$123K
Average loss per BEC incident in 2025. 86% moved by wire or ACH
28–33 days
Median time before anyone notices a compromised mailbox
1 in 10
Breached accounts get a hidden inbox rule planted within seconds, and it survives a password reset
6/3/26
Reg S-P deadline for RIAs under $1.5B AUM. It already passed.
The Real Scenario
Here’s why you’d have to write the letter
A threat actor gets into an advisor’s mailbox: a phished password, a reused credential, it doesn’t matter how. They do nothing dramatic. No wire request, no urgent ask. They just sit there, reading every email between that advisor and the firm’s largest clients: balances, account numbers, family details, upcoming trades.
In roughly 1 in 10 of these cases, the attacker plants a hidden inbox rule within seconds of getting in, quietly archiving or forwarding messages so the advisor never sees what’s being watched, and that rule survives even if the password gets reset.
This is never a one-client incident. That mailbox holds correspondence with every client that advisor ever worked with, plus anything other advisors in the office emailed him about a referral, a file, a shared account. The moment that inbox is compromised, it’s a firm-wide data breach.
Nothing has to be stolen for this to be reportable. Under Reg S-P, unauthorized access to sensitive customer information is enough, on its own, to trigger a 30-day notification requirement sent to every client whose information passed through that mailbox, not just one.
Most of those clients grumble and stay. Your largest client doesn’t have to. Wealth management firms typically concentrate 80% of AUM in the top 20% of clients. The fewest relationships, the most to lose, the most alternatives available. One breach, one letter mailed to dozens of clients, but the revenue that actually walks concentrates in the single relationship you can least afford to lose.
The Number Nobody’s Running
Your compliance officer’s job ends at the letter. This is what happens after.
Run your own numbers. Take your largest client’s AUM, multiply by your fee, multiply by however many years they’d have stayed.
| Largest client relationship (AUM) | $25,000,000 |
| Average RIA advisory fee | 1.00% |
| Annual revenue from this client | $250,000 |
| Years the relationship would likely have continued | 15 years |
| Lifetime revenue at risk from one letter | $3.75M |
Cyber insurance pays for forensics, legal fees, and notification costs. It does not replace a dollar of the $3.75M that walks out the door when a client decides your firm can’t be trusted with their information anymore.
Where BEC Actually Gets In
Five fronts. One tenant. Zero margin for a “no.”
Ask these five questions about your firm right now. If any answer is no, that’s the door a threat actor already knows about.
1
Identity
Entra ID P1
“Would we know if that mailbox had an active sign-in for a month from a device or location we’ve never seen?”
NO
2
Device Management
Intune
“Could we tell that access wasn’t coming from any device we’ve ever enrolled or approved?”
NO
3
Device sECURITY
Defender for Business
“Would EDR see any of this? There’s no malware, just a valid login to a cloud mailbox.”
NO
4
Email & App Security
Defender for Office 365
“Would we catch a hidden inbox rule planted within seconds that survives a password reset?”
NO
5
Data Security
Purview
“Could we produce an audit trail of exactly what that mailbox opened, before we have to write the letter?”
NO
What We Actually Do
We manage the five fronts, and we prove it every month.
- Configure and manage Entra ID, Intune, Defender for Business, Defender for Office 365, and Purview across your tenant; not just at onboarding, continuously.
- Monthly compliance report delivered directly to the majority partner: every user and device out of compliance with the baseline you set.
- Dated, exportable evidence your forensics team or insurer can pull directly, not reconstructed after the fact.
- Reg S-P readiness built around what the SEC actually checks: written policies, incident response, service provider oversight.
- BEC-specific hardening: Conditional Access, mailbox rule auditing, and session monitoring tuned for how advisors actually get compromised.
- One point of accountability for the technology risk your firm currently has no audit function for.
The Consequence Of Getting This Wrong
Every other option is the same exposure, sold with more confidence.
Anyone can hand you a slide with five Microsoft logos on it. Here’s what actually separates ATG from an IT vendor reading off the same box.
1
We run this ourselves.
We’ll show you our own M365 tenant and exactly how we use all five centers (Entra, Intune, Defender for Business, Defender for Office 365, Purview) to reduce our own exposure. It isn’t theory for ATG. It’s every. day. real. constant. unrelenting. unforgiving.
2
We’re SOC 2 attested, not SOC 2 curious.
ATG operates under SOC 2 controls and holds our own attestation. Most IT firms selling you “compliance” have never been through an audit themselves. They don’t know what it actually requires or how it holds up in real time. We do, because we live under it.
3
We have a track record, and references.
We have a proven history with current clients and will provide references as needed. You’re not the first RIA to ask us to prove it.
The alternative to ATG was never “do nothing.” It’s hiring someone to protect you from a threat they’ve never had to survive themselves.
