January feels like a long time ago.
Most RIAs started the year with a plan. Maybe you wanted to strengthen cybersecurity, improve compliance processes, review vendors, or finally update some documentation that had been sitting on your to-do list.
Then the year got busy.
Clients needed attention. Markets moved. New technology was added. Employees changed roles. New vendors came onboard. And somewhere in the middle of all that activity, your firm evolved.
The question is whether your cybersecurity, compliance, and operational processes evolved with it.
By the middle of the year, many advisory firms are operating on assumptions. They assume only the right people have access to client information. They assume their vendors are secure. They assume their backups work. They assume their documentation still reflects reality.
Unfortunately, assumptions have a way of becoming findings during examinations and problems during cybersecurity incidents.
A mid-year review is a simple way to make sure your firm is still operating the way you think it is.
1. Who Has Access to Client Information Today?
When a new employee joins the firm, access is usually granted quickly. The same thing happens when someone changes roles or needs temporary access to complete a project.
What rarely happens is a review afterward.
Over time, permissions accumulate. Employees keep access they no longer need. Administrative rights get handed out for convenience. Former vendors or contractors may still have accounts that should have been removed months ago.
For RIAs, this isn’t just an IT issue. It’s a client data protection issue.
Take a few minutes to ask:
- Who has access to sensitive client information?
- Who can access custodial platforms?
- Who has administrator privileges?
- When was the last formal access review?
If the answers aren’t immediately clear, now is a good time to take a closer look.
2. Have New Technology Tools Created New Risks?
Most technology decisions are made with good intentions.
A new CRM improves efficiency. A planning platform improves the client experience. A marketing tool helps support growth. A new vendor solves a problem that was slowing the team down.
Individually, those decisions make sense.
Collectively, they can create complexity that nobody fully owns.
Client data starts living in more places. Integrations are configured and forgotten. Different systems collect overlapping information. Before long, it becomes difficult to answer a simple question:
Where does our sensitive client information actually live?
This is an important conversation for both compliance and cybersecurity purposes.
Ask yourself:
- What systems contain client information?
- Which vendors have access to that information?
- Are all those vendors still approved and documented?
- Do we know how data moves between systems?
Technology should make your firm more efficient, not harder to understand.
3. Are You Confident Your Firm Could Recover From an Incident?
Most firms have backups.
That isn’t the same thing as having a recovery plan.
Whether it’s ransomware, accidental deletion, a vendor outage, or a cybersecurity incident, the real question is how quickly your firm could return to normal operations.
Many firms discover they don’t know the answer until they’re in the middle of a crisis.
A mid-year review is a good time to revisit:
- When were backups last tested?
- How long would recovery actually take?
- Who is responsible for managing the process?
- How would clients be informed if necessary?
- What systems would be restored first?
The firms that recover fastest are rarely the firms with the most technology. They’re usually the firms that have tested their process before they need it.
4. Does Everyone Know Who Owns What?
As firms grow, responsibilities often become less clear.
The CCO assumes IT is handling something. IT assumes the vendor is handling it. The vendor assumes the firm is handling it.
Meanwhile, nobody is actually responsible.
I’ve seen this happen with vendor reviews, user access management, incident response planning, employee training, and business continuity testing.
Everything appears covered until someone asks a simple question:
“Who owns this?”
If the answer isn’t obvious, that’s a risk worth addressing.
Every RIA should have clear ownership for:
- Cybersecurity oversight
- Vendor due diligence
- User access reviews
- Incident response planning
- Business continuity testing
- Employee security awareness training
When responsibilities are clear, problems get solved faster and important tasks don’t fall through the cracks.
Most Risk Doesn’t Come From What’s Broken
Most risk comes from what changed and never got revisited.
The firm grows. Technology changes. Employees come and go. Vendors are added. New processes are created.
But policies, procedures, and oversight often stay exactly the same.
That’s where gaps begin to appear.
The RIAs that stay ahead of compliance and cybersecurity challenges aren’t necessarily doing anything complicated. They simply make time to periodically step back and confirm that reality still matches their assumptions.
They know who has access to what.
They understand where client information lives.
They know their backups work.
And they know who is responsible when something needs attention.
That clarity creates confidence.
A Simple Mid-Year Review Can Prevent a Year-End Problem
Whether you’re a state-registered RIA preparing for your next examination or an SEC-registered firm focused on Regulation S-P readiness, now is the perfect time to review the systems, processes, and vendors your firm relies on every day.
A short conversation today can uncover risks that have quietly developed over the past six months and help ensure your firm enters the second half of the year secure, compliant, and prepared.
If you’d like a second set of eyes on your cybersecurity, compliance readiness, or technology environment, we’d be happy to help.
Because peace of mind comes from knowing your firm is protected—not assuming it is.
Let us ease your mind by a quick 27-minute call here.

