For organizations in the financial services sector, a robust incident response strategy is essential. Approaches have evolved significantly with the widespread adoption of public cloud solutions and the transition to hybrid work environments.
The attack methods that criminals employ, such as third-party supply chain attacks, MFA bypass attacks, and AI-driven voice impersonation, have grown more sophisticated, placing strain on companies’ cyber defenses. These advanced threats, combined with the shift in workplace technologies, expose the limitations of traditional security approaches that focus on securing the network perimeter.
Security incidents are a constant risk in the complex technological and threat environments that financial firms inhabit. When these incidents occur, firms must be ready to identify, contain, and mitigate them rapidly.
That may always have been true, but changes in regulation have given financial firms added impetus to draft and adopt even more effective response strategies. The primary stimulus is the US Security and Exchange Commission (SEC) amendments to Regulation S-P, which oversees the handling of non-public personal information by financial institutions.
These amendments reinforce the need for comprehensive measures to protect customer data, mandating that financial institutions notify affected individuals within 30 days if their sensitive information is accessed or used without authorisation. Additionally, firms are required to develop and maintain written policies for an incident response programme that detects, responds to, and recovers from unauthorised access to customer information.
Incident response strategies must go beyond the basics
With such stringent regulations hanging over them, financial services companies, particularly alternative investment firms, must adopt an advanced incident response strategy. This strategy should go beyond basic measures, assuming the network perimeter is not secure, and address modern threats such as business email compromise (BEC) attacks.
To comply with the SEC Regulation S-P amendments and prepare for the near-inevitable additional regulatory changes coming down the line, the first step is to develop a comprehensive incident response plan that matches up to the requirements of new and existing rules equally well. This plan should detail procedures for detecting, responding to, and recovering from security incidents, including protocols for assessing and containing incidents, enforcing data retention policies, and overseeing service providers.
Clear documentation and communication of these procedures should ensure that all team members understand their roles and responsibilities during an incident, minimising confusion and delays. Regular incident response tabletop exercises, social engineering testing, and ransomware simulation tests are essential for an effective incident response program that can quickly detect and contain modern cyber threats.
Improve end-user awareness of AI-based threats
Continuous threat detection and response across endpoints, cloud systems, and traditional network infrastructure is critical for early identification and rapid reactions that effectively contain malicious actors attempting to breach company systems. Enhanced end-user security awareness, including training on the latest malicious techniques such as generative AI voice impersonation and other sophisticated social engineering tactics, is crucial to ensure the organization responds with maximum impact when confronting modern threats.
Where there are significant budgetary constraints, firms should use free resources from agencies such as the Cybersecurity and Infrastructure Security Agency (CISA) and the Center for Internet Security (CIS) in the US, or the European Union Agency for Cybersecurity (ENISA) in the EU. These resources provide valuable materials for creating incident response plans and performing security assessments. Additionally, collaborating with industry peers and participating in information-sharing initiatives can offer insights and best practice guides to enhance incident response capabilities and ensure compliance with evolving data protection requirements.
It is always important to be fully informed on regulatory requirements. Financial institutions need to keep up with both regional and international regulations. The European Union, for example, has comprehensive incident response and breach notification rules coming into effect in 2025. The SEC’s recent amendments may influence other regions, including the EU, to adopt similar regulations, making it essential for firms to stay ahead of these developments.
Changes to IT demand updated incident response strategies
Maintaining an effective incident response strategy requires continuous improvement. Incident response plans should be regularly updated and tested, especially when there are significant changes to the company’s technology systems. Partnering with a cybersecurity expert can help ensure these plans are robust, up-to-date, and are actionable.
The changes to Regulation S-P will no doubt achieve the SEC’s aim of strengthening data security within the financial sector. By adopting what has become best practice and staying very well-informed about the constantly morphing sets of regulations that govern them, firms can protect sensitive customer information and reduce the impact of security incidents.
Achieving effective incident response increasingly depends on adaptability, continuous improvement, and constant vigilance. As the SEC sets new standards, it is likely that other regions, including the EU, will follow suit. This should remind us of the global importance of a robust and consistent approach to managing the current and emerging threats the financial sector is constantly up against.
The author
Christian Scott is Chief Operating Officer (COO) of Gotham Security, an Abacus Group company.






