A US Registered Investment Advisor engaged LeakTrace to establish a client-side exposure baseline supporting the Form ADV cyber disclosure the firm was preparing under the amended Regulation S-P Safeguards Rule. The audit produced the documented reference material the firm's Chief Compliance Officer used to complete the disclosure without further follow-up from the Commission staff.

Engagement origin

The firm operates a Registered Investment Advisor practice with approximately fifty investment advisor representatives across several states. The Chief Compliance Officer was preparing the firm's Form ADV Part 2A brochure disclosure on cybersecurity risks and had identified that the disclosure required substantive reference material beyond the firm-level information-security program that had been documented in prior filings. The amended Safeguards Rule's expectations had prompted the Commission staff to press peer firms on the specificity of their Form ADV disclosures. LeakTrace was engaged through the firm's outside counsel to establish a client-side baseline that could be referenced in the disclosure.

Discovery scope

LeakTrace conducted an external attack surface audit against each investment advisor representative's business email pattern, professional registration records, and the household correlation surface that a targeting attacker would use to construct a pretext against advisor-to-client communication. The engagement was formatted for regulatory filing use in coordination with the firm's Chief Compliance Officer and outside counsel, with specific attention to the categories of exposure the amended Safeguards Rule anticipates.

Findings summary

  • Advisor credential exposure. A meaningful fraction of the advisor representatives had personal email addresses appearing in monitored breach databases, with a subset having recoverable password fragments. Reuse patterns extended into custodian platform login in a subset of cases.
  • Household correlation exposure. Public-record aggregation on advisor representatives identified household composition, residential address history, and family relationship signals consistent with the pretext construction the amended Safeguards Rule anticipates in advisor-to-client wire fraud scenarios.
  • Custodian platform authentication. Multi-factor authentication was enforced across the custodian platform, but a subset of advisors had backup authentication methods enrolled that reduced the strength of the multi-factor posture below the current industry baseline referenced in Commission staff guidance.
  • Client-side pattern signals. The firm's public marketing content disclosed client-adjacent details in ways that permitted a targeting attacker to construct multiple context-anchored pretexts against advisor-to-client communication.
  • Vendor mapping and data flow. DNS records and public procurement filings identified the firm's outsourced information-technology provider, portfolio management platform, and client reporting service. Data flow to each vendor was documented against the vendor's own security posture and the firm's compliance records were updated to reference the mapping.

Firm actions

The firm implemented a phased remediation program in coordination with counsel. Advisor credentials appearing in the breach index were rotated across affected personal accounts, and multi-factor authentication backup methods were restricted to hardware tokens for advisors above a defined client book size. Household correlation exposure was addressed at the individual advisor level through data-broker opt-out processes documented by the compliance officer. Client-side marketing content was reviewed for aggregate inference potential and adjusted where feasible. Vendor documentation was updated to reference the current security posture. The Form ADV Part 2A disclosure was drafted with reference to the baseline audit and the remediation program.

Outcome

The firm's Form ADV Part 2A disclosure was accepted by the Commission staff without follow-up inquiry. The firm's subsequent compliance examination referenced the baseline audit as documented evidence of client-side Safeguards Rule attention. The Chief Compliance Officer engaged LeakTrace as a standing partner for annual baseline refreshes tied to the firm's Form ADV annual amendment cycle, and referred the pattern to two peer firms with comparable regulatory obligations.

Methodology transparency

All findings were derived from public and monitored sources only. No portion of this engagement required access to the firm's internal systems, any client account, or coordination with any threat actor. Form ADV disclosure was drafted by the firm's Chief Compliance Officer under counsel coordination with the LeakTrace baseline as reference material. This case file documents the pattern of Form ADV cyber disclosure engagements LeakTrace conducts with American Registered Investment Advisors, and is not attributed to the specific firm, advisor representatives, or clients referenced.