I would like to contribute briefly to the dialog on cybersecurity in wealth management.
Dozens of RIAs have already faced data breaches in 2025. Most of the conversation after an incident focuses on the breach. I think the more useful conversation is about what preceded it structurally.
RIAs are not banks. They do not have enterprise security teams. They are running lean ops, often with client data distributed across systems that were never designed to talk to each other. The threat surface is not just a perimeter problem. It is an organizational design problem.
The firms I talk to are not ignoring this. They are prioritizing. And cybersecurity often loses to the immediate operational fire in front of them: a transition, a merger, a new custodian, a compliance deadline.
I predict the regulatory pressure here accelerates faster than most RIA operators are currently planning for. Breach disclosure requirements are not getting looser. The reputational exposure is not getting smaller. And the gap between “we have strong perimeter security” and “we have a defensible data governance posture” is wider at most firms than anyone wants to admit.
The firms treating this as an infrastructure question now, not a crisis response question later, are building a different kind of durability.
https://citywire.com/ria/news/dozens-of-rias-have-already-faced-data-breaches-this-year/a2489356