Reg S-P for private fund advisers, six months in
What is actually enforceable in a private fund manager's cyber program, and what examiners, LPs, insurers and attackers are asking for now.
A note from the founder
Since June 3, every SEC-registered adviser has been under amended Regulation S-P. Since then we have heard the same question from CFOs and compliance officers at private equity and venture firms: what actually applies to us, and what is noise?
This brief is our answer. It lists every Reg S-P and identity-theft enforcement case the SEC has brought since 2018, what examiners cite, what LPs and insurers now ask, and the attacks aimed at fund managers this year. Where the record is thin, we say so. No private fund adviser has been fined under Reg S-P yet, and anyone telling you otherwise is overselling.
What the record does show is consistent. The firms that ended up in an SEC order had real harm on top of basic gaps, and half of those cases began with email accounts taken over. The questions now coming from examiners, LPs and insurers all ask for the same thing: evidence about your environment, not a policy about it.
If this brief helps you answer those questions with more confidence, it has done its job.
Evidence, not policies
The SEC has not yet fined a private fund adviser under Reg S-P. The pressure is still real, and it comes from exams, LPs, insurers and attackers. All four ask for evidence, not policies.
Advisers with $1.5B or more under management had to comply by December 3, 2025, and everyone else by June 3, 2026. The rule requires a written incident response program, notice to affected individuals within 30 days, and service providers that report breaches to you within 72 hours.
You can skip notifying individuals only if "a reasonable investigation" shows the information is not reasonably likely to be misused. That investigation runs on logs, and Microsoft keeps many of them for only 7 to 30 days by default.
Every case since 2018 involved a broker-dealer or a dual broker-dealer and adviser. What they share is real harm on top of basic gaps: accounts taken over, MFA not enforced, red flags ignored for years.
The SEC's FY2026 priorities name Reg S-P incident response and identity-theft red flags "during customer account takeovers and fraudulent transfers." Never-examined and newly registered advisers go first.
ILPA's due diligence questionnaire asks for an annual independent, third-party cyber audit, and whether the firm or any portfolio company had a breach in the last five years. Most GPs answer both from memory.
What changed, 2023 to 2026
Three years of rule changes left one new obligation for registered advisers (Reg S-P) and took away two that never arrived. State breach laws kept tightening.
What is enforceable for your firm
Your obligations depend on registration status more than size. LP due diligence applies to everyone. Items marked INTERP. are readings of rule text to confirm with counsel.
How much of your data is in scope
Reg S-P protects information about individuals, not companies. A fund with individual investors, family trusts or family offices has more in scope than one whose LPs are all institutions. Subscription documents, tax forms and wire instructions are where that information usually sits, and much of it moves by email.
The enforcement record, read honestly
What the cases have in common
Four of the eight began with email accounts taken over. Each pairs real harm with basic controls missing or unevenly applied, often for years. None involved a single incident the firm found and fixed quickly.
Where enforcement is heading
Novel theories are out: SolarWinds was dismissed in November 2025. The enforcement director says the SEC is "not focused on prosecuting firms or individuals for honest mistakes that cause no investor harm." But plain controls cases continue. What you can show you did before an incident decides how it goes.
What examiners actually cite
SEC risk alerts from 2019 to 2026 cite the same gaps again and again. Few are about technology the firm lacks. Most are about controls that exist on paper and not in practice.
Policies copied from a template, not tailored to the firm.
Policies written but not implemented, trained or tested. A September 2026 alert cites an identity-theft policy whose required annual testing the annual review skipped.
MFA and access controls applied unevenly: at headquarters but not for remote staff or branches.
Email set up weakly or without full logging, which "resulted in account takeover or business email compromise" and left firms unable "to perform adequate incident response."
No inventory of where investor personal information lives.
Incident response plans without named roles or actions.
Vendor oversight on paper only.
Identity-theft red flags never updated, even at firms "that experienced ongoing account takeovers over several years."
Former employees keeping access.
The first-day document request
The standard exam request list asks for cybersecurity incidents and breaches, with a description, the impact and the remediation. A firm that has never looked for a compromise has nothing to put there except "none known."
Where the pressure really comes from
For most private fund managers, the first questions come from LPs and insurers, not the SEC. They apply whatever your registration status.
"Does the Firm have an annual independent, third-party audit of the Firm's cyber/information security policy and controls?"
"Has the Firm or any of its portfolio companies had any cyber breaches in the last five years?"
Insurers check what you attest
Carriers now require enforced MFA, endpoint detection and response, and third-party risk management. Claim disputes increasingly turn on whether MFA was actually enforced when the incident happened.
A questionnaire, an attestation or an application asks you to state a fact about your environment. The policy binder cannot answer it. Only the environment can.
The threat that turns a policy into an incident
The attacks that matter most to a GP go after people and email, not servers. Several are aimed at private equity this year, and the most dangerous survive a password reset.
In that campaign, callers phone employees, often on personal mobiles, under a pretext to update MFA enrollment, then register their own sign-in method and pull data from Microsoft 365 and Okta-connected apps. The same month, Apollo confirmed that a social engineering attack reached its cloud environment in July.
What survives a password reset
Resetting a password does not remove a stolen session token, an MFA method the attacker added, an app the attacker was granted, or an inbox rule hiding bank emails. A firm can have MFA on, a gateway in front of its mail and a clean policy review, and still have someone inside.
Only the tenant's own records show whether that is the case. Microsoft keeps sign-in and directory logs for 7 days on free Entra plans and 30 days on P1 or P2, and the unified audit log for 180 days on standard licenses. After that, the evidence a "reasonable investigation" needs is gone.
Six questions before your next DDQ or exam
If you can answer all six with a document or a log rather than a belief, your program is ahead of most.
1. Could we prove, today, that no one else is inside our email?
Not "we have MFA," but "we checked for inbox rules, forwarding, added sign-in methods and app grants, and here is the date and the result."
2. How long do our logs go back, and who would pull them?
If the answer is 7 or 30 days and "our IT provider, probably," the 30-day notice clock may run out before the evidence is found.
3. Is MFA enforced for everyone, on every sign-in path?
Include remote staff, shared mailboxes, older sign-in methods and the help desk's reset process.
4. Which vendors can reach our investor data, and will they tell us within 72 hours?
Fund administrator, IT provider, outsourced CCO, CRM and data room.
5. When did someone independent last test our controls?
An IT provider reviewing a tenant it configured is not independent.
6. Can we say the same about our portfolio companies?
Question 18.5 asks about them too, and so will the next buyer's diligence team.
How to check your own firm
You can start on question one this week without buying anything.
Run the self-check
Our free checklist, 7 signs your Microsoft 365 is already compromised, shows your IT lead where to look for each one. It takes an afternoon.
cloudskope.com/7-signsAsk for your outside view
Write to advisory@cloudskope.com, or reply to the email that brought you here. We will send a one-page read of your firm's email, built only from public records: look-alike domains, whether your domain can be spoofed, and how your mail is protected. No access, no call.
Preserve before you clean
If something looks wrong, preserve it first. Deleting a rule or resetting a password also removes evidence your notice decision may depend on.
Want the PDF for your partners?
The full brief as a 13-page PDF, formatted for an IC or compliance committee pack.
Reg S-P questions, answered
What is the Reg S-P compliance date?
Advisers with $1.5B or more under management had to comply with amended Reg S-P by December 3, 2025. Everyone else had to comply by June 3, 2026. Neither date was extended.
What does amended Reg S-P require?
A written incident response program, notice to affected individuals within 30 days of learning that their sensitive information was or was reasonably likely to be accessed without authorization, and service providers that notify you within 72 hours of a breach affecting your data.
Does Reg S-P apply to private equity and venture capital firms?
It applies to every SEC-registered investment adviser, private fund advisers included. Exempt reporting advisers are not covered, because the rule covers advisers "registered with the Commission." Our reading is that the FTC Safeguards Rule may apply to them instead; confirm with counsel.
When can a firm skip notifying individuals after a breach?
Only if a reasonable investigation shows the information is not reasonably likely to be misused. That investigation depends on logs, and Microsoft keeps sign-in logs for 7 days on free Entra plans and 30 days on P1 or P2 by default.
Has the SEC fined a private fund adviser under Reg S-P?
Not as of September 26, 2026. Every Reg S-P and Reg S-ID case since 2018 involved a broker-dealer or a dual registrant. The most recent, in November 2025, followed 17 email account takeovers.
Cloudskope is a security-only advisory firm based in Dallas, Texas. We run forensic audits of Microsoft 365 and Azure, cyber due diligence for deals, and a fixed-fee six-day assessment and remediation program for firms and their portfolio companies. We are independent of your IT provider and compliance consultant, and we work alongside both.
Since May 1, 2026, our forensic audits have prevented $2.2M in wire fraud, none of it flagged first by the client's IT team, managed service provider, bank or security tools.
Sources
All opened and checked on September 26, 2026. This brief is general information, not legal advice. Items marked as interpretation should be confirmed with counsel.
.png)