You Can't Outsource the Risk: Reg S-P and Vendor Oversight
The SEC's amended Regulation S-P raises the bar on how investment advisors protect customer data — and the compliance timeline isn't moving. In this episode of the Ncast, Rafael DeLeon sits down with Tracy Soehle, Associate General Counsel at the Investment Advisors Association, to work through what the rule demands in practice: building an incident response program, meeting the 30-day notification requirement, and managing service providers in a regulatory environment that still leaves a lot open to interpretation. For RIAs, this isn't just a compliance exercise. It runs directly through fiduciary duty — and Tracy walks through how firms can meet that obligation while navigating vendor relationships that don't always cooperate. In this episode: The two most significant changes in amended Reg S-P: mandatory incident response programs and the 30-day customer notification requirement Why that 30-day clock is harder than it sounds — and what firms need in place before a breach happens What "reasonable assurances" from vendors actually means when the rule doesn't require it in the contract Which service providers will renegotiate and which won't — and how to document the diligence either way Why you can delegate notification to a vendor but can't delegate the liability Data mapping as the non-negotiable foundation of the entire program What SEC examiners are asking for and what "reasonably designed" has to mean in practice #ncontracts #regulation #regulationsp #sec #investment #dataprivacy #incidentresponse #vendormanagement #cybersecuritycompliance

Go Fast, Safely: What It Takes to Trust AI in Compliance

Creating Active Sellers Instead of Passive Partners

Trump Preps for 80th Birthday, Threatens to Hit Iran, Knicks Historic Win & Elon Musk Trillionaire!?

SBOA 110 - Bri Mendoza - Cybersecurity for Small Businesses: The Risks You're Probably Overlooking

Why Smart People Lose At Office Politics
![Company Training for NIS2, DORA, and ISO 27001 Training & Awareness [live webinar]](https://i.ytimg.com/vi/knzW3fAKBLw/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLArJNW3e3fZx_F-rLvnFHuYFnwLEw)
Company Training for NIS2, DORA, and ISO 27001 Training & Awareness [live webinar]

From Proactive to Reactive | LINK OH Preview | The Correspondent Podcast

Hotels Mag Webinar Series: The Digital Layer of Procurement Turning Spend Data Into Profitability

Designing Hospitals That Actually Heal - Episode 139 with Emily McGee

The Big Short (2015): The Jenga Scene – Explaining the Financial Collapse

LAWYER: If Cops Ask "Where Are You Coming From?" - Say These Words

Colette Dill-Lerner on Why Today’s CMO Role Has Changed

Conversation with Jennifer Cox, MHA, BSN, RN, PHN, CIC

Something is jamming GPS over Europe. Here's what we found

The French Do Not Care About Work

June 2026 Regulatory Update: Fair Banking, Fed Master Accounts & Credit Union Proposals

LIVE: Conan O’Brien speaks at Harvard graduation ceremony (full)

The Urgency Marathon

From Transactional to Transformational: Building an Employer Value Proposition That Works

