Skip to content

Compliance

SEC Regulation S-P
Penetration Testing

The SEC’s safeguards and disposal rules, 17 CFR 248.30, as amended in 2024

Component tests from $4,200, free retest. See all pricing →

Last reviewed

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When you need Regulation S-P testing

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • Your compliance date has passed, and the incident response program exists on paper but has never been run against a real intrusion.
  • An SEC examination is scheduled, and the request list asks how you test your safeguards and oversee your service providers.
  • An allocator’s operational due diligence questionnaire asks for a recent independent penetration test.
  • A vendor reported a breach, or your managed IT provider changed, and you need to know what an intruder could reach through them.
  • Wire fraud through a compromised mailbox hit a peer, and the operations team wants to know whether the same attack would work on them.

The 2024 amendments

What the Regulation S-P amendments require

The SEC adopted Regulation S-P in 2000, and its safeguards rule has long required policies protecting customer information. The amendments adopted in May 2024, effective August 2, 2024, expanded the safeguards and disposal rules into the obligations below. None of them names a penetration test, but each one depends on controls a test can prove or disprove.

What the rule says

Safeguards, 248.30(a)(1) and (2)
Written policies and procedures covering administrative, technical, and physical safeguards, reasonably designed to protect customer information against anticipated threats and unauthorized access
Incident response program, 248.30(a)(3)
A program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information, including assessing, containing, and controlling an incident
Customer notice, 248.30(a)(4)
Notice to affected individuals as soon as practicable, and no later than 30 days after becoming aware of unauthorized access to sensitive customer information
Service providers, 248.30(a)(5)
Oversight through due diligence and monitoring, and provider notice to you within 72 hours of a breach of a customer information system they maintain
Disposal, 248.30(b)
Proper disposal of both consumer information and customer information
Recordkeeping
Written records documenting compliance with the safeguards and disposal rules, kept under each registrant’s books-and-records rule

Where testing fits

Safeguards, 248.30(a)(1) and (2)
A test is the most direct evidence that the technical safeguards are reasonably designed and working
Incident response program, 248.30(a)(3)
A test shows whether you would detect an intrusion, and gives the team a real timeline to rehearse against
Customer notice, 248.30(a)(4)
Logs that show which records were touched let you notify the right people, not everyone in the system
Service providers, 248.30(a)(5)
Testing the provider connections into your network, and whether provider activity is visible to you
Disposal, 248.30(b)
Testing turns up the forgotten exports, backups, and file shares that should have been disposed of
Recordkeeping
Dated reports, remediation tracking, and retest results belong in those records

Customer information now includes information about the customers of other financial institutions that has been provided to you, and transfer agents registered with the SEC or another appropriate regulatory agency are covered by the safeguards rule for the first time.

Compliance dates

Larger and smaller entities: who had to comply when

The SEC set two compliance dates by firm size. Both have passed, so every covered institution must now comply, and the SEC’s examination staff said they would examine firms for compliance with the amended rule once each firm’s date arrived.

Larger entity: complied by December 3, 2025

Registered investment advisers
$1.5 billion or more in assets under management
Investment companies
Net assets of $1 billion or more at fiscal year end, counted with the other funds in the same group of related investment companies
Broker-dealers
Every broker-dealer that is not a small entity under the Exchange Act
Transfer agents
Every transfer agent that is not a small entity under the Exchange Act

Smaller entity: complied by June 3, 2026

Registered investment advisers
Under $1.5 billion in assets under management
Investment companies
Below that threshold
Broker-dealers
Total capital under $500,000, and not affiliated with any person that is not a small entity
Transfer agents
Small entities as the Exchange Act rules define them

Funding portals follow Regulation S-P as it applies to brokers. Private funds that rely on section 3(c)(1) or 3(c)(7) of the Investment Company Act are not covered themselves, but an SEC-registered adviser to those funds is.

What we assess

What your Reg S-P test covers

Regulation S-P protects customer information, and its notice rule turns on sensitive customer information: Social Security numbers, or account numbers and user names combined with the codes that open an account. We test the systems that hold it, and the people and providers who can reach it.

Email & Identity

The Microsoft 365 or Google Workspace tenant and the SSO provider, a common route into adviser and broker-dealer incidents.

We test for

  • MFA coverage and phishing-resistant sign-in
  • Conditional access and legacy authentication
  • Mailbox forwarding and inbox rules
  • Session theft through adversary-in-the-middle phishing

Perimeter & Internal Network

Everything internet-facing, and how far one compromised laptop reaches toward customer records.

We test for

  • VPN, remote desktop, and portal exposure
  • Active Directory attack paths
  • Access to shares and databases holding customer information
  • Segmentation of guest and office networks

People & Money Movement

The staff who approve wires, change bank details, or reset client access, tested the way fraudsters target them.

We test for

  • Targeted phishing of operations staff
  • Help desk and client service voice pretexting
  • Callback and account-change verification
  • Reporting rates and time to report

Providers & Detection

The service providers the amendments make you oversee, and whether your monitoring would notice unauthorized access at all.

We test for

  • Vendor remote access and shared accounts
  • Cloud storage and file-transfer exposure
  • Logging of our activity by you and your providers
  • Evidence to scope a notice under 248.30(a)(4)

The requirement

Does Regulation S-P require a penetration test?

What the rule says

No test is named. Rule 248.30 requires safeguards reasonably designed to protect customer information, and an incident response program reasonably designed to detect, respond to, and recover from unauthorized access. Whether a program was reasonably designed is judged by examiners, usually after the fact.

What examiners look at

The SEC’s fiscal 2026 examination priorities name governance, data loss prevention, access controls, account management, and response to incidents such as ransomware as cybersecurity focus areas, and commit to examining firms for compliance with the amended Regulation S-P after their compliance dates.

What a test proves

That access controls, MFA, and segmentation hold against a real attempt, and that monitoring saw it. A dated report with the fixes retested is evidence the policies are more than paper, and it is the same evidence allocators ask for in operational due diligence.

For how advisers and funds are tested day to day, see penetration testing for wealth management firms and hedge funds and asset managers.

Incident response

Testing the incident response program before an incident does

The notice clock starts when you become aware of unauthorized access, and it allows at most 30 days. If you cannot tell which customers’ sensitive information was accessed, 248.30(a)(4)(ii) requires notice to every individual whose sensitive customer information resides in the affected system. The difference between notifying a handful of clients and every client in the system is usually the logging.

We make that concrete. After testing, your team gets a timeline of what we did, from which account, and when. Checking it against what your logs, your managed IT provider, and your alerting recorded shows whether the program can detect, assess, and scope an incident, or only document one. To run the exercise live with your defenders, a purple team assessment works through it in the room, and a ransomware readiness assessment tests recovery.

FINRA’s 2026 oversight report lists tabletop exercises among effective cybersecurity practices for member firms. A timeline from a real test makes a better tabletop than a hypothetical scenario.

The examination file

What goes in the examination file

  • A penetration test report dated within the year, with a scope statement naming the systems that hold customer information.
  • Findings rated by severity, remediation tracking, and retest evidence showing closure.
  • Phishing results for the staff who handle customer accounts and money movement.
  • A detection timeline showing what the incident response program saw, for the records the amended rule requires.
  • An executive summary for the chief compliance officer’s annual review and for senior management.

The amended rule’s records are kept for the period in your own books-and-records rule: five years for advisers under Rule 204-2, three years for broker-dealers under Rule 17a-4 and for transfer agents under Rule 17Ad-7, and six years for investment companies.

Methodology

How we test

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your compliance test runs through.

  1. 01

    Scope the boundary

    The systems your framework actually covers, and nothing you would pay to test twice.

  2. 02

    Test

    The component penetration tests run to PTES and OWASP standards by senior testers.

  3. 03

    Map to controls

    Every finding tied to the requirement or control it evidences.

  4. 04

    Report for the auditor

    Evidence formatted the way your assessor, examiner, or QSA expects to read it.

  5. 05

    Fix & retest

    A free retest so the audit shows closed findings, not open ones.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope customer information

    We map where customer information lives: CRM, portfolio and trading systems, the email tenant, cloud storage, and the providers that hold it for you.

  2. 02

    Test the safeguards

    External, internal, identity, and phishing testing against the technical safeguards the rule requires.

  3. 03

    Exercise the response

    Your team gets a timeline of our activity to check against what the incident response program detected.

  4. 04

    Report & retest

    A report written for the examination file, then a free retest of what you fix.

Fixed prices

What Regulation S-P testing costs

Published starting prices, fixed in writing before work begins. A typical adviser starts with the first three.

What it covers

External penetration test
VPN, portals, email, and everything else internet-facing
Microsoft 365 or Google Workspace review
MFA, conditional access, mailbox rules, and sharing in the email tenant
Phishing simulation
Operations, client service, and executive staff
Internal penetration test
The office network, from one compromised workstation
Cloud penetration test
AWS, Azure, or GCP accounts holding customer information

Price

External penetration test
From $4,200, free retest
Internal penetration test
From $6,000, free retest
Cloud penetration test
From $6,800, free retest

Every starting price is on our pricing page. Larger firms and multi-office estates are quoted from the scope, as one fixed price.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Post-Incident Web App Assessment

Medium risk

Excessive data exposure: API responses leaked transaction metadata, including precise geolocation, enabling real-world tracking of users.

Outcome. Surfaced the exposure and hardening gaps, prioritized by how readily an attacker could chain them, and delivered fixes plus a retest to confirm closure.

8

Findings

3

Medium

Post-incident

Engagement

Read the case study

Insurance

Email + Voice Social Engineering

A targeted credential-phishing email impersonating the company SSO password-reset flow led 19 employees to submit their credentials.

Outcome. Gave the security team a realistic multi-channel picture of susceptibility and a roadmap for help-desk identity-verification procedures and targeted training for high-exposure roles.

200

Email targets

19

Credential entries

2-channel

Attack simulated

Read the case study

FAQ

Frequently asked questions

What teams most often ask before Reg S-P testing.

Still have questions? 
01Does Regulation S-P require penetration testing?

Not by name. Rule 248.30 requires written administrative, technical, and physical safeguards reasonably designed to protect customer information and, since the 2024 amendments, an incident response program reasonably designed to detect, respond to, and recover from unauthorized access. Whether those are reasonably designed is what examiners assess. A penetration test with the fixes retested is the most direct evidence that the technical safeguards work and that you would detect an intrusion.

02Who has to comply with the amended Regulation S-P?

Covered institutions: broker-dealers, including funding portals, investment companies, investment advisers registered with the SEC, and transfer agents registered with the SEC or another appropriate regulatory agency. Larger entities had to comply by December 3, 2025 and smaller entities by June 3, 2026. A registered adviser counts as a larger entity with $1.5 billion or more in assets under management.

03What must the incident response program include?

Procedures to assess the nature and scope of an incident and identify the customer information systems and types of customer information involved, to contain and control it, and to notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. Notice goes out as soon as practicable and no later than 30 days after you become aware, unless a reasonable investigation finds the information has not been, and is not reasonably likely to be, used in a way that would result in substantial harm or inconvenience. The program must also include written policies for overseeing service providers.

04What does the rule require of our service providers?

Your policies must require oversight through due diligence and monitoring, and must be reasonably designed to ensure providers protect customer information and notify you as soon as possible, and no later than 72 hours, after becoming aware of a breach resulting in unauthorized access to a customer information system they maintain. A provider can send customer notices on your behalf under a written agreement, but the obligation stays with you. Fund administrators, custodians, CRM and portfolio platforms, and managed IT providers are the usual list.

05Is a penetration testing firm a service provider under Regulation S-P?

It can be, if the engagement gives it access to customer information. We plan for that in writing before testing starts: the rules of engagement set how proof of access to customer records is captured and kept to a minimum, evidence is handled through our platform rather than email, testing artifacts are destroyed on the schedule set in the engagement terms, and we tell you at once if testing reaches sensitive customer information. Put the same questions to any tester you consider, because your oversight policies apply to them too.

06Why does logging matter so much under the amendments?

Because it decides who you notify. If you cannot identify which individuals’ sensitive customer information was accessed, 248.30(a)(4)(ii) requires notice to everyone whose sensitive customer information resides in the affected system. Logs that show what an intruder touched let you narrow the notice to the people actually affected. A penetration test checks that the logs capture that activity before you need them to.

07Our funds are private funds. Does Regulation S-P apply?

To the adviser, if it is registered with the SEC. Private funds that rely on section 3(c)(1) or 3(c)(7) of the Investment Company Act are excluded from the definition of an investment company, so the funds themselves are not covered institutions, but their registered adviser is. Our page on penetration testing for private equity firms covers how a firm and its portfolio companies are scoped.

08Do NYDFS or FINRA add anything?

Often. A firm or affiliate operating under a New York DFS license also follows 23 NYCRR 500, which requires annual penetration testing from inside and outside the network boundary; see NYDFS 23 NYCRR 500 penetration testing. FINRA points member firms to Rule 30 of Regulation S-P in its cybersecurity guidance, and its 2026 oversight report lists tabletop exercises among effective practices. One test can be scoped and reported for all of them.

09How much does Regulation S-P testing cost?

A typical first engagement for an adviser combines an external penetration test from $4,200, a Microsoft 365 or Google Workspace review from $4,200, and a phishing simulation from $3,600, each fixed in writing before work begins. Firms with an office network add an internal test from $6,000, and firms holding customer data in AWS, Azure, or GCP add a cloud test from $6,800. Penetration tests include a free retest. Every starting price is on our pricing page.

Ready to test your defenses?

Talk to our team about what your Reg S-P compliance requires.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.