Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Incident response strategies: meeting the SEC’s new requirements (Page 7)
Cyber resilience

Incident response strategies: meeting the SEC’s new requirements

Christian Scott explains how firms can develop a comprehensive incident response plan that meets the new requirements of the US Security and Exchange Commission (SEC) amendments to Regulation S-P.
August 1, 20245 Mins Read
The logo of the U.S. Securities and Exchange Commission (SEC) is seen at its headquarters in Washington, DC.

For organizations in the financial services sector, a robust incident response strategy is essential. Approaches have evolved significantly with the widespread adoption of public cloud solutions and the transition to hybrid work environments.

The attack methods that criminals employ, such as third-party supply chain attacks, MFA bypass attacks, and AI-driven voice impersonation, have grown more sophisticated, placing strain on companies’ cyber defenses. These advanced threats, combined with the shift in workplace technologies, expose the limitations of traditional security approaches that focus on securing the network perimeter.

Security incidents are a constant risk in the complex technological and threat environments that financial firms inhabit. When these incidents occur, firms must be ready to identify, contain, and mitigate them rapidly.

That may always have been true, but changes in regulation have given financial firms added impetus to draft and adopt even more effective response strategies. The primary stimulus is the US Security and Exchange Commission (SEC) amendments to Regulation S-P, which oversees the handling of non-public personal information by financial institutions.

These amendments reinforce the need for comprehensive measures to protect customer data, mandating that financial institutions notify affected individuals within 30 days if their sensitive information is accessed or used without authorisation. Additionally, firms are required to develop and maintain written policies for an incident response programme that detects, responds to, and recovers from unauthorised access to customer information.

Incident response strategies must go beyond the basics

With such stringent regulations hanging over them, financial services companies, particularly alternative investment firms, must adopt an advanced incident response strategy. This strategy should go beyond basic measures, assuming the network perimeter is not secure, and address modern threats such as business email compromise (BEC) attacks.

To comply with the SEC Regulation S-P amendments and prepare for the near-inevitable additional regulatory changes coming down the line, the first step is to develop a comprehensive incident response plan that matches up to the requirements of new and existing rules equally well. This plan should detail procedures for detecting, responding to, and recovering from security incidents, including protocols for assessing and containing incidents, enforcing data retention policies, and overseeing service providers.

Clear documentation and communication of these procedures should ensure that all team members understand their roles and responsibilities during an incident, minimising confusion and delays. Regular incident response tabletop exercises, social engineering testing, and ransomware simulation tests are essential for an effective incident response program that can quickly detect and contain modern cyber threats.

Improve end-user awareness of AI-based threats

Continuous threat detection and response across endpoints, cloud systems, and traditional network infrastructure is critical for early identification and rapid reactions that effectively contain malicious actors attempting to breach company systems. Enhanced end-user security awareness, including training on the latest malicious techniques such as generative AI voice impersonation and other sophisticated social engineering tactics, is crucial to ensure the organization responds with maximum impact when confronting modern threats.

Where there are significant budgetary constraints, firms should use free resources from agencies such as the Cybersecurity and Infrastructure Security Agency (CISA) and the Center for Internet Security (CIS) in the US, or the European Union Agency for Cybersecurity (ENISA) in the EU. These resources provide valuable materials for creating incident response plans and performing security assessments. Additionally, collaborating with industry peers and participating in information-sharing initiatives can offer insights and best practice guides to enhance incident response capabilities and ensure compliance with evolving data protection requirements.

It is always important to be fully informed on regulatory requirements. Financial institutions need to keep up with both regional and international regulations. The European Union, for example, has comprehensive incident response and breach notification rules coming into effect in 2025. The SEC’s recent amendments may influence other regions, including the EU, to adopt similar regulations, making it essential for firms to stay ahead of these developments.

Changes to IT demand updated incident response strategies

Maintaining an effective incident response strategy requires continuous improvement. Incident response plans should be regularly updated and tested, especially when there are significant changes to the company’s technology systems. Partnering with a cybersecurity expert can help ensure these plans are robust, up-to-date, and are actionable.

The changes to Regulation S-P will no doubt achieve the SEC’s aim of strengthening data security within the financial sector. By adopting what has become best practice and staying very well-informed about the constantly morphing sets of regulations that govern them, firms can protect sensitive customer information and reduce the impact of security incidents.

Achieving effective incident response increasingly depends on adaptability, continuous improvement, and constant vigilance. As the SEC sets new standards, it is likely that other regions, including the EU, will follow suit. This should remind us of the global importance of a robust and consistent approach to managing the current and emerging threats the financial sector is constantly up against.

The author

Christian Scott is Chief Operating Officer (COO) of Gotham Security, an Abacus Group company.

North America
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleMany organizations cannot meet recovery time objectives after ransomware attacks
Next Article Anticipate, absorb, adapt: the ‘Triple A’ of resilience

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

July 9, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?