Landscape brief · Q4 2026 · For PE and VC CFOs, COOs and CCOs

Reg S-P for private fund advisers, six months in

What is actually enforceable in a private fund manager's cyber program, and what examiners, LPs, insurers and attackers are asking for now.

By Dipan Mann, Founder, CloudskopeUpdated September 26, 202612 minute readGeneral information, not legal advice
01 · Why we wrote this

A note from the founder

0
private fund advisers fined under Reg S-P or Reg S-ID to date
30 days
to notify affected individuals under amended Reg S-P
7 to 30
days of sign-in history Microsoft keeps by default
$3.05B
business email compromise losses reported to the FBI in 2025

Since June 3, every SEC-registered adviser has been under amended Regulation S-P. Since then we have heard the same question from CFOs and compliance officers at private equity and venture firms: what actually applies to us, and what is noise?

This brief is our answer. It lists every Reg S-P and identity-theft enforcement case the SEC has brought since 2018, what examiners cite, what LPs and insurers now ask, and the attacks aimed at fund managers this year. Where the record is thin, we say so. No private fund adviser has been fined under Reg S-P yet, and anyone telling you otherwise is overselling.

What the record does show is consistent. The firms that ended up in an SEC order had real harm on top of basic gaps, and half of those cases began with email accounts taken over. The questions now coming from examiners, LPs and insurers all ask for the same thing: evidence about your environment, not a policy about it.

If this brief helps you answer those questions with more confidence, it has done its job.

Dipan Mann
Founder, CEO & CTO, Cloudskope
02 · The short version

Evidence, not policies

The SEC has not yet fined a private fund adviser under Reg S-P. The pressure is still real, and it comes from exams, LPs, insurers and attackers. All four ask for evidence, not policies.

01
The rule is live and was not extended.

Advisers with $1.5B or more under management had to comply by December 3, 2025, and everyone else by June 3, 2026. The rule requires a written incident response program, notice to affected individuals within 30 days, and service providers that report breaches to you within 72 hours.

02
The one exception to notice needs evidence.

You can skip notifying individuals only if "a reasonable investigation" shows the information is not reasonably likely to be misused. That investigation runs on logs, and Microsoft keeps many of them for only 7 to 30 days by default.

03
No private fund adviser has been fined under Reg S-P or S-ID. Yet.

Every case since 2018 involved a broker-dealer or a dual broker-dealer and adviser. What they share is real harm on top of basic gaps: accounts taken over, MFA not enforced, red flags ignored for years.

04
Examiners are already looking.

The SEC's FY2026 priorities name Reg S-P incident response and identity-theft red flags "during customer account takeovers and fraudulent transfers." Never-examined and newly registered advisers go first.

05
LPs ask the harder question.

ILPA's due diligence questionnaire asks for an annual independent, third-party cyber audit, and whether the firm or any portfolio company had a breach in the last five years. Most GPs answer both from memory.

03 · What changed

What changed, 2023 to 2026

Three years of rule changes left one new obligation for registered advisers (Reg S-P) and took away two that never arrived. State breach laws kept tightening.

Date
Change
What it means for a GP
Sept 2, 2026
Change
Delaware HB 381: earlier notice to the attorney general; narrower safe harbor for GLBA-regulated firms
What it means for a GP
Turns on where affected people live, not where the fund is domiciled
Sept 2026
Change
CISA's CIRCIA reporting rule targeted for September; not published as of Sept 26
What it means for a GP
Aimed at critical infrastructure. Some portfolio companies may be covered, not the adviser
June 3, 2026
Change
Reg S-P compliance date, advisers under $1.5B
What it means for a GP
Incident response program, 30-day notice and 72-hour vendor notice now apply
Jan 1, 2026
Change
California SB 446: notify residents within 30 calendar days
What it means for a GP
Any GP with California LPs or employees
Dec 3, 2025
Change
Reg S-P compliance date, advisers with $1.5B or more
What it means for a GP
Same obligations, six months earlier
Nov 1, 2025
Change
Final phase of NYDFS Part 500: MFA for anyone accessing any information system
What it means for a GP
Only if the firm or an affiliate holds a New York DFS license
Sept 1, 2025
Change
Texas SB 2610: firms under 250 employees with a recognized framework are shielded from punitive damages in breach suits
What it means for a GP
A reason for Texas GPs and portfolio companies to document a NIST or CIS program
June 17, 2025
Change
SEC withdrew the proposed adviser cybersecurity rule, 206(4)-9
What it means for a GP
It is not coming. Reg S-P is the live rule
June 5, 2024
Change
Fifth Circuit vacated the Private Fund Adviser Rules
What it means for a GP
Does not touch Reg S-P, Reg S-ID or the compliance rule
May 16, 2024
Change
SEC adopted the Reg S-P amendments
What it means for a GP
Applies to every SEC-registered adviser, private fund advisers included
May 13, 2024
Change
FTC Safeguards Rule: notify the FTC within 30 days of a breach involving 500+ consumers
What it means for a GP
Names advisers "not required to register with the SEC," which counsel read to include exempt reporting advisers
Dec 18, 2023
Change
SEC Form 8-K Item 1.05: public companies disclose material cyber incidents in four business days
What it means for a GP
Matters for portfolio companies heading to an IPO
04 · What applies

What is enforceable for your firm

Your obligations depend on registration status more than size. LP due diligence applies to everyone. Items marked INTERP. are readings of rule text to confirm with counsel.

Firm type
Reg S-P (amended)
Reg S-ID
FTC Safeguards
SEC exams
LP DDQ
SEC-registered, $1.5B or more
Reg S-P (amended)
Yes, since Dec 3, 2025
Reg S-ID
Yes, if you can direct an individual investor's distributions to a third party
FTC Safeguards
No; the SEC regulates you
SEC exams
Incident response, account-takeover red flags, vendor oversight
LP DDQ
Yes
SEC-registered, under $1.5B
Reg S-P (amended)
Yes, since June 3, 2026
Reg S-ID
Same test
FTC Safeguards
No
SEC exams
Never-examined and newly registered go first
LP DDQ
Yes
Exempt reporting adviser
Reg S-P (amended)
No; covers advisers "registered with the Commission"
Reg S-ID
No
FTC Safeguards
Yes by rule text, to the extent you hold consumer information INTERP. MFA and FTC notice apply even to small firms
SEC exams
Limited; no routine Reg S-P exams
LP DDQ
Yes
State-registered adviser
Reg S-P (amended)
No
Reg S-ID
No
FTC Safeguards
Yes by rule text INTERP.
SEC exams
State examiners instead
LP DDQ
If raising from institutions

How much of your data is in scope

Reg S-P protects information about individuals, not companies. A fund with individual investors, family trusts or family offices has more in scope than one whose LPs are all institutions. Subscription documents, tax forms and wire instructions are where that information usually sits, and much of it moves by email.

05 · The record

The enforcement record, read honestly

0
cases against a private fund adviser, 2018 to Sept 2026
$325K
the most recent order, Nov 2025, after 17 email takeovers
$35M
the largest pure Reg S-P penalty, for customer data left on resold drives
Date
Firm
What happened
Penalty
Nov 25, 2025
Firm
M Holdings Securities
What happened
17 email account takeovers over five years exposed about 8,500 people; one led to an unauthorized wire. Offices that were hit lacked controls such as MFA.
Penalty
$325,000
Jan 13, 2025
Firm
Robinhood
What happened
Identity-theft program failures and an unaddressed remote-access weakness, within a wider settlement
Penalty
$45M total, all violations
Sept 20, 2022
Firm
Morgan Stanley Smith Barney
What happened
Decommissioned drives resold with customer data still on them
Penalty
$35M
July 27, 2022
Firm
J.P. Morgan, UBS, TradeStation
What happened
Identity-theft red-flag programs not tailored or updated
Penalty
$1.2M, $925K, $425K
Aug 30, 2021
Firm
Cetera (five entities)
What happened
60+ cloud email accounts taken over, plus misleading breach notices
Penalty
$300K
Aug 30, 2021
Firm
Cambridge Investment Research
What happened
121+ email accounts taken over
Penalty
$250K
Aug 30, 2021
Firm
KMS Financial Services
What happened
15 email accounts compromised
Penalty
$200K
Sept 26, 2018
Firm
Voya Financial Advisors
What happened
Intruders reset passwords by calling the support line posing as contractors
Penalty
$1M

What the cases have in common

Four of the eight began with email accounts taken over. Each pairs real harm with basic controls missing or unevenly applied, often for years. None involved a single incident the firm found and fixed quickly.

Where enforcement is heading

Novel theories are out: SolarWinds was dismissed in November 2025. The enforcement director says the SEC is "not focused on prosecuting firms or individuals for honest mistakes that cause no investor harm." But plain controls cases continue. What you can show you did before an incident decides how it goes.

06 · Examinations

What examiners actually cite

SEC risk alerts from 2019 to 2026 cite the same gaps again and again. Few are about technology the firm lacks. Most are about controls that exist on paper and not in practice.

Policies copied from a template, not tailored to the firm.

Policies written but not implemented, trained or tested. A September 2026 alert cites an identity-theft policy whose required annual testing the annual review skipped.

MFA and access controls applied unevenly: at headquarters but not for remote staff or branches.

Email set up weakly or without full logging, which "resulted in account takeover or business email compromise" and left firms unable "to perform adequate incident response."

No inventory of where investor personal information lives.

Incident response plans without named roles or actions.

Vendor oversight on paper only.

Identity-theft red flags never updated, even at firms "that experienced ongoing account takeovers over several years."

Former employees keeping access.

The first-day document request

The standard exam request list asks for cybersecurity incidents and breaches, with a description, the impact and the remediation. A firm that has never looked for a compromise has nothing to put there except "none known."

07 · LPs and insurers

Where the pressure really comes from

For most private fund managers, the first questions come from LPs and insurers, not the SEC. They apply whatever your registration status.

ILPA DDQ 2.0 · Question 18.4

"Does the Firm have an annual independent, third-party audit of the Firm's cyber/information security policy and controls?"

ILPA DDQ 2.0 · Question 18.5

"Has the Firm or any of its portfolio companies had any cyber breaches in the last five years?"

72%
of limited partners surveyed in the past 12 to 24 months requested more comprehensive IT and cybersecurity details in due diligence (RSM)
61%
of private fund CFOs said investors consider strong cybersecurity protocols "must-haves" (RSM)
53%
of PE firms carry their own cyber insurance policy (QBE)

Insurers check what you attest

Carriers now require enforced MFA, endpoint detection and response, and third-party risk management. Claim disputes increasingly turn on whether MFA was actually enforced when the incident happened.

A questionnaire, an attestation or an application asks you to state a fact about your environment. The policy binder cannot answer it. Only the environment can.

08 · The threat

The threat that turns a policy into an incident

The attacks that matter most to a GP go after people and email, not servers. Several are aimed at private equity this year, and the most dangerous survive a password reset.

$3.05B
in business email compromise losses across 24,768 complaints to the FBI in 2025. Texas ranked second nationally in total reported cybercrime losses, about $1.83B.
12,000+
inboxes in 10,000+ organizations taken over by one device-code phishing campaign, which searched mail for "wire transfer details" (Microsoft, Sept 22, 2026)
PE
named as a target. Google reported a help-desk impersonation campaign with "infrastructure directed at private equity firms" (Aug 2026)

In that campaign, callers phone employees, often on personal mobiles, under a pretext to update MFA enrollment, then register their own sign-in method and pull data from Microsoft 365 and Okta-connected apps. The same month, Apollo confirmed that a social engineering attack reached its cloud environment in July.

What survives a password reset

Resetting a password does not remove a stolen session token, an MFA method the attacker added, an app the attacker was granted, or an inbox rule hiding bank emails. A firm can have MFA on, a gateway in front of its mail and a clean policy review, and still have someone inside.

Only the tenant's own records show whether that is the case. Microsoft keeps sign-in and directory logs for 7 days on free Entra plans and 30 days on P1 or P2, and the unified audit log for 180 days on standard licenses. After that, the evidence a "reasonable investigation" needs is gone.

09 · Six questions

Six questions before your next DDQ or exam

If you can answer all six with a document or a log rather than a belief, your program is ahead of most.

1. Could we prove, today, that no one else is inside our email?

Not "we have MFA," but "we checked for inbox rules, forwarding, added sign-in methods and app grants, and here is the date and the result."

REG S-P · ILPA 18.5

2. How long do our logs go back, and who would pull them?

If the answer is 7 or 30 days and "our IT provider, probably," the 30-day notice clock may run out before the evidence is found.

REG S-P INCIDENT RESPONSE

3. Is MFA enforced for everyone, on every sign-in path?

Include remote staff, shared mailboxes, older sign-in methods and the help desk's reset process.

INSURANCE · SEC ALERTS

4. Which vendors can reach our investor data, and will they tell us within 72 hours?

Fund administrator, IT provider, outsourced CCO, CRM and data room.

REG S-P VENDOR OVERSIGHT

5. When did someone independent last test our controls?

An IT provider reviewing a tenant it configured is not independent.

ILPA 18.4

6. Can we say the same about our portfolio companies?

Question 18.5 asks about them too, and so will the next buyer's diligence team.

ILPA 18.5 · EXIT READINESS
10 · Next step

How to check your own firm

You can start on question one this week without buying anything.

01

Run the self-check

Our free checklist, 7 signs your Microsoft 365 is already compromised, shows your IT lead where to look for each one. It takes an afternoon.

cloudskope.com/7-signs
02

Ask for your outside view

Write to advisory@cloudskope.com, or reply to the email that brought you here. We will send a one-page read of your firm's email, built only from public records: look-alike domains, whether your domain can be spoofed, and how your mail is protected. No access, no call.

03

Preserve before you clean

If something looks wrong, preserve it first. Deleting a rule or resetting a password also removes evidence your notice decision may depend on.

Want the PDF for your partners?

The full brief as a 13-page PDF, formatted for an IC or compliance committee pack.

Sent. Look for an email from nicole@lc.cloudskope.com in the next few minutes. Add that address to your safe senders list so it reaches your inbox.
Not there? Check spam or junk, or email advisory@cloudskope.com
Something went wrong. Please try again or email advisory@cloudskope.com.
11 · FAQ

Reg S-P questions, answered

What is the Reg S-P compliance date?

Advisers with $1.5B or more under management had to comply with amended Reg S-P by December 3, 2025. Everyone else had to comply by June 3, 2026. Neither date was extended.

What does amended Reg S-P require?

A written incident response program, notice to affected individuals within 30 days of learning that their sensitive information was or was reasonably likely to be accessed without authorization, and service providers that notify you within 72 hours of a breach affecting your data.

Does Reg S-P apply to private equity and venture capital firms?

It applies to every SEC-registered investment adviser, private fund advisers included. Exempt reporting advisers are not covered, because the rule covers advisers "registered with the Commission." Our reading is that the FTC Safeguards Rule may apply to them instead; confirm with counsel.

When can a firm skip notifying individuals after a breach?

Only if a reasonable investigation shows the information is not reasonably likely to be misused. That investigation depends on logs, and Microsoft keeps sign-in logs for 7 days on free Entra plans and 30 days on P1 or P2 by default.

Has the SEC fined a private fund adviser under Reg S-P?

Not as of September 26, 2026. Every Reg S-P and Reg S-ID case since 2018 involved a broker-dealer or a dual registrant. The most recent, in November 2025, followed 17 email account takeovers.

Ground truth. Not story.

Cloudskope is a security-only advisory firm based in Dallas, Texas. We run forensic audits of Microsoft 365 and Azure, cyber due diligence for deals, and a fixed-fee six-day assessment and remediation program for firms and their portfolio companies. We are independent of your IT provider and compliance consultant, and we work alongside both.

Since May 1, 2026, our forensic audits have prevented $2.2M in wire fraud, none of it flagged first by the client's IT team, managed service provider, bank or security tools.

Sources

Sources

All opened and checked on September 26, 2026. This brief is general information, not legal advice. Items marked as interpretation should be confirmed with counsel.

SEC, Reg S-P amendments, 89 FR 47688 (June 3, 2024), govinfo.gov
Holland & Knight, Reg S-P compliance deadline (May 7, 2026), hklaw.com
17 CFR Part 248, Reg S-P and S-ID, ecfr.gov
SEC Division of Examinations, FY2026 priorities (Nov 17, 2025), sec.gov
SEC risk alerts: Reg S-ID (Dec 5, 2022); branch offices (Apr 26, 2023); adviser document requests (Sept 6, 2023); annual compliance reviews (Sept 14, 2026), sec.gov
SEC order, M Holdings Securities, 34-104255 (Nov 25, 2025), sec.gov
SEC press releases 2025-5 (Robinhood), 2022-168 (Morgan Stanley), 2022-131 (identity theft red flags), 2021-169 (email takeovers), 2018-213 (Voya), sec.gov
SEC LR-26423, SolarWinds (Nov 20, 2025); remarks of Enforcement Director Woodcock (May 13, 2026), sec.gov
Withdrawal of proposed Rule 206(4)-9, Federal Register (June 17, 2025); SEC statement on Private Fund Adviser Rules
FTC Safeguards Rule, 16 CFR Part 314; FTC notification amendment (Oct 27, 2023)
NYDFS Part 500 amendment (Nov 1, 2023); SEC 2023-139, Form 8-K Item 1.05
Texas SB 2610; California SB 446 (Hunton, Mar 17, 2026); Delaware HB 381 (National Law Review, Sept 16, 2026); CIRCIA timing (Hunton, July 17, 2026)
ILPA Due Diligence Questionnaire 2.0, ilpa.org
RSM, Private Funds CFO Insights 2025; RSM on PE cybersecurity (Dec 16, 2024)
Cybersecurity Dive on underwriting and claims (June 8, 2026); QBE PE cyber white paper (Apr 23, 2025)
FBI IC3 2025 Internet Crime Report
Google Threat Intelligence, UNC6671 (Aug 6, 2026); TechCrunch on Apollo (Aug 21, 2026)
Microsoft Security Blog, device code phishing (Sept 22, 2026)
Microsoft Learn: Entra log retention; Purview audit log retention