Cybersecurity Risk Assessment Checklist
Governance and Risk Management
Document the named CISO (or virtual CISO), incident response lead, and backup deputy in the firm's WISP. NYDFS Part 500 and the SEC's proposed Reg S-P amendments both expect a designated, documented owner — not a shared inbox. Confirm coverage during PTO and CCO transitions.
Walk the written information security program against the FTC Safeguards Rule elements: risk assessment, access controls, encryption, MFA, monitoring, training, incident response, and vendor oversight. Flag any element where the written policy doesn't match current practice — auditors compare both.
List every system that holds NPI (nonpublic personal information) or client account data: CRM (Wealthbox / Redtail / Salesforce FSC), portfolio management (Black Diamond / Orion / Tamarac / Addepar), planning (eMoney / MoneyGuide / RightCapital), custodian portals, email archive, and any shadow SaaS the team has signed up for.
Score likelihood and impact for each in-scope system using the firm's risk matrix (NIST CSF or CIS Controls mapping is typical). Document residual risk after compensating controls — not just inherent risk. The aggregate rating drives whether an emergency board session is convened.
Present residual risk, top three remediation priorities, and budget asks at the next regularly scheduled board or management committee meeting. Capture the meeting minutes — SEC examiners and NYDFS regularly ask for evidence that cybersecurity reaches the board, not just IT.
A High residual risk rating warrants a same-week briefing rather than waiting for the next quarterly meeting. Walk through the specific findings, recommended interim controls, and a 30/60/90-day remediation plan with named owners.
Access Controls and Authentication
Verify that Schwab Advisor Center, Fidelity Wealthscape, Pershing NetX360, Altruist, and the firm CRM all require MFA — preferably authenticator app or hardware key, not SMS. Spot-check a sample of advisor and CSA accounts; SMS-only fallback is a common audit finding.
Pull the HR JML log for the last 12 months and reconcile against current access lists in every regulated system. The recurring gotcha: a paraplanner who moved teams still has access to the prior team's client folder, or a terminated rep still has a Schwab login because IT closed Active Directory but not the custodian profile.
Admin rights in Tamarac, Orion Eclipse, iRebal, or Black Diamond can move money, change models, or export entire client books. Confirm each privileged user is still in role and that the count matches the last quarterly attestation.
Inventory non-human accounts: data feed credentials between the custodian and PMS, integration tokens between the CRM and planning software, vendor API keys. Rotate any key older than 12 months and disable any service account whose business owner can no longer be identified.
Verify that read access to NPI in the CRM, document portal, and custodian downloads is logged and retained per books-and-records (SEC Rule 204-2: 5 years, first 2 onsite). Sample a recent week's logs to confirm they are actually being captured, not just configured.
Data Protection and Encryption
Map each data store to a tier: NPI (SSN, account numbers, balances), confidential (planning assumptions, meeting notes), and internal. The classification drives encryption, retention, and disposal requirements downstream.
Daily position and transaction files from Schwab, Fidelity, and Pershing often land on a network share or local drive before import. Confirm those landing zones are encrypted (BitLocker, FileVault, or AES-256 on the file server) and that the import job purges the file after load.
A backup that has never been restored is not a backup. Restore a sample of the PMS database, CRM export, and document portal to an isolated environment and confirm the data opens cleanly. Capture screenshots and the restore timestamp as audit evidence.
Pull certificates of destruction for any laptop, server, or copier hard drive retired since the last assessment. Lease-return copiers are a recurring blind spot — the multifunction unit at the front desk has a hard drive that scanned every client tax return for three years.
Confirm Smarsh, Global Relay, or Bloomberg Vault is capturing every advisor's email, LinkedIn DMs, and approved texting channel (MyRepChat, Hearsay Relate). The SEC's $2B+ in off-channel sweep penalties through 2024 came from personal text and WhatsApp use — spot-check that the policy is enforced, not just written.
Incident Response and Recovery
Walk through a scenario where the CRM and document portal are encrypted on a Friday afternoon. Test the call tree, custodian notification, cyber insurance hotline, and outside counsel engagement. The most common gap surfaced: nobody has the cyber insurer's 24/7 hotline number in their phone.
Log each gap with a named owner, target date, and verification method. Examiners look for the loop being closed — a tabletop that surfaced gaps two years running with no remediation log is worse than not doing the tabletop.
Public companies (and many BDs) must file an 8-K Item 1.05 within four business days of determining a material cybersecurity incident. Confirm the materiality determination process is documented and that disclosure counsel is on the IR call tree. Even non-public RIAs should mirror the four-day cadence for client notification.
The amended FTC Safeguards Rule requires notification to the FTC within 30 days of discovering an incident affecting 500+ consumers. State breach notification laws (CCPA, NY SHIELD, MA 201 CMR 17) layer on top with their own timelines and content requirements. Confirm the template letter, FTC notification path, and state-by-state matrix are current.
If the primary office is down, can advisors still place trades and process distributions through the custodian's web portal from a clean device? Walk through the steps with a sample advisor on a non-firm laptop. Confirm that hardware MFA tokens travel with the advisor or are recoverable.
Revise the incident response plan with any updated phone numbers, vendor contacts, and decision-tree changes from the tabletop. Re-circulate to the IR team and capture acknowledgments — version control matters when an examiner asks which IRP was in effect during a real incident.
Vendor and Third-Party Risk Management
Critical vendors include the custodian, PMS, CRM, planning software, email archive, and managed IT provider. Refresh the due diligence questionnaire, ownership/control changes, financial health, and any reportable incidents in the past 12 months.
Read the exception sections — not just the cover page. Confirm the report covers the period since the last review with no gap, that complementary user entity controls (CUECs) the vendor expects you to perform are actually being performed, and that no material exceptions go unaddressed.
Request the vendor's remediation plan and target dates in writing. If the exception touches a control the firm relies on (encryption, access review, change management), document the compensating control the firm will run until the vendor closes the gap.
Each material vendor's MSA should commit to notification within 72 hours (or sooner) of a security incident affecting firm or client data. Older contracts often have weak or no notification language — flag for renegotiation at the next renewal.
Every vendor and its named principals should be screened against the OFAC SDN list at onboarding and re-screened at least annually. Tools like Refinitiv World-Check, LexisNexis Bridger, or ComplyAdvantage automate the recurring screen — manual one-time checks at onboarding are a recurring exam finding.
The CCO signs the consolidated vendor risk register and attaches it to the assessment file. The register should show every material vendor's tier, last DD date, SOC 2 status, and any open exceptions — this is the single document an examiner will ask for first.
Use this template in Manifestly
- Cybersecurity Protocol Checklist
- Cybersecurity Checklist for Real Estate
- Manufacturing Cybersecurity Checklist
- Cyber Security Checklist
- Data Security Checklist
- Disaster Recovery Checklist
- Cybersecurity Incident Response Checklist
- Network Security Checklist
- IT Asset Inventory Management Checklist
- Insurance IT Security Review Checklist
- Data Security Review Checklist
- Financial Services IT Security Audit Checklist
- Cybersecurity Incident Response Checklist
- Motor Carrier Cybersecurity Protocol Checklist
- Annual Attorney Professional Conduct Review
- Restaurant New Hire Checklist
- Restaurant Policy Update Checklist
- Retail Policy Update and Compliance Checklist
- New Hire Paperwork Checklist
- Department of Transportation (DOT) Audit Checklist
- Restaurant Permit and Licensing Renewal Checklist
- Marketing Strategy Checklist
- E-commerce Risk Management Checklist
- E-commerce Legal Compliance Checklist
- CRM Data Entry Checklist
- Cybersecurity Incident Response Checklist
- Agency Compliance and Risk Management Checklist
- Advisor and Staff Onboarding Checklist
- New Hire Onboarding Checklist
- Financial Services IT Security Audit Checklist
- Litigation Preparation Checklist
- Internal Audit Checklist
- PCI DSS Compliance Checklist
- Contract Review Checklist
- Annual Financial Reporting Checklist
- Intellectual Property Management Checklist
- Annual Compliance Program Review
- Project Monitoring Checklist
- Operational Risk Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Regulatory Reporting Checklist
- Advisor and Employee Onboarding Checklist
- Quarterly Performance Measurement Checklist
- IT Policy Review Checklist
- Project Closure Checklist
- Monthly Financial Reporting Checklist
- Quarterly Operations and Compliance QA Review
- Know Your Customer (KYC) Checklist
- User Access Review Checklist
- Data Protection Checklist
- Employee File Audit Checklist
- Email Deliverability Checklist
- HR Compliance Checklist
- Law Firm Ethics Compliance Review
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Licensing Renewal Checklist
- Motor Carrier TSA Security Compliance Checklist
- Risk Assessment Checklist
- School First Aid and Emergency Medication Audit
- Annual School Compliance Audit
- Annual Risk Management Review Checklist
- Vendor Contract Review Checklist
- Business Continuity Plan Checklist
- HR Audit Checklist
- Insurance Marketing Campaign Checklist
- Cloud Security Checklist
- Insurance Program Launch Project Monitoring Checklist
- Anti-Money Laundering Compliance Checklist
- System Backup Checklist
- Data Privacy Compliance Checklist
- Quarterly Risk Monitoring Checklist
- Insurance Program Initiation Checklist
- Law Firm Compliance Checklist
- Training Materials Checklist
- Professional Responsibility Compliance Review
- Employee Offboarding Checklist
- Network Security Checklist
- Regulatory Reporting Checklist
- IT Asset Inventory Management Checklist
- Manufacturing Regulatory Compliance Checklist
- Compliance Audit Checklist
- Training Needs Assessment Checklist
- Email Compliance Checklist
- Audit Preparation Checklist
- Skills Development Checklist
- Law Firm Compliance Checklist
- Financial Statement Review Checklist
- Employee Termination Checklist
- Project Planning Checklist
- Project Execution Checklist
- Security Audit Checklist
- Quarterly Compliance Monitoring Checklist
- Regulatory Compliance Checklist
- E-commerce Sales Tax Reporting Checklist
- Annual Risk Assessment Checklist
- Compliance Audit Checklist
- Client Satisfaction Survey Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Financial Services Project Initiation Checklist
- Brokerage HR Policy Compliance Checklist
- Data Privacy Compliance Checklist
- Employee Handbook Annual Review
- Expense Management Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Regulatory Compliance Checklist
- Listing Agreement Intake Checklist
- Employee Records File Audit
- Employee Termination Checklist
- Law Firm Risk Management Checklist
- ISO/IEC 27001 Compliance Checklist
- Complaint Resolution Checklist
- IT Regulatory Compliance Review
- HR Compliance Checklist
- Business Continuity Checklist
- Lead Generation Checklist
- Insurance Program Launch Execution Checklist
- Employee Benefits Checklist
- Law Firm Risk Management Checklist
- Fair Housing Compliance Audit
- Real Estate Website Audit Checklist
- Real Estate Ethics & Compliance Review
- Software Licensing Compliance Checklist
- Property Risk Assessment Checklist
- Lease Agreement Checklist
- Security Audit Checklist
- Legal Compliance Checklist for New Properties
- Fair Housing Compliance Checklist
- IT Security Audit Checklist
- Claims Auditing Checklist
- Document Retention Policy Checklist
- Insurance Training and Development Checklist
- Quarterly Industry Standards Compliance Review
- Risk Management Checklist
- Employee Records Management Checklist
- Building Code Compliance Checklist
- GDPR Compliance Review Checklist
- Legal Entity Management Checklist
- SOX Compliance Checklist
- Quarterly Internal Control Review Checklist
- Legal Document Storage Checklist
- Anti-Money Laundering Compliance Checklist
- Regulatory Compliance Checklist
- Insurance Compliance Checklist
- Real Estate Contract Review Checklist
- Employee Termination Checklist
- GDPR Compliance Checklist
- Continuing Education Checklist
- Real Estate License Renewal Checklist
- MLS Listing Review Checklist
- HIPAA Compliance Checklist
- Real Estate Legal Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Professional Development Checklist
- Brokerage Trust Account Management Checklist
- Cybersecurity Protocol Checklist
- HR Compliance Checklist
- Data Security Review Checklist
- Risk Management Checklist
- Sales Tax Reporting Checklist
- Property Safety Inspection Checklist
- Employee File Audit Checklist
- Brokerage Technology Inventory Audit
- Payroll Processing Checklist
- Marketing Strategy Checklist
- Annual Budget Planning Checklist
- Month-End Close Checklist
- Advisor and Staff Onboarding Checklist
- Portfolio Management Checklist
- New Hire Onboarding Checklist
- Advisory Firm Operational Efficiency Review
- Financial Services IT Security Audit Checklist
- Litigation Preparation Checklist
- Internal Audit Checklist
- Practice Process Improvement Review
- Disaster Recovery Checklist
- AML / BSA Compliance Checklist
- Contract Review Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Project Monitoring Checklist
- Operational Risk Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- Market Risk Checklist
- Accounts Receivable Checklist
- Regulatory Reporting Checklist
- Client Retention Checklist
- Quarterly Performance Measurement Checklist
- Project Closure Checklist
- Monthly Financial Reporting Checklist
- Quarterly Operations and Compliance QA Review
- Anti-Money Laundering (AML) Checklist
- Employee Performance Review Checklist
- Know Your Customer (KYC) Checklist
- Daily Operations Checklist
- Investment Due Diligence Checklist
- RIA Acquisition Due Diligence Checklist
- Data Protection Checklist
- Campaign Performance Checklist
- Sales Pipeline Checklist
- Annual Client Review Checklist
- Client Onboarding Checklist
- Internal Controls Checklist
- Client Communication Checklist
- Annual Risk Management Review Checklist
- Business Continuity Plan Checklist
- Vendor Management Checklist
- Financial Statement Review Checklist
- Employee Termination Checklist
- KYC Checklist
- Project Planning Checklist
- Project Execution Checklist
- Credit Risk Checklist
- Asset Allocation Checklist
- Quarterly Financial Reporting Checklist
- Regulatory Compliance Checklist
- Annual Risk Assessment Checklist
- Client Satisfaction Survey Checklist
- Financial Services Project Initiation Checklist
- Business Continuity Checklist
- Lead Generation Checklist
- Client Risk Profile Checklist
- Data Security Review Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
