6 min read

Your Custodian, Your Clients, and the IRS Are Not Asking the Same Question

Your Custodian, Your Clients, and the IRS Are Not Asking the Same Question

"Financial services" is not one industry, and treating it as one is why most security advice aimed at it is useless.

An RIA answers to an examiner and a custodian. A CPA firm answers to the IRS and to a filing calendar that concentrates its entire year of risk into about ten weeks. An insurance agency answers to the carriers it represents, and holds client data it never actually asked for.

Same controls, mostly. Completely different reasons, different documents, and different moments when someone asks you to produce them.

So rather than write another piece about how financial firms should take security seriously, here is what each of the three is actually asked for, and what it means for what you should be spending.

The Part That Applies to All Three

Every firm holding client financial data is being evaluated by someone. Not hypothetically, and not by an attacker. By a party with paperwork and a schedule.

 

 Four parties reviewing a financial services firm's security. The examiner, whether SEC, FINRA, or a state regulator, asks for a written information security program, an incident response plan, and vendor due diligence records. The custodian, such as Schwab, Fidelity, or Pershing, asks for multi-factor authentication on every advisor login and controls around how client instructions get verified. The client asks where their data is stored and who else can see it. The carrier, covering cyber and errors and omissions, asks for the eight-control checklist on the renewal application with evidence.

The pattern worth noticing: all of them accept documentation, and none of them accept intent. You cannot answer any of these by describing how carefully your firm operates. Every one of them ends in a request for a specific artifact.

That is the gap we find most often. Not missing protection. Missing proof.

What Each Firm Type Is Actually Asked For

Three financial firm types and their different security obligations. RIA and wealth management firms face SEC or state exam cycles and custodian requirements, and need a written information security program, vendor due diligence file, MFA on advisor logins, and documented client instruction verification. CPA and accounting firms are required by the IRS to maintain a written security plan and handle enormous data volume in a ten-week window, needing a WISP, encrypted client file exchange, access controls on prior-year returns, and a tested restore before filing season. Insurance agencies answer to carrier appointments and state licensing, needing carrier data handling compliance, a retention and disposal policy, email security on quote traffic, and access review across producers.

 

If you run an RIA

Your obligation is the most predictable of the three, which is genuinely an advantage. Exams happen on a cycle, and the questions do not change much year to year.

The document that gets requested first is a written information security program. Not a folder of invoices from your IT provider. A document stating what you protect, how, who is responsible, and what happens when something goes wrong.

The second thing, and the one firms are least prepared for, is vendor due diligence. You are accountable for the security of every firm you hand client data to: your technology provider, your CRM, your portfolio management software, your document storage, your email. Most firms have never documented a single review of any of them.

Your custodian is a separate check, and a more immediate one. Schwab, Fidelity, and Pershing all have security requirements attached to advisor access, and unlike an examiner, a custodian can restrict access this week.

If you run a CPA firm

Your obligation is a written security plan, and it is not optional. The IRS requires one to maintain a PTIN, which means it applies to firms of every size, including sole practitioners.

The distinctive thing about your risk is not what you hold. It is when.

From late January through mid-April, and again in the weeks before September and October deadlines, your firm holds more sensitive data in active circulation than at any other point in the year, and it is the moment you can least afford to lose access to any of it. A three-day outage in June is an inconvenience. A three-day outage on April 10 is a different conversation with every client you have.

Which is why the single most valuable thing a CPA firm can do is unglamorous: test a full restore before filing season, not after. Confirm it works, write down the date, and keep the record. Most firms have backups. Very few have ever restored from them, and nobody wants to discover the difference during the busiest fortnight of the year.

If you run an insurance agency

Your obligations arrive from a direction the other two do not deal with: the carriers you represent. Appointments come with data handling requirements attached, and those requirements are contractual.

You also hold a category of data you did not choose to collect. Quote submissions come in with dates of birth, driver license numbers, medical history depending on the line, and property details. A lot of it belongs to people who never became clients, and it is still sitting in an inbox two years later.

That makes retention and disposal the question worth asking first. Not what are we protecting, but what are we still holding that we no longer need? Data you have deleted cannot be exposed, and no product on the market protects it more cheaply than that.

Where Financial Firms Overspend

Two patterns, consistently.

Governance platforms bought without a governance function. Enterprise compliance software is built for organizations with a compliance officer whose job is to feed it. A twelve-person RIA that buys one ends up with an expensive dashboard nobody updates, which is genuinely worse than a maintained spreadsheet because it creates the appearance of a control that is not actually being exercised.

Monitoring without response. Around-the-clock alerting produces alerts. Alerts create value only when someone is positioned to act on them. If nobody at your firm is on call at 2 a.m. and there is no documented escalation path, you have bought a notification.

Both products are real and both eventually make sense. At most firm sizes in this market, neither is the next dollar you should spend.

Where Financial Firms Underspend

Verification procedure on money movement.

The realistic loss event at a financial firm is not a sophisticated intrusion. It is a client instruction that was not actually from the client. An email about a wire, arriving at a plausible moment, from an address one character off from a real one, or from a genuine client mailbox that someone else is reading.

What defeats it is procedural and nearly free: a verbal callback to a number you already had on file before the request arrived, for every change to payment instructions, with no exceptions for good clients or urgent timelines. Write it down, make it a rule, and apply it when it is inconvenient. That is the entire control.

Alongside it: email authentication so your domain cannot be convincingly spoofed, and filtering that catches lookalike domains. Neither is expensive. Both get skipped in favor of products that demo better.

Right-Sizing Applies Here Too

None of this is an argument to buy everything.

We sort security into three tiers, and where a firm belongs is set by its obligations rather than its budget. Secured is the floor for any business: firewall, multi-factor authentication, endpoint protection, offsite backup, email security. Insured adds what carriers now require: training with completion records, password management, managed detection, advanced email protection. Compliant adds centralized logging, formal governance, and documentation, and it makes sense when somebody outside your firm can compel you to produce proof on their timeline.

Most financial firms we look at sit at Insured and belong there, while paying for pieces of Compliant they cannot use.

The full framework is in our security spending guide, Overpaid and Underprotected, including what actually moves a firm up a tier.

Can You See What You Are Paying For?

Here is the awkward part underneath all of it.

Most firms get one bundled line on the invoice. Something like "security and compliance." The number moves occasionally and nobody can explain why, because nobody can see inside it.

That means you cannot tell whether you are paying for the tier you are actually in, whether two products are doing the same job because one was added years ago and never removed, or whether the user count still matches your headcount after turnover.

We itemize every component with a monthly report behind it. Not generosity. A client who can see what they are buying makes better decisions.

If your provider cannot produce a line-item breakdown of your security spend within a day, that is the finding. You do not need to understand endpoint detection to know that is a problem.


Frequently Asked Questions

Does an RIA need a written information security program?

Yes. SEC and state examiners expect registered advisors to maintain written policies and procedures covering information security, and the written program is typically the first document requested in an exam. A collection of invoices from an IT provider does not satisfy it. The document should state what data you protect, what safeguards are in place, who is responsible, and what happens during an incident.

Do CPA firms have to have a written security plan?

Yes. The IRS requires tax professionals to maintain a written information security plan as a condition of holding a PTIN, which applies to firms of every size including sole practitioners. The requirement is not scaled away for small firms, though the plan itself should be proportionate to the size and complexity of the practice.

What security do custodians like Schwab and Fidelity require from advisors?

Custodian requirements vary but consistently include multi-factor authentication on advisor access, controls around how client instructions are verified before funds move, and increasingly, attestations about the firm's broader security posture. Custodian requirements matter more urgently than examiner requirements for a practical reason: a custodian can restrict access far faster than a regulator can act.

How do financial firms prevent wire fraud?

The most effective control is procedural, not technical: a verbal callback to a phone number already on file, made before executing any change to payment instructions, applied without exception. Supporting technical controls include email authentication so the firm's domain cannot be spoofed and filtering that catches lookalike domains. This combination costs very little and addresses the way losses actually occur.

How long should an insurance agency keep quote data?

Longer than most agencies realize they are keeping it, and shorter than they actually do. State requirements and carrier agreements set the floor, and agencies should document a retention and disposal policy that meets both. The practical point is that quote submissions contain sensitive personal data from people who never became clients, and data that has been properly disposed of cannot be exposed.


Find Out Which Tier You Are Actually In

Ninety-second version: take the three-question self-check. No email required to see your result.

Longer version: send us your cyber policy or your most recent renewal application, whichever you have handy. A client or custodian security questionnaire works too. We will tell you which of those controls your firm can actually prove today, which ones you cannot, and which tier you are genuinely operating at. Send your IT invoice along with it if you want us to check whether your spend matches your tier, though that part is optional.

No charge. No meeting required. Five business days.

Request a Security Stack Review

Four Winds IT is a technology company serving 300+ businesses across Southwest Florida, headquartered right here in Sarasota. Call us at (941) 315-2380 and an engineer picks up.

The Case You Can’t Afford to Lose: Better IT Support for Law Firms

1 min read

The Case You Can’t Afford to Lose: Better IT Support for Law Firms

Running a law firm means every minute counts. Yet too many firms still fight with slow systems, misplaced documents, and downtime that chips away at...

Explore More Four Winds Insights
Law firm cybersecurity requirements: The Eight Security Questions on Your Renewal Application

1 min read

Law firm cybersecurity requirements: The Eight Security Questions on Your Renewal Application

There is a moment that happens in a lot of law firms around renewal time. The cyber insurance application comes in, it is longer than last year, and...

Explore More Four Winds Insights
Your Staff Is Already Using AI With Privileged Client Files.

1 min read

Your Staff Is Already Using AI With Privileged Client Files.

I’m going to tell you something most managing partners don’t want to hear: your associates and paralegals are already using AI with privileged client...

Explore More Four Winds Insights