphasizes the sensitive nature of the incident without in any way discouraging recipients from exercising their rights. He gave an example of some of the language that a thoughtfully worded notification might include: “We informed you of the incident as soon as we could because we want to protect you. But our investigation is ongoing. Therefore, we ask for your help in keeping the matter confidential until we are able to come back to you with more information.”
The thing to remember here, Slovick emphasized, is that such a request will be exactly that – a request that in no way inhibits people from speaking to the government or the media.