Cybersecurity Requirements for Dallas Financial Services Firms

Dallas financial services firms fall under the FTC Safeguards Rule, SEC Regulation S-P, FINRA supervision, or some combination of the three, decided by what a firm does rather than what it calls itself. Texas then stacks two more obligations on top of whichever federal rule applies.

Short version. Most firms shopping for financial services IT in Dallas assume one regulator owns them. Two or three usually do. The security controls overlap heavily, which is the easy part. The breach notification deadlines do not overlap at all, and they start counting from four different events. Fix the map before you fix the tooling.

Almost every compliance conversation I have with a Dallas firm opens in the wrong place. Someone asks which security tools they need to buy. That is the last question, not the first. By a distance.

The first question is which rulebook the firm is in. That sounds like paperwork. It is not. A Richardson mortgage brokerage, a Preston Center advisory firm managing $80 million, and a Las Colinas broker-dealer are three different regulatory animals, and two of the three are usually surprised to hear they are regulated for cybersecurity at all. One of them is not even sure it counts as a financial institution. That is not a hypothetical. It comes up most months.

It does. So this walks the actual map. Who is covered, by which rule, what each one demands in writing, and what happens to your calendar the day something goes wrong. Every requirement below is cited to the rule text rather than to somebody’s summary of it. The summaries are where most of the bad advice starts.

Which cybersecurity rules apply to a Dallas financial services firm?

Cybersecurity requirements for Dallas financial services firms come from four places. The FTC Safeguards Rule under Gramm-Leach-Bliley covers non-bank financial institutions. SEC Regulation S-P covers SEC registrants. FINRA supervises broker-dealers. Texas law adds a breach notification statute and a securities filing that most firms have never heard of.

They are not alternatives. Not even close. A single Dallas firm can sit under three of the four simultaneously, and the overlap is not tidy. Here is how the four sort out.

RuleWho it reaches in DallasCore obligationIn force since
FTC Safeguards Rule, 16 CFR 314Non-bank financial institutions. Mortgage brokers, tax preparers, appraisers, title and settlement firms, state-registered advisers, auto dealers with a finance deskA written information security program with 9 required elements plus FTC breach notificationAmended program elements since June 2023, notification since May 2024
SEC Regulation S-P, 17 CFR 248.30Broker-dealers, SEC-registered investment advisers, funds, transfer agents, funding portalsA written incident response program, 30-day customer notice, service provider oversight, recordkeepingLarger entities December 3 2025, smaller entities June 3 2026
FINRA supervisionMember broker-dealersSupervisory system covering cyber risk and outsourced activity under Rules 3110 and 4370Ongoing, with the 2026 examination priorities published December 9 2025
Texas lawAny firm doing business in Texas, plus Texas-registered dealers and advisers specificallyBreach notice under Business and Commerce Code 521.053, plus notice to the Texas Securities Commissioner under 7 TAC 115.23 and 116.23521.053 as amended 2023, the securities rules since February 27 2020

The quickest way to place your own firm. Ask 2 questions. Does anything the firm does appear in the activity list at 16 CFR 314.2(h)(2)? And is the firm registered with the SEC, with FINRA, or with the Texas State Securities Board? A yes to the first puts you under the Safeguards Rule regardless of the answer to the second.

The Safeguards Rule reaches further into Dallas than most firms expect

Compliance officer and firm principal working through stacked regulation binders and printed rule documents at a Dallas conference table

The Safeguards Rule does not ask what your firm is called. It asks what your firm does. That distinction is deliberate. The definition at 314.2(h)(1) covers any institution “the business of which is engaging in an activity that is financial in nature or incidental to such financial activities” under the Bank Holding Company Act, and then the rule spells out 13 worked examples so there is no room to argue.

Several of those examples catch Dallas businesses that would never describe themselves as financial institutions. Here are 8 of them.

  • A real estate or personal property appraiser, because appraisal is a listed financial activity
  • A firm providing real estate settlement services, which sweeps in a large share of the North Texas title industry
  • A mortgage broker, because brokering loans is a financial activity
  • An accountant or tax preparation service in the business of completing income tax returns
  • An automobile dealership that leases vehicles on a nonoperating basis for longer than 90 days, with respect to its leasing business
  • An investment advisory company or credit counseling service, including advisers too small to register with the SEC
  • A company acting as a finder, bringing buyers and sellers together for deals the parties negotiate themselves
  • A career counselor specializing in placements inside finance, accounting or audit departments

That last one always gets a reaction in the room. It is in the rule. Word for word.

The scale of the gap shows up in the labor numbers. Dallas-Fort Worth carried 392,000 financial activities jobs in June 2026, of which 297,100 sat in finance and insurance on preliminary Bureau of Labor Statistics figures. The roughly 95,000 job difference is real estate, rental and leasing. That is precisely the population the Safeguards Rule reaches through appraisal, settlement services and mortgage brokerage, and precisely the population least likely to have a Qualified Individual on paper. That gap is the story.

The fewer than 5,000 consumers exception is narrower than it reads

This is the single most misread provision in the rule, and I have seen it cost firms real money. The exception at 314.6 is one sentence long. It says that “Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.” Four paragraphs. That is the entire relief. Nothing else moves.

Almost every summary I have read describes this as the risk assessment being waived. Read the citation again. It waives 314.4(b)(1), which is the requirement that the risk assessment be written and contain 3 specific criteria. The assessment itself survives. So does 314.4(b)(2), the duty to periodically perform additional ones.

RequirementUnder 5,000 consumersWhat that actually means
Written risk assessment, 314.4(b)(1)WaivedYou still have to do a risk assessment. You just are not compelled to document it in the prescribed format
Continuous monitoring, or annual pen test plus 6-monthly vulnerability assessment, 314.4(d)(2)WaivedThe general duty to regularly test safeguards under 314.4(d)(1) is unchanged
Written incident response plan, 314.4(h)WaivedYou are excused from writing the plan and still bound by the 30-day FTC filing that a real incident triggers
Annual written report to the board, 314.4(i)WaivedNothing removes the need for a Qualified Individual to actually oversee the program
Qualified Individual, MFA, encryption, disposal, service provider oversight, FTC notificationAll still requiredEverything in 314.4(a), (c), (e), (f), (g) and (j) applies at any size

The trap in that table. Paragraph (j) is not on the waiver list. A firm holding information on 4,000 consumers is excused from writing an incident response plan, and is still required to notify the FTC within 30 days of discovering an event touching 500 or more of them. 500 out of 4,000 is one bad mailbox. The exception removes the plan and leaves the deadline.

What the Safeguards Rule actually requires, paragraph by paragraph

Strip the rule to its operative parts and you get 9 obligations. Nine. Not nineteen. The FTC’s own guidance groups them the same way. What follows is the plain-language read, with the detail that trips firms up.

ParagraphRequirementThe detail firms miss
314.4(a)Designate a Qualified Individual to oversee and enforce the programThe role can sit with a service provider, but you retain compliance responsibility and must name a senior person internally to direct and oversee them
314.4(b)Base the program on a risk assessment and repeat it periodicallyPeriodic is not defined. Annual is the defensible reading, and a material change to the business restarts it
314.4(c)(3)Encrypt all customer information in transit over external networks and at restIf encryption is infeasible, compensating controls must be reviewed and approved by the Qualified Individual
314.4(c)(5)Implement multi-factor authentication for any individual accessing any information systemAny individual. Any system. An exception needs written approval from the Qualified Individual for controls that are equivalent or better
314.4(c)(6)Securely dispose of customer information within 2 years of last useA hard deadline that almost no small firm tracks, plus a periodic review of the retention policy itself
314.4(d)Test and monitor the effectiveness of key controlsContinuous monitoring, or annual penetration testing plus vulnerability assessments at least every 6 months
314.4(e)Train personnel and keep security staff currentTwo separate duties. General awareness training for everyone, and ongoing technical currency for whoever runs security
314.4(f)Oversee service providersSelect capable providers, bind them by contract, and periodically reassess them. The reassessment is the part that never happens
314.4(j)Notify the FTC of a notification event affecting 500 or more consumersWithin 30 days of discovery, electronically, with 6 prescribed fields

If you are SEC-registered, Regulation S-P is already live

The 2024 amendments to Regulation S-P are no longer a future problem for anyone. Larger entities had to comply by December 3, 2025. Smaller entities had until June 3, 2026, which has now passed. If your firm is an SEC-registered adviser under $1.5 billion in assets under management, you were in the second group. The deadline is behind you.

The adopting release imposes 4 things. A written incident response program reasonably designed to detect, respond to and recover from unauthorized access to customer information. Notification to affected individuals. Oversight of service providers, including a duty to be notified by them. And records. Records proving the other 3 actually happened.

The notification piece is where firms get caught. You have 30 days from becoming aware that unauthorized access has occurred, or is reasonably likely to have occurred, to notify affected individuals. There is an off-ramp. If a reasonable investigation determines that sensitive customer information has not been and is not reasonably likely to be used in a way causing substantial harm or inconvenience, notice is not required. Note the shape of that. You have to run the investigation to earn the exemption. The clock does not pause.

The enforcement signal is not subtle either. In January 2025 Robinhood’s broker-dealer entities paid $45 million in combined civil penalties over Regulation S-P and Regulation S-ID failures. Read that figure twice. That was under the old rule. The amended one is stricter.

What FINRA is examining in 2026

Two financial services executives standing in a glass meeting room discussing a third party vendor review, one holding a closed navy folio

FINRA published its 2026 Annual Regulatory Oversight Report on December 9, 2025. For member firms in Dallas the cybersecurity section is the one to read, and it anchors on Rules 3110 and 4370 rather than on any new cyber-specific rule. Supervision and business continuity are the hooks. They always were. No new rule was needed.

The threat list is specific and worth mapping against your own controls. Every entry is named.

  • Ransomware and extortion, including stolen data held for ransom rather than encrypted in place
  • Data breaches exposing firm or customer personal information
  • Phishing, smishing and quishing, the last one delivered through QR codes
  • New account fraud using falsified or stolen identity information
  • Account takeovers using compromised customer credentials
  • Account impersonation combining stolen customer data with a spoofed or compromised email address
  • Imposter websites and spoofed social media profiles
  • Insider threats, whether deliberate or accidental

Two entries there are not really IT problems. New account fraud and account impersonation are operational controls wearing a cyber label, which is why FINRA’s effective practices include verifying email addresses and signatures on third-party fund transfer requests, and coordinating the cyber and anti-money-laundering teams. If your provider treats those as somebody else’s job, that gap is yours. Nobody else is closing it.

Third-party risk gets its own treatment, and the framing is blunt. Attacks and outages at vendors now disrupt many firms at once because the industry leans on the same handful of providers. FINRA expects due diligence at onboarding and on an ongoing basis, an inventory of which data types each vendor touches, and active monitoring of vendors for breaches and vulnerabilities. An inventory is the piece most firms cannot produce on request. Start there. It is the cheapest of the three anyway.

Four breach clocks, and they do not start together

Four analog wall clocks in a row on a navy office wall each showing a different time, representing four separate breach notification deadlines

This is the part that separates a compliant Dallas firm from one that merely owns compliant software. After an incident, a firm can owe 4 different notifications, on 4 different deadlines, each measured from a different triggering event. They are not synchronized. Nobody harmonized them.

NotificationWho you tellDeadlineThe clock starts when
FTC Safeguards Rule 314.4(j)The Federal Trade Commission, at 500 or more consumers30 daysYou discover the event. Deemed discovered the first day it is known to any employee, officer or agent other than the person who did it
SEC Regulation S-PAffected individuals30 daysYou become aware that unauthorized access occurred or is reasonably likely to have occurred
Texas Business and Commerce Code 521.053(i)The Texas Attorney General, at 250 or more Texas residents30 daysYou determine that the breach occurred
Texas Business and Commerce Code 521.053(b)Affected individuals60 daysYou determine that the breach occurred
7 TAC 115.23 and 116.23The Texas Securities Commissioner, for Texas-registered dealers and advisersSimultaneouslyAny of the notices above goes out. There is no separate countdown

Read the fourth column, not the third. Discovery, awareness and determination are three different moments. Three. In a real incident they can be days or weeks apart. A firm that discovers suspicious access on a Monday, becomes aware it involved customer data on Thursday, and formally determines a breach occurred the following month has already burned most of its federal window while the state clock has not started.

The Texas securities rules are the ones nobody sees coming. Under 7 TAC 116.23 for investment advisers and 7 TAC 115.23 for dealers, a registered firm must notify the Securities Commissioner “at the time” any other required notice goes out, whenever the event does or may affect customers located in Texas. It is a derivative trigger. It has no grace period. There is no countdown to grant one. Both rules took effect on February 27, 2020, and both define information system to include systems maintained by a third party at the firm’s direction. A vendor incident counts.

The practical fix is boring and it works. Put all 4 notifications on one page of the incident response plan, each with its own trigger word circled, and name the person who files each one. When a real incident lands, nobody is reading regulations. They are reading whatever you wrote down in advance. That page is the deliverable, not the 40-page policy it sits inside.

What Texas adds beyond the federal rules

Texas has no equivalent of the New York cybersecurity regulation, and Dallas firms sometimes take that as meaning the state is quiet on the subject. It is not. Just scattered. The requirements sit in 3 separate places rather than one rule.

The breach statute is the broadest. Section 521.053 reaches anyone conducting business in Texas who owns or licenses sensitive personal information in computerized form. Disclosure to individuals must happen “without unreasonable delay and in each case not later than the 60th day” after determining a breach occurred, and the Attorney General must be told “as soon as practicable and not later than the 30th day” when 250 or more Texas residents are involved. So the state filing comes due before the consumer letters. It surprises people.

The securities rules are covered above. Third piece. The safe harbor.

Senate Bill 2610 took effect September 1, 2025 and added Chapter 542 to the Business and Commerce Code. A Texas business entity with fewer than 250 employees that maintains a compliant cybersecurity program gets an affirmative defense, and a person harmed by a breach “may not recover exemplary damages” from it. The requirements scale by headcount.

  • Under 20 employees. Simplified requirements including password policies and appropriate employee cybersecurity training
  • 20 to 99 employees. The Center for Internet Security Controls Implementation Group 1
  • 100 to 249 employees. An industry-recognized framework such as NIST or the ISO 27000 series

Be precise about what that buys. It caps exemplary damages only. Actual damages, regulatory penalties and the cost of notifying everyone are all untouched. And because it is an affirmative defense, your lawyers have to prove the program existed before the breach, using dated policies, deployment records and training logs. A program you can describe but not date is worth nothing here. Nothing at all.

Encryption changes the definition, not just the odds

Heavy steel bank vault door standing partly open in a darkened corridor, illustrating encryption of customer information at rest

Most people file encryption under reducing damage. Under the Safeguards Rule it does something stronger. Much stronger. It changes whether the event is reportable at all.

A notification event at 314.2(m) means “acquisition of unencrypted customer information without the authorization of the individual to which the information pertains.” Encrypted data acquired by an attacker is not a notification event. There is a catch in the same paragraph. Information counts as unencrypted if the encryption key was accessed by an unauthorized person, so key custody matters as much as the ciphers do.

There is a second sentence in that definition worth reading slowly, because it runs against you. “Unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless you have reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of such information.” Access is presumed to be acquisition. The burden is yours. You rebut it with logs.

That single sentence is the strongest argument for detailed access logging in any financial firm I work with. Not because logs prevent a breach. They do not. Because without them, every unauthorized access becomes a reportable acquisition by default, and a contained incident turns into a filing, a customer letter and a Texas Securities Commissioner notice on the same afternoon.

Where Dallas financial firms most often fall short

Across the financial firms we assess in North Texas, the failures cluster. It is rarely the firewall. It almost never is.

  • No named Qualified Individual. Everyone assumes the IT provider is it, and the provider assumes the compliance officer is it. 314.4(a) requires an actual designation, and if the role sits with a provider you must also name the senior person overseeing them
  • MFA covering email and nothing else. The rule says any individual accessing any information system. Portfolio accounting, the CRM, the document vault and remote access all count
  • Vendors onboarded once and never reassessed. 314.4(f)(3) and the FINRA report both call for periodic reassessment, and both are usually answered with a service organization control report from 3 years ago
  • Retention with no disposal. Old client files kept indefinitely because storage is cheap, against a 2-year disposal clock in 314.4(c)(6) and an evidence problem in any breach
  • An incident response plan with no notification page. Plenty of firms have a plan. Very few have the 4 clocks written down with names next to them

Here is the honest version of the advice. None of these are expensive to fix. They are unglamorous, they need someone to own them, and they are exactly what an examiner asks for first because they are cheap to verify. A firm with excellent tooling and no designation letter looks worse on paper than a firm with modest tooling and a tidy binder. Every time.

If you want the wider picture of how this fits an operating IT program, our page on cybersecurity services in Dallas covers the control side, and the guide to FFIEC compliance covers what changes once a bank charter is in the picture. Firms already running a security operation usually get here through a managed security services provider in Dallas rather than by hiring for it.

Not sure which of these 4 rulebooks your firm is in?

We map the applicable requirements against what your firm already has, name the gaps, and hand you the notification page for your incident response plan. It takes about a week and you keep the documentation either way.

Request a compliance gap review

Questions Dallas financial firms ask us

Does the FTC Safeguards Rule apply to a Dallas RIA managing under $100 million?

Yes. The Safeguards Rule lists an investment advisory company as a financial institution, and it specifically reaches advisers that are not required to register with the SEC.

That is the group most likely to think it has no federal cybersecurity obligation. A Texas state-registered adviser sits outside Regulation S-P and squarely inside 16 CFR 314. It also picks up the notice duty under 7 TAC 116.23. Both apply.

How fast does a Dallas firm have to report a data breach?

It depends which notification you mean. Texas gives you 60 days to tell individuals and 30 days to tell the Attorney General at 250 or more Texas residents. The FTC also wants 30 days at 500 or more consumers.

The deadlines are less important than the trigger events, which are all different. Texas counts from when you determine a breach occurred, the FTC counts from discovery, and Regulation S-P counts from when you became aware. Build the plan around the triggers. Not the deadlines.

We have fewer than 5,000 clients. Do we still need a written incident response plan?

No, but the relief is narrow. Section 314.6 waives the written plan requirement at 314.4(h) for firms maintaining customer information on fewer than 5,000 consumers.

Everything else about an incident survives. You still have to notify the FTC within 30 days of discovering an event touching 500 or more consumers, and a firm that size can easily have one. We recommend writing it anyway. The alternative is improvising during the worst week of the year.

If our data is encrypted, do we avoid breach notification entirely?

Under the Safeguards Rule, largely yes. A notification event is defined as acquisition of unencrypted customer information, so properly encrypted data that is stolen is not a reportable event.

Two conditions attach. The data counts as unencrypted if an unauthorized person reached the encryption key, and unauthorized access to unencrypted information is presumed to be acquisition unless you hold reliable evidence otherwise. Texas breach law and Regulation S-P run on their own definitions, so encryption helps everywhere but does not switch off all 4 clocks at once. Check each one separately.

What is FINRA expecting us to do about our technology vendors?

Ongoing due diligence rather than a one-time check. The 2026 oversight report asks for initial and continuing diligence on vendors supporting mission-critical systems, an inventory of the data each vendor touches, and monitoring for vendor breaches.

The inventory is the practical starting point and it is the one most firms cannot produce on demand. It also feeds the Safeguards Rule requirement at 314.4(f)(3) to periodically reassess providers, so the same document answers 2 regulators. Build it once.

Will the Texas safe harbor protect our firm if we get sued after a breach?

Partly. Senate Bill 2610 gives a Texas business with fewer than 250 employees an affirmative defense against exemplary damages if it maintained a qualifying cybersecurity program.

It does not touch actual damages, regulatory penalties or notification costs, and being an affirmative defense means the burden of proof sits with you. Dated policies, training logs and deployment records are what make it work. A program nobody documented is not a defense. Date everything.

One last thing worth saying plainly. Nothing above is legal advice. The edge cases in Safeguards Rule coverage are genuinely arguable and a securities attorney should settle them. What we can do is tell you which rules an examiner would apply to your operation, show you what evidence each one wants, and build the program that produces it. If the firm also needs the underlying platform sorted, that starts with managed IT services across Dallas-Fort Worth, and the industry view sits on our financial services page.

About Author

Learn More