2023-03-15 SEC Press pdf 260 KB 6,363 chars

Advisers and funds play an important role in our financial markets and increasingly depend

summary

The U.S. SEC proposed new cybersecurity rules to require investment advisers and funds to adopt risk management policies, report significant incidents via Form ADV-C, and improve investor disclosures—no fraud or charges are alleged, as this is a regulatory initiative to enhance systemic protection and transparency.

paragraph

The U.S. Securities and Exchange Commission proposed new rules under the Advisers Act and Investment Company Act to strengthen cybersecurity preparedness among investment advisers and funds. These rules mandate written policies addressing cyber risks, require reporting of significant incidents on a new Form ADV-C, and enhance disclosures to clients and shareholders about cybersecurity exposures and past incidents. The proposal also introduces recordkeeping requirements to ensure accountability, with no enforcement actions or monetary penalties involved—only regulatory enhancements to protect investors and assess systemic risks.

narrative

The U.S. Securities and Exchange Commission (SEC) proposed new cybersecurity risk management rules to address growing concerns about the sector’s reliance on interconnected technology systems and third-party vendors. The proposal requires investment advisers and funds to adopt and implement written policies reasonably designed to mitigate cybersecurity risks, including those that could lead to unauthorized access to client data or operational failures. Advisers must report significant cybersecurity incidents to the SEC via a new Form ADV-C, enabling better monitoring of systemic threats and investor protection. The rules also amend Form ADV Part 2A and several fund registration forms to mandate clear, standardized disclosures about cybersecurity risks and incidents occurring within the past two fiscal years. Additionally, advisers and funds must maintain and retain detailed records of their cybersecurity policies, procedures, and incident responses under updated books and records requirements. The SEC aims to improve transparency, strengthen industry-wide resilience, and enhance its oversight capacity—not to punish fraud, as no individual or entity is accused of wrongdoing. The initial comment period closed in 2022 and was reopened in March 2023 to gather further public input, with the proposal still under review as of the document’s issuance.

Enriched metadata

Scheme
non-corporate (99%)
Classified non-corporate(confidence 99%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Statutes
rule 38a-2rule 204-6Rule 204-2
Parties
cybersecurity preparednessSecurities and Exchange Commission
Keywords
cybersecurityadvisersadvisers fundscybersecurity risksfundsriskscybersecurity riskrisk managementcybersecurity incidentsincidentsform formproposedformcommissionfund

Extracted insights

Entities 2
  • person cybersecurity preparedness
  • agency Securities and Exchange Commission
Triples 13
  • U.S. Securities And Exchange Commission is proposing new cybersecurity risk management rules
  • U.S. Securities And Exchange Commission is proposing related amendments to certain rules under the Investment Advisers Act of 1940
  • U.S. Securities And Exchange Commission is proposing related amendments to certain rules under the Investment Company Act of 1940
  • Proposed rules would enhance cybersecurity preparedness
  • Proposed rules would improve resilience of investment advisers and investment companies against cybersecurity threats and attacks
  • Advisers are required to adopt written policies and procedures
  • Funds are required to adopt written policies and procedures
  • Advisers are required to report significant cybersecurity incidents to the Commission
  • Advisers are required to submit new Form ADV-C
  • Advisers are required to maintain cybersecurity-related books and records
  • Funds are required to maintain cybersecurity-related books and records
  • Proposed cybersecurity risk management rules would require advisers and funds to adopt and implement policies and procedures
  • New rule 204-6 would require advisers to report significant cybersecurity incidents to the Commission
Text layers
Extracted body text (6,363c)
Warning: TT: undefined function: 32

FACT SHEET
Cybersecurity Risk
Management

U.S. SECURITIES AND EXCHANGE COMMISSION  PAGE 1 OF 2

Background
Advisers and funds play an important role in our financial markets and increasingly depend
on technology for critical business operations.  Advisers and funds are exposed to, and rely
on, a broad array of interconnected systems and networks, both directly and through service
providers  such  as  custodians,  brokers,  dealers,  pricing  services,  and  other  technology
vendors.    As  a  result,  they  face  numerous  cybersecurity  risks  and  may  experience
cybersecurity  incidents  that  can  cause,  or  be  exacerbated  by,  critical  system  or  process
failures.
The Commission is concerned about the efficacy of adviser and fund practices industry-wide
to  address  cybersecurity  risks  and  incidents,  and  that  less  robust  cybersecurity practices
may not adequately address investor protection concerns.  There is also concern about the
effectiveness of   disclosures   to   advisory   clients   and   fund   shareholders   concerning
cybersecurity risks and incidents.  The Commission’s proposed rules and amendments are
designed to address concerns about advisers’ and funds’ cybersecurity preparedness and
reduce cybersecurity-related risks to clients and investors; to improve the disclosures clients
and   investors   receive   about   advisers’   and   funds’   cybersecurity   exposures   and   the
cybersecurity incidents that occur at advisers and funds; and to enhance the Commission’s
ability to assess systemic risks and its oversight of advisers and funds.

Proposed Amendments
Cybersecurity Risk Management Rules
The proposal includes new rule 206(4)-9 under the Advisers Act and new rule 38a-2 under
the  Investment  Company  Act  (collectively,  the “proposed  cybersecurity  risk  management

The Commission is proposing new cybersecurity risk management rules and related
amendments to certain rules under the Investment Advisers Act of 1940 (the “Advisers Act”)
and the Investment Company Act of 1940 (the “Investment Company Act”). The proposed rules
and amendments would enhance cybersecurity preparedness and improve the resilience of
investment advisers and investment companies against cybersecurity threats and attacks by:
●    Requiring advisers and funds to adopt and implement written policies and
procedures that are reasonably designed to address cybersecurity risks;
●    Having advisers report significant cybersecurity incidents to the Commission on
proposed Form ADV-C;
●    Enhancing adviser and fund disclosures related to cybersecurity risks and
incidents; and
●    Requiring advisers and fund to maintain, make, and retain certain cybersecurity-
related books and records.

FACT SHEET | Cybersecurity Risk Management
U.S. SECURITIES AND EXCHANGE COMMISSION  Page 2 of 2
rules”).    The  proposed  cybersecurity  risk  management  rules  would  require  advisers  and
funds  to  adopt  and  implement  policies  and  procedures  that  are  reasonably  designed  to
address cybersecurity risks.  The proposed rules enumerate certain general elements that
advisers  and  funds  would  be  required  to  address  in  their  cybersecurity  policies  and
procedures.  These policies and procedures would help address operational and other risks
that could harm advisory clients and fund investors or lead to the unauthorized access to or
use  of  adviser  or  fund  information,  including  the  personal  information  of  their  clients  or
investors.
Reporting of Significant Cybersecurity Incidents
The proposal also includes a reporting requirement under new rule 204-6 that would require
advisers to report significant cybersecurity incidents to the Commission, including on behalf
of a fund or private fund client.  The adviser would have to report by submitting a new Form
ADV-C.    These confidential reports  would  bolster  the  efficiency  and  effectiveness  of  the
Commission’s efforts to protect investors by helping the Commission monitor and evaluate
the effects of a cybersecurity incident on an adviser and its clients, as well as assess the
potential systemic risks affecting financial markets more broadly.
Disclosure of Cybersecurity Risks and Incidents
Currently,  advisers  provide  disclosures  to  their  prospective  and  current  clients  on  Form
ADV’s  narrative  brochure,  or  Part  2A,  which  is  publicly  available  and  one  of  the  primary
client-facing  disclosure  documents used  by  advisers.    Form  ADV  Part  2A  contains
information  about  the  investment  adviser’s  business  practices,  fees,  risks,  conflicts  of
interest, and disciplinary information.  The proposal includes amendments to Form ADV Part
2A  to  require  disclosure  of  cybersecurity  risks  and  incidents  to  an  adviser’s  clients  and
prospective clients.
Like advisers, funds would also be required to provide prospective and current investors with
cybersecurity-related  disclosures.    More  specifically,  the proposed  amendments  would
require a description of any significant fund cybersecurity incidents that has occurred in the
last two fiscal years in    funds’ registration statements, tagged in a structured data language.
The proposal includes amendments to Form N-1A, Form N-2, Form N-3, Form N-4, Form N-
6, Form N-8B-2, and Form S-6.
Recordkeeping
The  proposal also includes  new  recordkeeping  requirements  under  the  Advisers  Act  and
Investment Company Act. Rule 204-2, the books and records rule, under the Advisers Act
sets forth requirements for maintaining, making, and retaining books and records relating to
an adviser’s investment advisory business.  The proposal would amend this rule to require
advisers to maintain certain records related to the proposed cybersecurity risk management
rules and the occurrence of cybersecurity incidents.
Similarly, proposed rule 38a-2 under the Investment Company Act would require that a fund
maintain  copies  of  its  cybersecurity  policies  and  procedures  and  other  related  records
specified under the proposed rule.

Additional Information:
The initial comment period closed on April 11, 2022. The comment period was reopened on March 15, 2023, and
will remain open until 60 days after the date of publication of the reopening release in the Federal Register.
OCR text (6,277c · tika · 95% conf)
FACT SHEET 
Cybersecurity Risk 
Management  

 

U.S. SECURITIES AND EXCHANGE COMMISSION  PAGE 1 OF 2 

 

Background 
Advisers and funds play an important role in our financial markets and increasingly depend 
on technology for critical business operations.  Advisers and funds are exposed to, and rely 
on, a broad array of interconnected systems and networks, both directly and through service 
providers such as custodians, brokers, dealers, pricing services, and other technology 
vendors.  As a result, they face numerous cybersecurity risks and may experience 
cybersecurity incidents that can cause, or be exacerbated by, critical system or process 
failures. 

The Commission is concerned about the efficacy of adviser and fund practices industry-wide 
to address cybersecurity risks and incidents, and that less robust cybersecurity practices 
may not adequately address investor protection concerns.  There is also concern about the 
effectiveness of disclosures to advisory clients and fund shareholders concerning 
cybersecurity risks and incidents.  The Commission’s proposed rules and amendments are 
designed to address concerns about advisers’ and funds’ cybersecurity preparedness and 
reduce cybersecurity-related risks to clients and investors; to improve the disclosures clients 
and investors receive about advisers’ and funds’ cybersecurity exposures and the 
cybersecurity incidents that occur at advisers and funds; and to enhance the Commission’s 
ability to assess systemic risks and its oversight of advisers and funds.   

 

Proposed Amendments 
Cybersecurity Risk Management Rules 

The proposal includes new rule 206(4)-9 under the Advisers Act and new rule 38a-2 under 
the Investment Company Act (collectively, the “proposed cybersecurity risk management 

 
The Commission is proposing new cybersecurity risk management rules and related 
amendments to certain rules under the Investment Advisers Act of 1940 (the “Advisers Act”) 
and the Investment Company Act of 1940 (the “Investment Company Act”). The proposed rules 
and amendments would enhance cybersecurity preparedness and improve the resilience of 
investment advisers and investment companies against cybersecurity threats and attacks by:  

● Requiring advisers and funds to adopt and implement written policies and 
procedures that are reasonably designed to address cybersecurity risks;  

● Having advisers report significant cybersecurity incidents to the Commission on 
proposed Form ADV-C;    

● Enhancing adviser and fund disclosures related to cybersecurity risks and 
incidents; and 

● Requiring advisers and fund to maintain, make, and retain certain cybersecurity-
related books and records. 

 



FACT SHEET | Cybersecurity Risk Management  

U.S. SECURITIES AND EXCHANGE COMMISSION  Page 2 of 2 

rules”).  The proposed cybersecurity risk management rules would require advisers and 
funds to adopt and implement policies and procedures that are reasonably designed to 
address cybersecurity risks.  The proposed rules enumerate certain general elements that 
advisers and funds would be required to address in their cybersecurity policies and 
procedures.  These policies and procedures would help address operational and other risks 
that could harm advisory clients and fund investors or lead to the unauthorized access to or 
use of adviser or fund information, including the personal information of their clients or 
investors. 

Reporting of Significant Cybersecurity Incidents  

The proposal also includes a reporting requirement under new rule 204-6 that would require 
advisers to report significant cybersecurity incidents to the Commission, including on behalf 
of a fund or private fund client.  The adviser would have to report by submitting a new Form 
ADV-C.  These confidential reports would bolster the efficiency and effectiveness of the 
Commission’s efforts to protect investors by helping the Commission monitor and evaluate 
the effects of a cybersecurity incident on an adviser and its clients, as well as assess the 
potential systemic risks affecting financial markets more broadly.   

Disclosure of Cybersecurity Risks and Incidents 

Currently, advisers provide disclosures to their prospective and current clients on Form 
ADV’s narrative brochure, or Part 2A, which is publicly available and one of the primary 
client-facing disclosure documents used by advisers.  Form ADV Part 2A contains 
information about the investment adviser’s business practices, fees, risks, conflicts of 
interest, and disciplinary information.  The proposal includes amendments to Form ADV Part 
2A to require disclosure of cybersecurity risks and incidents to an adviser’s clients and 
prospective clients.   

Like advisers, funds would also be required to provide prospective and current investors with 
cybersecurity-related disclosures.  More specifically, the proposed amendments would 
require a description of any significant fund cybersecurity incidents that has occurred in the 
last two fiscal years in funds’ registration statements, tagged in a structured data language.  
The proposal includes amendments to Form N-1A, Form N-2, Form N-3, Form N-4, Form N-
6, Form N-8B-2, and Form S-6.   

Recordkeeping 

The proposal also includes new recordkeeping requirements under the Advisers Act and 
Investment Company Act. Rule 204-2, the books and records rule, under the Advisers Act 
sets forth requirements for maintaining, making, and retaining books and records relating to 
an adviser’s investment advisory business.  The proposal would amend this rule to require 
advisers to maintain certain records related to the proposed cybersecurity risk management 
rules and the occurrence of cybersecurity incidents.   

Similarly, proposed rule 38a-2 under the Investment Company Act would require that a fund 
maintain copies of its cybersecurity policies and procedures and other related records 
specified under the proposed rule. 

 

Additional Information: 

The initial comment period closed on April 11, 2022. The comment period was reopened on March 15, 2023, and 
will remain open until 60 days after the date of publication of the reopening release in the Federal Register. 


	Background
	Proposed Amendments
	Additional Information: