Data Security Review Checklist
Periodic data security review run by the CCO and IT lead at an RIA, broker-dealer, or community bank. Covers GLBA Safeguards, Reg S-P, identity-theft red flags, off-channel communications archiving, and vendor SOC 2 oversight.
Access Controls & Physical Security
-
Audit badge access to server rooms
Pull the current badge roster from the access control system and reconcile against active employees in HRIS. Common gotchas: contractors whose badges were never decommissioned, and shared badges issued to the cleaning vendor that haven't been rotated.
-
Reconcile MFA enrollment on custodian portals
Confirm every advisor and ops user with Schwab Advisor Center, Fidelity Wealthscape, Pershing NetX360, or Altruist access has hardware or app-based MFA enrolled. SMS-only MFA is no longer acceptable under most custodian policies and is a known SIM-swap weakness.
-
Review VPN and remote desktop session logs
Pull last quarter's VPN and RDP session logs. Look for off-hours sessions, sessions from unexpected geographies, and concurrent sessions per user. Tag anything anomalous for follow-up with the user before closing the review.
-
Verify clean-desk policy on the advisor floor
Walk the floor after hours. Photograph any client statements, account numbers, or SSNs left visible on desks. Reg S-P expects reasonable safeguards over client NPI in physical form, not just digital.
Data Protection & Encryption
-
Verify encryption at rest on client PII stores
Confirm AES-256 encryption on the CRM database (Wealthbox, Redtail, Salesforce FSC), the document management store (NetDocuments, ShareFile, Laserfiche), and any local file shares holding client account data. Spot-check that backup volumes are also encrypted, not just primary storage.
-
Confirm TLS 1.2+ on client-facing portals
Run an SSL Labs scan on every public-facing domain — client portal, planning tool deep links, marketing site forms that collect PII. TLS 1.0 and 1.1 are deprecated; weak cipher suites and expired certs are common audit findings.
-
Test the quarterly backup restore
Pick a non-trivial dataset — a CRM table, a planning file, a portfolio accounting export — and restore it to a test environment. A backup that has never been restored is not a backup. Document the restore time against the firm's RTO.
-
Review the Reg S-P data retention schedule
Cross-check the firm's retention policy against SEC Rule 204-2 (advisors, 5 years), FINRA Rule 4511 / SEC 17a-4 (broker-dealers, 6 years for most records), and state recordkeeping rules. Note the 2024 Reg S-P amendments require disposal of customer information no longer needed.
Network Security & Monitoring
-
Review firewall ruleset for stale entries
Walk the firewall ruleset with the network admin. Common findings: any-any rules left over from a vendor onboarding, port forwards to decommissioned systems, allow rules to former employee home IPs.
-
Run the quarterly vulnerability scan
Run the authenticated scan against the internal network and a credentialed scan against the DMZ. Tenable, Rapid7, and Qualys are common tools. Capture the report and record the highest severity finding for the conditional below.
Collects list -
Remediate critical vulnerabilities within 72 hours
Patch or compensate for any CVSS 9.0+ findings within 72 hours per the firm's vulnerability management policy. If the affected system is a vendor-managed appliance, open a P1 ticket with the vendor and document the compensating control until the patch ships.
-
Review SIEM alerts from the prior quarter
Pull the SIEM dashboard (Arctic Wolf, Huntress, Blackpoint, Microsoft Sentinel) and review alerts that closed without a ticket. Particular attention to impossible-travel logins, mass file downloads from the document store, and OAuth grants on the M365 / Google Workspace tenant.
Identity and Access Management
-
Review user access privileges quarterly
Have each department head certify their team's access list — CRM roles, custodian portal entitlements, document store permissions. Least-privilege is the standard; an associate advisor does not need principal-trade entitlements.
-
Verify Form U5 offboarding closes all access
For every rep terminated in the prior quarter, confirm Form U5 was filed within 30 days and that the off-boarding checklist closed CRM, custodian portal, M365, archiving, and any planning-tool seats. Stale custodian access for departed reps is a common SEC exam finding.
-
Enforce password policy in the directory
Confirm Entra ID / Active Directory / Okta enforces NIST 800-63B-aligned policy: minimum 14 characters, breached-password rejection, no forced rotation absent suspicion of compromise. Document any service accounts exempted and the compensating MFA / vault controls.
-
Audit privileged trading-system accounts
Identify every account with block-trading, principal-review, or fee-billing entitlements at the custodian and in the rebalancer (iRebal, Tamarac, Black Diamond). Confirm each has a named human owner, MFA, and no shared credentials. Service accounts go in the vault.
Application & Vendor Security
-
Patch advisor applications to current versions
Confirm latest stable releases on the planning tools (eMoney, MoneyGuide, RightCapital), the CRM, the rebalancer, and any local trading apps. Out-of-support browsers used to access custodian portals are a recurring finding.
-
Run security testing on the client portal
If the firm operates its own client portal or planning portal, run OWASP-aligned application testing — at minimum authenticated DAST. If the portal is fully vendor-hosted, collect and review the vendor's most recent pentest summary instead.
-
Audit off-channel communication archiving
Sample five reps and reconcile their personal phone usage against the texting archive (MyRepChat, Hearsay Relate, Smarsh Connect). The 2022-2024 SEC and CFTC sweep on personal-device texting drove $2B+ in fines; this is the highest-velocity exam topic in advisor compliance.
Collects list -
Remediate off-channel communication findings
For each rep with unarchived business communication, document the gap, retrieve and archive what is recoverable, and issue written supervisory action per the firm's WSPs. Repeat offenders move to heightened supervision.
-
Collect SOC 2 Type II reports from key vendors
Request the current-year SOC 2 Type II from custodian, CRM, planning tool, archiving vendor, and rebalancer. Review the auditor's exceptions and any subservice-organization carve-outs. File for the next exam cycle.
Findings & CCO Sign-Off
-
Compile the data security findings report
Roll up findings, remediation status, and open items into the firm's annual GLBA Safeguards Rule report. Attach scan output, restore test logs, access-review certifications, and SOC 2 receipts. This is the document the SEC or state examiner will request first.
Collects file -
CCO sign-off on the data security review
The CCO reviews the compiled report, records the disposition, and signs. Conditional approvals require named owners and dates for each open item; the next quarterly review will reconcile against this list.
Collects list Collects paragraph Collects signature
Use this template
Copy it to your account, customize the steps, and run it with your team in minutes.
Browse hundreds of free templates across every team and industry.
Back to template libraryRelated templates
More workflows your team can run.
Run Data Security Review Checklist with your team
Customize the steps, assign roles, set a schedule, and keep a complete record for every run.