Key Takeaways
- The FTC Safeguards Rule (updated June 2023) requires MFA, annual penetration testing, and a written incident response plan for covered financial institutions.
- Regulators are actively examining security programs and vendor contracts — not just responding to breaches after the fact.
- Missing a Qualified Individual designation or board-level security reporting is a common, easily avoidable compliance failure.
- Financial firms that cannot demonstrate a documented security program face both regulatory penalties and competitive disadvantage.
- Submitting an inaccurate self-assessment score or SPRS entry exposes organizations to False Claims Act liability.
In 2026, financial firms are facing pressure from several directions at once. Cybercriminals continue to target financial data. Clients are more aware of security risks. Cyber insurance carriers are asking tougher questions. Regulators are paying closer attention to whether firms have reasonable safeguards in place.
The challenge is that many firms still have gaps in their cybersecurity programs. Some are technical. Others are procedural. Many are the result of systems, users, vendors, and workflows growing over time without a formal security review.
Here are some of the key cybersecurity gaps financial firms should pay attention to in 2026.
No Formal Written Security Program
One of the biggest gaps for smaller and midsize financial firms is the lack of a formal written security program.
Many firms have security tools in place. They may use antivirus software, email filtering, cloud platforms, backups, and password requirements. But tools alone do not equal a cybersecurity program.
A strong security program should define how the firm protects client information, who is responsible for key decisions, how risks are reviewed, and what happens when something goes wrong.
Without written policies and procedures, firms may struggle to answer basic questions such as:
- Who is responsible for cybersecurity?
- How often are risks reviewed?
- How are employees trained?
- How is access to client data managed?
- What happens if an account is compromised?
- How are vendors evaluated?
- How are incidents documented and reported?
Regulators are not only looking for whether a firm owns security technology. They are looking for evidence that security is being managed in a structured and consistent way.
Weak Access Controls
Access control is one of the most important parts of protecting sensitive financial information.
If a firm cannot clearly explain who has access to client data, why they have access, and how that access is protected, that creates risk.
Common access control gaps include:
- Lack of multi-factor authentication
- Shared user accounts
- Weak or reused passwords
- Too many administrator accounts
- Former employees with active logins
- No regular access reviews
- Unsecured remote access
- Employees having access to files they no longer need
These issues can make it much easier for attackers to move through a firm’s systems after one account is compromised.
For financial firms, one stolen password can create serious exposure. A compromised email account, CRM login, document portal, or cloud storage account could give an attacker access to client records, financial documents, tax information, transaction details, or internal communications.
Multi-factor authentication is one of the most important safeguards firms can implement. It is not perfect, but it makes it much harder for a stolen password to become a full account takeover.
Firms should also review user access regularly and remove permissions that are no longer needed.
Poor Incident Response Planning
Many firms know a cyber incident is possible, but they have not clearly documented what they would do if one happened.
That can create confusion at the worst possible time.
An incident response plan helps a firm respond quickly and consistently when something goes wrong. It should outline who needs to be involved, how the issue will be investigated, how systems will be contained, and how client information will be assessed.
A basic incident response plan should answer questions such as:
- Who should employees contact if they suspect a breach?
- Who decides whether outside help is needed?
- How are affected systems isolated?
- How is client data reviewed?
- When should legal counsel, insurance, or regulators be contacted?
- Who communicates with clients if notification is required?
- How will the firm continue operating during downtime?
Financial firms should not be building their response plan during an active incident. By then, stress is high, information may be limited, and every delay can increase the impact.
Regulators are increasingly focused on whether firms are prepared to detect, respond to, and recover from unauthorized access to customer information. Having a written and tested incident response plan is a critical part of that preparation.
Vendor and Third-Party Risk
Financial firms rely on outside providers every day. These may include software vendors, cloud platforms, payroll providers, custodians, CRMs, accounting tools, document management systems, outsourced IT providers, and marketing platforms.
Those vendors can make operations more efficient, but they can also introduce risk.
If a vendor stores, processes, or has access to client information, the firm needs to understand how that information is protected. Outsourcing a service does not mean outsourcing responsibility.
Firms should ask important questions about vendors, including:
- What client data does the vendor access?
- How is that data protected?
- Does the vendor use multi-factor authentication?
- What happens if the vendor experiences a breach?
- How quickly will the firm be notified?
- Are security expectations included in the contract?
- Who reviews vendor access on an ongoing basis?
Vendor risk is especially important because attackers often look for weaker points in the chain. A firm may have strong internal controls, but a poorly managed vendor relationship can still create exposure.
Inadequate Employee Training
Employees remain one of the most common entry points for cyberattacks.
Financial firms are especially attractive targets for phishing, wire fraud, business email compromise, fake invoices, and impersonation scams. Attackers may pretend to be clients, executives, vendors, custodians, or other trusted contacts.
These attacks are becoming more convincing. AI-generated messages can sound polished, personal, and urgent. A fake email may reference a real transaction, mimic a familiar writing style, or pressure an employee to act quickly.
That is why employee training needs to be practical and ongoing.
Training should cover:
- Phishing emails
- Malicious attachments
- Fake login pages
- Wire transfer fraud
- Business email compromise
- Social engineering
- Password security
- Safe handling of client data
- AI-enabled scams
- Reporting suspicious activity
A once-a-year training session is better than nothing, but it is not enough on its own. Employees need regular reminders, real examples, and a clear process for reporting anything suspicious.
The goal is not to make employees afraid of every email. The goal is to help them pause, verify, and respond appropriately.
Backups That Are Not Tested
Many firms believe they are protected because they have backups.
The real question is whether those backups would work when needed.
Ransomware attacks, system failures, accidental deletions, and vendor outages can all disrupt operations. If a firm cannot restore critical systems and data quickly, the business impact can be significant.
Common backup and recovery gaps include:
- Backups are not tested
- Backups are connected to the same network
- Recovery time is unclear
- Critical systems are not prioritized
- Staff do not know what to do during downtime
- No documented business continuity plan
Having backups is not the same as having a recovery strategy.
Financial firms should know which systems need to be restored first, how long recovery may take, who is responsible for the process, and how the firm will continue serving clients if systems are unavailable.
Limited Monitoring and Detection
Prevention is important, but firms also need to know when something suspicious is happening.
Many cyber incidents become more damaging because attackers remain undetected for too long. They may access email accounts, move through systems, collect data, or wait for the right moment to launch fraud or ransomware.
Financial firms should consider stronger monitoring across:
- Email accounts
- Endpoints and devices
- Remote access tools
- Cloud applications
- File activity
- Login attempts
- Administrative accounts
Managed detection and response can be especially valuable for firms that do not have internal security teams. The goal is to identify unusual activity before it becomes a larger incident.
Connecticut Adds a State-Level Requirement on Top of Federal Rules
Financial firms in Connecticut face a regulatory layer beyond the FTC Safeguards Rule. Insurance-licensed firms — agencies, brokers, and carriers — are also subject to Connecticut’s cybersecurity requirements for insurers (Conn. Gen. Stat. § 38a-38), which adopted the NAIC Insurance Data Security Model Law. The statute requires a written information security program, a designated individual responsible for it, and incident notification to the Connecticut Insurance Commissioner — obligations that run parallel to, not instead of, federal Safeguards Rule requirements.
This matters most for the concentration of registered investment advisors, insurance agencies, and wealth management firms along the I-95 corridor in Stamford and Norwalk, where firms frequently carry both FTC Safeguards obligations and state insurance-license requirements at the same time. A security program built to satisfy only one framework typically leaves gaps in the other.
Kyber Security’s Managed IT Services for financial firms are built to satisfy both layers from the start — a single documented program, not two competing checklists.
What Financial Firms Should Do Next
Cybersecurity does not need to feel overwhelming, but it does need to be intentional.
Financial firms should prioritize the steps that reduce the most risk and support compliance expectations:
- Conduct a cybersecurity risk assessment
- Review regulatory and insurance requirements
- Require multi-factor authentication across critical systems
- Document a formal security program
- Create and test an incident response plan
- Review employee access and remove unnecessary permissions
- Evaluate vendor and third-party risk
- Train employees regularly
- Test backups and recovery procedures
- Improve monitoring across email, endpoints, and cloud systems
These steps help firms move from reactive security to a more structured cybersecurity program.
Cybersecurity Readiness Is Becoming a Business Requirement
Financial firms handle some of the most sensitive information clients have. That makes cybersecurity a core part of protecting trust.
In 2026, regulators, clients, vendors, and insurance carriers all want to see that firms are taking reasonable steps to protect data, manage risk, and respond effectively if something goes wrong.
The firms that wait until an incident happens may find themselves trying to solve technical, legal, operational, and reputational problems all at once.
Kyber Security helps financial firms assess their cybersecurity posture, identify security gaps, and build practical programs that support compliance, resilience, and client trust.
Compliance Support for Fairfield County Businesses
Kyber Security helps healthcare providers, financial services firms, and law firms throughout Bridgeport, Stamford, Norwalk, and the rest of Fairfield County, CT meet HIPAA, FTC Safeguards Rule, and other compliance requirements. Explore our Compliance services.

