Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupport
Contact Us
Search
Close

SEC Proposes Cybersecurity Risk Management Rules for Registered Funds and Advisers

By Edward McNicholas, Fran Faircloth & Briana Fasone on February 22, 2022
Email this postTweet this postLike this postShare this post on LinkedIn

On February 9, 2022, the SEC published a release addressing Cybersecurity Risk Management for Investment Advisers, Registered Investment Companies, and Business Development Companies (“Release”). The Release contained proposed new rules under the Advisers Act (Rules 206(4)-9 and 204-6) and the Investment Company Act of 1940 (Rule 38a-2) and amendments (collectively, the “Proposals”), which would require registered investment advisers (“advisers”) and registered investment companies (“registered funds”) to implement cybersecurity risk management programs and new incident notification regimes. If adopted, the Proposals would:

  • Require advisers and registered funds to disclose detailed information about their “cybersecurity risks” and “cybersecurity incidents” to current and prospective clients and shareholders;
  • Require reporting of any “significant adviser cybersecurity incidents” (which may occur with respect to private funds or clients) and “significant fund cybersecurity incidents” (for registered funds) to the SEC within 48 hours of reasonably concluding an incident occurred; and
  • Require advisers and registered funds to adopt and implement cybersecurity policies and procedures that are reasonably designed to address cybersecurity risks.

The proposed rules would not apply to private funds, which are exempt from the Investment Company Act of 1940 and thus are subject to the FTC’s Safeguards Rule for cybersecurity. The proposed SEC rules would, however, apply to registered investment advisers who advise those private funds. Fortunately, the proposed rules appear to be largely consistent with the FTC’s revised Safeguards Rule.

For more details, you can read Ropes & Gray’s client alert on the Proposals here.

Photo of Edward McNicholas Edward McNicholas
Read more about Edward McNicholasEmail
Photo of Fran Faircloth Fran Faircloth
Read more about Fran FairclothEmail
Photo of Briana Fasone Briana Fasone
Read more about Briana FasoneEmail
  • Posted in:
    Banking, Finance and Securities
  • Blog:
    RopesDataPhiles
  • Organization:
    Ropes & Gray
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
  • About LexBlog
  • The Field We Built
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo