The 15-Minute Meeting Every Salt Lake City Financial Advisory Firm Should Have This Month

September 2026 | IT Support for Financial Advisors Salt Lake City | National Preparedness Month | SEC Incident Response Planning

If an unexpected disruption hit your Salt Lake City advisory firm tomorrow, would your team handle it with confidence?

You may assume the answer is yes. But many RIAs and wealth management firms don't discover gaps in communication, decision-making and operational planning until they're responding to a disruption in real time --- which is the most expensive possible moment to learn. And for financial advisors, there's an added layer: the SEC expects registered firms to maintain written incident response plans. "We would have figured it out" is not an answer an examiner accepts.

September is National Preparedness Month, making this the perfect time to take a hard look at your firm's readiness. The good news: you don't need an all-day planning session or a full managed IT services audit to get started. You need 15 minutes, the right people in the room and five direct questions. For an advisory firm, this meeting isn't just a best practice --- it's the foundation of a regulatory requirement.

Question 1: If Our Firm Stopped Operating Tomorrow, What Needs to Be Restored First?

You already know which tools your advisory team relies on every day. But recovery planning requires a more specific answer. If operations stopped tomorrow, your team would need to know which functions protect clients, revenue and daily work first.

For most advisory firms, that means three things: access to your CRM --- whether that's Redtail, Wealthbox or Salesforce Financial Services Cloud --- so you know who needs what; your portfolio management platform, whether Orion, Black Diamond or Tamarac, so you can see positions and respond to markets; and client communication, so a market-moving day doesn't pass in silence. Custodian portal access and financial planning tools like eMoney or MoneyGuidePro follow close behind.

When you define those priorities early, your team can focus on what matters most to clients instead of trying to restore everything at once.

Question 2: Who Makes Decisions During a Disruption?

Pressure has a way of quickly exposing unclear ownership. When people don't know who can make the call, they wait for approval, duplicate work or pull the managing partner into separate conversations that slow the response.

Your advisory team should know who starts the response, who updates staff, who communicates with clients, and who works with your custodian, your software vendors and your IT support partner. Here's the part many firms miss: the SEC expects documented incident response ownership. If your written policies name a responsible party and that person --- and their backup --- can't describe their role, that's a finding waiting to happen in your next exam.

Clear decision-making roles help people act with confidence when normal routines break down --- and they demonstrate to regulators that your plan exists in practice, not just on paper.

Question 3: How Would We Communicate If Our Normal Tools Weren't Available?

Email, phones and collaboration platforms feel dependable until they stop working. Then even simple communication becomes harder than it should be --- and for an advisory firm, harder in a very specific way.

If your advisory team couldn't access firm email, would they know where to look for instructions? If your phone system failed, how would clients reach you during a volatile market day? And here's the compliance wrinkle: any backup channel you use for client communication still falls under your books-and-records obligations. If advisors switch to personal email or text messages during an outage, those communications must still be captured by your archiving platform --- Smarsh, Global Relay or whatever your firm uses. Off-channel communications have been the subject of major SEC enforcement actions, and an outage is not an exemption.

A backup communication plan doesn't need to be complex. It needs to give your team and your clients a dependable, compliant place to turn when the usual channels aren't available.

Question 4: What's Our Biggest Operational Dependency?

Some risks hide in plain sight because they support the firm every day without drawing attention.

For advisory firms, the usual suspects are custodian connectivity, the portfolio management platform that feeds every client conversation, the integrations that move client financial data between your CRM and planning tools --- or the one operations person who is the only one who knows how billing runs, how the Orion download gets fixed when it breaks, or where the ACAT paperwork process is documented.

If your firm depends heavily on one system, one vendor or one person, it's critical to understand what happens when that dependency suddenly isn't available. This clarity helps you decide where documentation, testing, backup options or outside IT support could reduce avoidable risk --- and it feeds directly into the vendor due diligence the SEC increasingly expects.

Question 5: If a Disruption Hit Tomorrow, What Would We Wish We'd Prepared Today?

This question cuts through assumptions because it puts your leadership team inside the moment they're trying to avoid.

Your firm may wish it had documented an operations process, tested backups of client financial data, updated client and custodian contact lists, identified responsibilities or agreed on the order in which systems come back online. None of those tasks sound dramatic during a normal week --- which is exactly why firms push them aside until an examiner or an incident forces the issue.

Preparation gives you room to respond instead of react. The best incident response plans answer questions before anyone --- including the SEC --- has to ask them.

Where an IT Partner for Advisory Firms Comes In

After working through these five questions, you'll know which answers feel solid and which rely on assumptions.

That's where the right provider makes the difference. A firm offering RIA cybersecurity services in Utah helps identify operational risks, test recovery processes, verify backups of client financial data, document key systems and align your technology with SEC and FINRA cybersecurity requirements --- so your written policies describe what actually happens, not what someone hoped would happen.

The point isn't to make preparedness feel technical. It's to help you understand how systems, people and processes work together when pressure hits --- and to protect the client trust your entire practice is built on.

Frequently Asked Questions

Do you offer SEC and FINRA-compliant IT services for financial advisory firms in Salt Lake City?

Yes. Qual IT provides SEC-compliant IT services in Salt Lake City for RIAs, wealth managers and financial advisory firms --- including written incident response planning support, cybersecurity controls, backup and recovery testing, and documentation that stands up to regulatory examination.

Why does the SEC expect advisory firms to have a written incident response plan?

Because client financial data is among the most valuable targets for attackers, and regulators know improvised responses fail. A documented, tested incident response plan --- with named decision-makers --- is part of your fiduciary responsibility and a standard focus area in SEC exams.

How does Qual IT help advisory firms with preparedness planning?

Qual IT works with Salt Lake City advisory firms to identify operational risks, test backup and recovery of CRM and portfolio data, document critical systems and dependencies, and build incident response plans your team can actually execute under pressure.

Put This Meeting on Your Calendar

Don't wait to schedule this 15-minute conversation. If your leadership team can answer all five questions clearly, you have a strong sense of how your firm would respond under pressure --- and solid footing for your next exam. If some answers feel uncertain, you've found gaps worth addressing before they affect clients or appear in a deficiency letter.

We work with Salt Lake City financial advisors to meet SEC/FINRA requirements and protect client data.

Schedule a 10-minute discovery call with Qual IT to identify potential gaps, strengthen your incident response plan and build a recovery strategy that protects your clients before you need it. Book your discovery call here.