Data Security Review Checklist

Periodic data security review run by the CCO and IT lead at an RIA, broker-dealer, or community bank. Covers GLBA Safeguards, Reg S-P, identity-theft red flags, off-channel communications archiving, and vendor SOC 2 oversight.

6 sections 23 steps Collects data
1

Access Controls & Physical Security

  1. Audit badge access to server rooms
    • Pull the current badge roster from the access control system and reconcile against active employees in HRIS. Common gotchas: contractors whose badges were never decommissioned, and shared badges issued to the cleaning vendor that haven't been rotated.

  2. Reconcile MFA enrollment on custodian portals
    • Confirm every advisor and ops user with Schwab Advisor Center, Fidelity Wealthscape, Pershing NetX360, or Altruist access has hardware or app-based MFA enrolled. SMS-only MFA is no longer acceptable under most custodian policies and is a known SIM-swap weakness.

  3. Review VPN and remote desktop session logs
    • Pull last quarter's VPN and RDP session logs. Look for off-hours sessions, sessions from unexpected geographies, and concurrent sessions per user. Tag anything anomalous for follow-up with the user before closing the review.

  4. Verify clean-desk policy on the advisor floor
    • Walk the floor after hours. Photograph any client statements, account numbers, or SSNs left visible on desks. Reg S-P expects reasonable safeguards over client NPI in physical form, not just digital.

2

Data Protection & Encryption

  1. Verify encryption at rest on client PII stores
    • Confirm AES-256 encryption on the CRM database (Wealthbox, Redtail, Salesforce FSC), the document management store (NetDocuments, ShareFile, Laserfiche), and any local file shares holding client account data. Spot-check that backup volumes are also encrypted, not just primary storage.

  2. Confirm TLS 1.2+ on client-facing portals
    • Run an SSL Labs scan on every public-facing domain — client portal, planning tool deep links, marketing site forms that collect PII. TLS 1.0 and 1.1 are deprecated; weak cipher suites and expired certs are common audit findings.

  3. Test the quarterly backup restore
    • Pick a non-trivial dataset — a CRM table, a planning file, a portfolio accounting export — and restore it to a test environment. A backup that has never been restored is not a backup. Document the restore time against the firm's RTO.

  4. Review the Reg S-P data retention schedule
    • Cross-check the firm's retention policy against SEC Rule 204-2 (advisors, 5 years), FINRA Rule 4511 / SEC 17a-4 (broker-dealers, 6 years for most records), and state recordkeeping rules. Note the 2024 Reg S-P amendments require disposal of customer information no longer needed.

3

Network Security & Monitoring

  1. Review firewall ruleset for stale entries
    • Walk the firewall ruleset with the network admin. Common findings: any-any rules left over from a vendor onboarding, port forwards to decommissioned systems, allow rules to former employee home IPs.

  2. Run the quarterly vulnerability scan
    • Run the authenticated scan against the internal network and a credentialed scan against the DMZ. Tenable, Rapid7, and Qualys are common tools. Capture the report and record the highest severity finding for the conditional below.

    Collects list
  3. Remediate critical vulnerabilities within 72 hours
    • Patch or compensate for any CVSS 9.0+ findings within 72 hours per the firm's vulnerability management policy. If the affected system is a vendor-managed appliance, open a P1 ticket with the vendor and document the compensating control until the patch ships.

  4. Review SIEM alerts from the prior quarter
    • Pull the SIEM dashboard (Arctic Wolf, Huntress, Blackpoint, Microsoft Sentinel) and review alerts that closed without a ticket. Particular attention to impossible-travel logins, mass file downloads from the document store, and OAuth grants on the M365 / Google Workspace tenant.

4

Identity and Access Management

  1. Review user access privileges quarterly
    • Have each department head certify their team's access list — CRM roles, custodian portal entitlements, document store permissions. Least-privilege is the standard; an associate advisor does not need principal-trade entitlements.

  2. Verify Form U5 offboarding closes all access
    • For every rep terminated in the prior quarter, confirm Form U5 was filed within 30 days and that the off-boarding checklist closed CRM, custodian portal, M365, archiving, and any planning-tool seats. Stale custodian access for departed reps is a common SEC exam finding.

  3. Enforce password policy in the directory
    • Confirm Entra ID / Active Directory / Okta enforces NIST 800-63B-aligned policy: minimum 14 characters, breached-password rejection, no forced rotation absent suspicion of compromise. Document any service accounts exempted and the compensating MFA / vault controls.

  4. Audit privileged trading-system accounts
    • Identify every account with block-trading, principal-review, or fee-billing entitlements at the custodian and in the rebalancer (iRebal, Tamarac, Black Diamond). Confirm each has a named human owner, MFA, and no shared credentials. Service accounts go in the vault.

5

Application & Vendor Security

  1. Patch advisor applications to current versions
    • Confirm latest stable releases on the planning tools (eMoney, MoneyGuide, RightCapital), the CRM, the rebalancer, and any local trading apps. Out-of-support browsers used to access custodian portals are a recurring finding.

  2. Run security testing on the client portal
    • If the firm operates its own client portal or planning portal, run OWASP-aligned application testing — at minimum authenticated DAST. If the portal is fully vendor-hosted, collect and review the vendor's most recent pentest summary instead.

  3. Audit off-channel communication archiving
    • Sample five reps and reconcile their personal phone usage against the texting archive (MyRepChat, Hearsay Relate, Smarsh Connect). The 2022-2024 SEC and CFTC sweep on personal-device texting drove $2B+ in fines; this is the highest-velocity exam topic in advisor compliance.

    Collects list
  4. Remediate off-channel communication findings
    • For each rep with unarchived business communication, document the gap, retrieve and archive what is recoverable, and issue written supervisory action per the firm's WSPs. Repeat offenders move to heightened supervision.

  5. Collect SOC 2 Type II reports from key vendors
    • Request the current-year SOC 2 Type II from custodian, CRM, planning tool, archiving vendor, and rebalancer. Review the auditor's exceptions and any subservice-organization carve-outs. File for the next exam cycle.

6

Findings & CCO Sign-Off

  1. Compile the data security findings report
    • Roll up findings, remediation status, and open items into the firm's annual GLBA Safeguards Rule report. Attach scan output, restore test logs, access-review certifications, and SOC 2 receipts. This is the document the SEC or state examiner will request first.

    Collects file
  2. CCO sign-off on the data security review
    • The CCO reviews the compiled report, records the disposition, and signs. Conditional approvals require named owners and dates for each open item; the next quarterly review will reconcile against this list.

    Collects list Collects paragraph Collects signature

Use this template

Copy it to your account, customize the steps, and run it with your team in minutes.


Sections 6
Steps 23
Category Financial Services
Price Free to start
Need a different process

Browse hundreds of free templates across every team and industry.

Back to template library

Run Data Security Review Checklist with your team

Customize the steps, assign roles, set a schedule, and keep a complete record for every run.