
August 2026 | RIA Cybersecurity Services Utah | Managed IT Services Salt Lake City | SEC-Compliant IT Services Salt Lake City
Mike Tyson once said, "Everyone has a plan until they get punched in the mouth."
In financial advisory, that punch usually arrives as a disruption you assumed you were ready for — a failed backup, an unexpected outage or a security incident that exposes a weakness nobody knew existed.
That's the thing about assumptions. They feel like facts right up until they're tested. For Salt Lake City RIAs and wealth managers relying on advisory technology to serve clients and satisfy regulators, these are the four assumptions that most often cause the real damage.
Assumption #1: "We're Backed Up"
Having an untested backup is like carrying a spare tire in your trunk and discovering it's flat when you're stranded on the side of the road.
Most advisory firms know backups exist. They've seen the notifications and the green checkmarks. But few can confidently say when they last tested a restore of their Redtail CRM data, how long recovery of eMoney financial plans would actually take or whether every critical system is included in the backup scope.
When Redtail goes down before a scheduled client review — or when eMoney client financial plans and records become unavailable without warning — that's the moment the untested backup reveals itself. A backup proves its value only when it successfully restores client financial data. The most dangerous backup is the one you've never tested.
IT support for financial advisors in Salt Lake City should include regular restore testing — not just backup confirmation. Knowing that data was copied is not the same as knowing it can be recovered.
Assumption #2: "Our Custodian Handles Our Client Data"
This is one of the most common — and most costly — assumptions in the advisory space.
Your custodian — whether that's Schwab, Fidelity, TD or another institution — manages the custody of client assets. They do not manage your firm's CRM records, financial planning files, client correspondence or compliance documentation.
Redtail, Wealthbox, eMoney, MoneyGuidePro, RightCapital, Smarsh — these platforms hold data your firm is responsible for backing up and protecting. If Redtail experiences an outage or your firm loses access to Wealthbox, your custodian cannot restore that data. That responsibility sits with your firm.
The SEC's cybersecurity guidance makes this clear: registered investment advisers are responsible for the integrity and availability of their own records. Assuming your custodian covers that responsibility leaves a gap that examiners will find.
Assumption #3: "Our Advisory Team Knows the SEC Incident Response Steps"
Every advisory team looks prepared — until the moment they actually need to respond.
Picture this: A critical system goes offline on a Friday afternoon during client review season. Suddenly nobody can agree on who's in charge, what to restore first or how long recovery will take. And nobody is sure what the SEC requires the firm to document about the incident.
When there's no documented incident response plan and no practice run, even a capable advisory team is starting from zero. The SEC expects registered investment advisers to have written policies and procedures — including how they respond to cybersecurity incidents. "Our team will figure it out" does not satisfy that requirement.
You don't run a fire drill because you expect the building to burn down tomorrow. You do it so that if there ever is a fire, nobody is standing around asking which way to run. A documented and tested incident response plan works exactly the same way for an advisory firm.
When something goes wrong, you want your advisory team executing a plan they already know — not figuring things out under pressure while also trying to determine what the SEC needs to be notified about.
Assumption #4: "We Won't Be Targeted"
Nobody thinks they'll be the one. Until they are.
When your advisory team is focused on client relationships, portfolio management and compliance, a cyberattack feels like something that happens to other firms. But client financial data is among the most valuable information a cybercriminal can target. The combination of account numbers, tax information, social security numbers, investment holdings and wire transfer authority makes advisory firms a high-value target.
Business email compromise targeting financial advisors is one of the fastest-growing fraud vectors in the industry. An attacker who gains access to an advisor's email can impersonate the advisor, request fraudulent wire transfers and damage client relationships in ways that take years to repair.
SEC-compliant IT services in Salt Lake City start with the recognition that advisory firms hold data worth protecting — and that the question is never whether a disruption will occur, but whether your firm is prepared when it does. The firms that recover fastest aren't the ones that avoided the incident. They're the ones that expected it.
Frequently Asked Questions
What's the difference between backup and disaster recovery for an advisory firm?
Backup is the process of copying and storing client financial data, CRM records and financial plans. Disaster recovery is the documented plan for restoring that data and getting advisory systems back online after an incident. You need both — and both need to be tested to satisfy SEC and FINRA expectations.
How often should Salt Lake City advisory firms test their backups?
At minimum, quarterly. Advisory firms with compliance requirements or large volumes of client financial data should test more frequently. The goal is to verify that backups restore completely and within an acceptable timeframe — and to document those results in a way that supports your incident response plan.
Do you offer SEC and FINRA-compliant IT services for financial advisory firms in Salt Lake City?
Yes. Qual IT provides RIA cybersecurity services in Utah and SEC-compliant IT services for Salt Lake City financial advisors, including backup testing, incident response planning, email archiving support for Smarsh and Global Relay, and cybersecurity aligned with regulatory requirements.
You Can't Block a Punch You Didn't Prepare For
It's rarely the dramatic event that catches advisory firms off guard — it's the ordinary ones that hit on a Wednesday during client review season when nobody is expecting it.
The good news is that most of these risks can be addressed before they become compliance problems or client relationship failures. That's exactly what Qual IT helps Salt Lake City financial advisors do.
We work with Salt Lake City financial advisors to meet SEC and FINRA requirements and protect client data — starting with an honest look at what assumptions your firm is currently operating on.
Schedule a 10-minute discovery call to walk through your backups, recovery process and incident response plan. We'll identify what's been tested, what hasn't and where the gaps are. Book your discovery call here.

