
October 2026 | RIA Cybersecurity Services Utah | Cybersecurity Awareness Month | Security Myths
October is Cybersecurity Awareness Month - a good time for your advisory firm to take stock of what you actually know versus what you think you know about protecting client financial data. Not all of the advice circulating among Salt Lake City RIAs and wealth managers is accurate. Some of it has been repeated at conferences and in study groups for so long that it sounds like fact, even when it's outdated or wrong.
When bad advice goes unchallenged, it creates blind spots. And blind spots are exactly what cybercriminals - and SEC examiners - look for. Knowledge gaps and comfortable assumptions are what make advisory firms easy targets, not the makeup of their book of business or where their office sits.
The good news is that these gaps are simple to close once you know where they are. Here are six myths we hear from financial advisors regularly, along with the truth behind each one.
Myth 1: "Hackers Target Banks and Custodians, Not Advisory Firms"
It's tempting to assume attackers go after the institutions holding the assets. But an RIA holds something just as valuable: the keys to client wealth. Your firm sits on account numbers, Social Security numbers, statements, beneficiary details and the standing authority to move money at the custodian. Compromise one advisor's email and an attacker can work toward every client household in your CRM.
Regulators know this, which is why SEC and FINRA cybersecurity requirements apply squarely to advisory firms - and why examiners increasingly expect firms to demonstrate they understand their own risk profile.
Fact: Cybercriminals choose targets based on opportunity, and advisory firms are a prime one.
Myth 2: "Our Advisors Will Recognize a Phishing Email"
The days of obvious phishing emails full of typos are gone. Today's messages are polished and personalized - a fake custodian security notice, a spoofed "document ready for review" alert that looks like it came from Redtail or ShareFile, or an email that appears to be from a longtime client asking about their account.
Thanks to AI, it's become harder to catch a scam from the text alone. Instead, your advisory team needs to think about sender behavior. Ask whether the supposed sender would:
- Make an unusual request, like moving funds to a new account
- Change wire or distribution instructions
- Request sensitive client financial data or login credentials
- Send a new or unusual login link for your custodian or portfolio platform
If anything seems off, verify through a second channel before clicking or responding.
Fact: A convincing email can still be a scam - even one that looks like it came from your custodian or a client.
Myth 3: "MFA Fully Protects Our Accounts"
Multi-factor authentication (MFA) is essential - your custodians likely require it, and examiners expect it. But it's not invulnerable. Attackers use MFA fatigue to their advantage, counting on staff approving requests out of habit. "Prompt bombing" floods a phone with requests in hopes someone will approve access to your CRM or portfolio management system just to make them stop.
MFA is a tool, not a shield. Attackers are finding ways around weaker authentication methods, which is why MFA needs support from the security controls around it.
Fact: MFA should be part of a broader, documented cybersecurity program - the kind the SEC expects to see.
Myth 4: "Our Backups Have Us Covered"
Ask yourself: if your firm was hit with a ransomware attack tomorrow, could you actually restore your client financial data? Your CRM records in Redtail or Wealthbox, your financial plans in eMoney or MoneyGuidePro, your reporting history in Orion or Black Diamond, your signed agreements and account paperwork - how long would it take to get them back?
A backup is great when you know it's going to work. An untested backup isn't something you can rely on during an incident - and days of downtime during a market swing is not a position any fiduciary wants to explain to clients.
Fact: Having backups is not the same as being able to recover.
Myth 5: "Cybersecurity Is IT's Job - or Compliance's"
Your IT provider and your CCO both play critical roles, but neither can control every click your advisory team makes. Cybersecurity decisions happen at every desk - an advisor opening an attachment, an operations associate processing a money movement request, a paraplanner logging into a planning tool. It takes only one bad click to expose client financial data.
And when something goes wrong, the SEC doesn't hold your IT vendor accountable. It holds the firm accountable. Employee security awareness training turns everyone in the office into part of your defenses instead of the gap in them.
Fact: Training your advisory team to make good decisions strengthens both your security posture and your compliance posture.
Myth 6: "We'd Know What to Do If Something Happens"
It's Tuesday morning. Your team suddenly can't access the CRM, and a client calls about an email they received "from your office." Many firms discover in that exact moment that nobody has answered the basic questions:
- Should staff shut down their computers?
- Who calls IT - and who calls the custodian to freeze money movement?
- What do you do if email is compromised and you can't trust it?
- When do the cyber insurance carrier and legal counsel get involved?
- Who communicates with clients and regulators - and how?
Don't rely on memory in the moment. The SEC expects advisory firms to maintain a documented incident response plan - improvising during an incident isn't just risky, it's an exam deficiency waiting to be written up.
Fact: Your incident response plan shouldn't debut during an incident - or during an SEC exam.
Frequently Asked Questions
Do you offer SEC and FINRA-compliant IT services for financial advisory firms in Salt Lake City?
Yes. Qual IT provides IT support for financial advisors in Salt Lake City, including SEC-compliant IT services: threat detection and response, email security and archiving support, phishing protection, employee security awareness training, MFA implementation, documented policies and incident response planning aligned with SEC and FINRA cybersecurity requirements.
What is the biggest cybersecurity mistake advisory firms make?
Assuming they're covered without verifying it. Untested backups, unexamined assumptions about staff readiness and security tools nobody monitors create a false sense of protection - which is often more dangerous than a known gap, and harder to defend during an examination.
How do I know if my firm's cybersecurity is actually working?
Through testing and review: verified restores of client financial data, simulated phishing exercises for your advisory team, and a periodic assessment of your tools, policies and response plans by an IT partner who understands what RIA cybersecurity requires.
Cybersecurity Awareness Starts With the Facts
Cybersecurity Awareness Month is about making sure the assumptions guiding your firm's decisions are correct. Myths are comfortable - they let you feel covered without digging deeper. But cybersecurity gaps rarely come from a missing product. They come from believing you've already got it handled when you don't - and your fiduciary responsibility to clients doesn't leave room for that assumption.
We work with Salt Lake City financial advisors to meet SEC/FINRA requirements and protect client data. If any of these myths sound familiar, it's time to take a closer look at where your firm stands.
Schedule a free 10-minute discovery call with Qual IT and we'll help you separate what's protecting you from what's only giving you peace of mind. Book your discovery call here.

