A mid-size American wealth advisory firm engaged LeakTrace to build a documented client-side exposure baseline as part of its Regulation S-P Safeguards Rule compliance program. The engagement identified advisor-level exposure conditions that the firm's information-security program had not been scoped to detect, and shaped the compliance program's remediation posture.

Engagement origin

The firm operates a Registered Investment Advisor practice with approximately forty investment advisor representatives across several offices in one region of the United States. The firm's Chief Compliance Officer had reviewed the amended Safeguards Rule and identified a gap in the firm's compliance documentation: while the firm-level information-security program was documented and audited, the individual advisor-level exposure surface was not evaluated in a manner that the Commission would consider consistent with the amended rule's expectations. The Chief Compliance Officer engaged LeakTrace to conduct an advisor-level exposure baseline that could be documented and referenced in the firm's compliance filings.

Discovery scope

LeakTrace conducted an external attack surface audit against each investment advisor representative's business email pattern, professional registration records, and the household correlation surface that a targeting attacker would use to construct a pretext against advisor-to-client communication. The engagement did not touch the firm's internal systems, did not access any client account, and was scoped as pre-advisor education material rather than as a firm-wide penetration engagement. The findings were formatted for compliance filing use in coordination with the firm's counsel.

Findings summary

  • Advisor credential exposure. A meaningful fraction of the advisor representatives had personal email addresses appearing in monitored breach databases, several with recoverable password fragments. Password reuse across professional and personal platforms was identifiable in a subset of those cases, extending the potential blast radius into the firm's advisor login for the custodian platform.
  • Household correlation exposure. Public-record aggregation on advisor representatives identified household composition, residential address history, and family relationship signals that would allow a targeting attacker to construct a plausible pretext against a client wire request. Several advisors had social media exposure of family travel that could be timed with client wire cycles.
  • Custodian platform authentication. The firm's custodian platform login was reachable through a publicly discoverable authentication URL. The firm had multi-factor authentication configured, but a subset of advisors had backup authentication methods enrolled that reduced the strength of the multi-factor posture below the current industry baseline for the platform.
  • Client-side pattern signals. The firm's public-facing marketing content disclosed several client-adjacent details (event sponsorships, philanthropic affiliations, industry participation) that intersected with the advisors' own public footprint. A targeting attacker profiling the firm would have had multiple angles from which to construct a client-facing impersonation.

Firm actions

The firm implemented a phased remediation program. Advisor credentials appearing in the breach index were rotated across affected personal accounts, and multi-factor authentication was enforced on the custodian platform with backup authentication methods restricted to hardware tokens for advisors above a defined book size. Household correlation exposure was addressed at the individual advisor level through data-broker opt-out processes documented by the firm's compliance team. Client-side pattern signals were reviewed by the firm's marketing and compliance teams jointly, and the firm's public content was adjusted to reduce the intersection with advisors' personal footprints. The compliance filings referenced the baseline audit and the remediation program as documented evidence of client-side Safeguards Rule attention.

Outcome

The firm's next compliance examination included the LeakTrace baseline as a referenced document. The examination staff acknowledged the documented client-side program and did not raise findings on the advisor-level exposure surface. The firm's Chief Compliance Officer engaged LeakTrace as a standing partner for annual baseline refreshes and for new-advisor onboarding audits, and referred the pattern to two peer firms in the same channel.

Methodology transparency

All findings were derived from public and monitored sources only. No portion of this engagement required access to the firm's internal systems, purchased breach data, or coordination with any threat actor. Compliance filings referenced the baseline audit under coordination with the firm's counsel. This case file documents the pattern of advisor-level exposure baselines LeakTrace conducts with American wealth advisory firms under the amended Safeguards Rule, and is not attributed to the specific firm referenced.