Install
$ agentstack add skill-joellewis-finance-skills-privacy-data-security ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Privacy and Data Security
Regulatory status current as of June 2026 — verify effective dates, dollar thresholds, and pending rulemakings against current SEC/FINRA/FinCEN sources before advising.
Core Concepts
Regulation S-P (Privacy of Consumer Financial Information)
Regulation S-P (17 CFR Part 248, Subparts A and B) implements Title V of the Gramm-Leach-Bliley Act (GLBA) for entities registered with the SEC. It applies to SEC-registered investment advisers, broker-dealers, investment companies, and transfer agents. The regulation has three core components:
Privacy Notice Requirements. Firms must provide an initial privacy notice to each customer at the time of establishing the customer relationship (17 CFR 248.4). The notice must describe: (a) categories of nonpublic personal information (NPI) collected, (b) categories of NPI disclosed to third parties, (c) categories of affiliates and nonaffiliated third parties to whom NPI is disclosed, (d) the customer's right to opt out of certain disclosures, (e) the firm's policies and practices for protecting confidentiality and security of NPI, and (f) any disclosures required under the Fair Credit Reporting Act. Annual privacy notices must be delivered once during each 12-month period for the duration of the customer relationship (17 CFR 248.5). The FAST Act of 2015 (Pub. L. 114-94, Section 75001) created an exception to the annual notice requirement: firms that (i) share NPI only under the exceptions in 17 CFR 248.14 and 248.15, and (ii) have not changed their privacy policies and practices since the most recent notice, may satisfy the annual requirement by posting the privacy notice continuously on their website in a clear and conspicuous manner rather than mailing it to each customer.
Opt-Out Requirements. Before sharing NPI with nonaffiliated third parties, firms must provide customers with a reasonable opportunity to opt out (17 CFR 248.7 and 248.10). The opt-out notice must be clear, conspicuous, and delivered along with or as part of the privacy notice. Exceptions to the opt-out requirement include: (a) disclosures necessary to effect, administer, or enforce a transaction requested by the customer, (b) disclosures to service providers and joint marketing partners under written contractual agreements that restrict the third party's use of NPI, (c) disclosures with customer consent, (d) disclosures to protect against fraud, and (e) disclosures required by law (17 CFR 248.14 and 248.15). Joint marketing agreements must include written contracts specifying that the third party will maintain the confidentiality of NPI and will use it only for the purposes for which it was disclosed.
Safeguards Rule. Section 248.30 requires every covered institution to adopt written policies and procedures that address administrative, technical, and physical safeguards for the protection of customer records and information. Administrative safeguards include designating a responsible employee or officer, conducting risk assessments, implementing employee training, and establishing oversight of service providers. Technical safeguards include access controls, encryption, intrusion detection systems, and monitoring of information systems. Physical safeguards include secure storage of records, controlled access to facilities, and proper disposal of documents. The policies must be reasonably designed to: (a) ensure the security and confidentiality of customer records and information, (b) protect against anticipated threats or hazards to the security or integrity of such records, and (c) protect against unauthorized access to or use of such records that could result in substantial harm or inconvenience to the customer.
Disposal Rule. Section 248.30(b) requires proper destruction of consumer report information derived from consumer reports. Reasonable measures for disposal include shredding physical documents, erasing or destroying electronic media, and entering into contracts with third-party disposal services that require proper destruction.
Regulation S-ID (Red Flags Rule)
Regulation S-ID (17 CFR 248.201-202) implements Sections 114 and 315 of the Fair and Accurate Credit Transactions Act (FACTA) for SEC-regulated entities. It requires financial institutions and creditors that hold "covered accounts" to develop and implement a written Identity Theft Prevention Program (ITPP) designed to detect, prevent, and mitigate identity theft.
Covered Accounts. Two categories of accounts are covered: (a) accounts primarily for personal, family, or household purposes that involve or are designed to permit multiple payments or transactions (e.g., brokerage accounts, margin accounts, advisory accounts with ongoing services), and (b) any other account for which there is a reasonably foreseeable risk to customers or to the safety and soundness of the financial institution from identity theft, including financial, operational, compliance, reputation, or litigation risks.
Identity Theft Prevention Program Requirements. The ITPP must include reasonable policies and procedures to: (1) identify relevant red flags applicable to the firm's covered accounts, drawing from five categories of red flags — alerts, notifications, or warnings from consumer reporting agencies; suspicious documents; suspicious personal identifying information; unusual use of or suspicious activity related to a covered account; and notices from customers, victims of identity theft, law enforcement, or other persons regarding possible identity theft — (2) detect red flags that have been incorporated into the program, (3) respond appropriately to any red flags that are detected to prevent and mitigate identity theft, and (4) ensure the program is updated periodically to reflect changes in risks to customers and to the safety and soundness of the firm.
Administration. The ITPP must be approved by the board of directors, a committee of the board, or senior management (17 CFR 248.201(d)). Ongoing administration includes: assigning specific responsibility for the program's implementation, training staff to carry out the program, exercising appropriate and effective oversight of service provider arrangements (ensuring that service providers' activities in connection with covered accounts are conducted in accordance with reasonable policies and procedures to detect, prevent, and mitigate identity theft), and ensuring the program is updated as necessary.
SEC Cybersecurity Rules and Guidance
The SEC has addressed cybersecurity through a combination of rulemaking, interpretive guidance, and enforcement.
Public Company Disclosure Rules (2023). In July 2023, the SEC adopted rules requiring public companies to disclose material cybersecurity incidents on Form 8-K (Item 1.05) within four business days of determining that an incident is material. Companies must also disclose their cybersecurity risk management, strategy, and governance on Form 10-K (Item 1C of Regulation S-K). Required disclosures include: processes for assessing, identifying, and managing cybersecurity risks; whether cybersecurity risks have materially affected or are reasonably likely to materially affect the company's business strategy, results of operations, or financial condition; the board of directors' oversight of cybersecurity risk; and management's role in assessing and managing cybersecurity risks.
2024 Reg S-P Amendments — Incident Response and Breach Notification. In May 2024 the SEC adopted amendments to Regulation S-P (Release No. 34-100155) that impose the first general federal breach-response requirements on SEC-registered broker-dealers, investment advisers, investment companies, and transfer agents. Covered institutions must: (a) develop, implement, and maintain a written incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information; (b) notify affected individuals whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization — as soon as practicable, and no later than 30 days after becoming aware of the incident; and (c) maintain written policies for oversight of service providers, including provisions ensuring the institution receives notice of breaches at service providers. Compliance dates: December 3, 2025 for larger entities and June 3, 2026 for smaller entities — as of June 2026 these requirements are in effect for all covered institutions (verify any transition guidance for newly registered firms).
Standalone cybersecurity rulemaking status. The SEC's February/March 2022 proposed cybersecurity risk management rules for advisers and funds (Release No. IA-5956) were formally withdrawn in June 2025 along with thirteen other pending proposals. Beyond the 2024 Reg S-P amendments, the SEC enforces cybersecurity obligations through existing authority: the Reg S-P Safeguards Rule (17 CFR 248.30), the books-and-records rules (SEC Rule 17a-4, IA Act Rule 204-2), and the general antifraud provisions. Verify the current rulemaking agenda before advising on prospective requirements.
SEC EXAMS (formerly OCIE) Examination Priorities. Cybersecurity has been a top SEC examination priority since 2014. Key areas examined include: governance and risk assessment (board or senior management oversight, CISO or equivalent role, documented risk assessments), access rights and controls (least privilege, multi-factor authentication, access logging, prompt deprovisioning of terminated employees), data loss prevention (monitoring for unauthorized data transfers, encryption at rest and in transit, endpoint protection), vendor management (due diligence on third-party service providers, contractual security requirements, ongoing monitoring), incident response (written plans, testing and tabletop exercises, escalation procedures), and training (frequency, content, phishing simulation results).
SEC Enforcement. The SEC has brought enforcement actions against registered firms for cybersecurity failures under Reg S-P's Safeguards Rule and under the Identity Theft Red Flags Rule. Notable enforcement themes include: failure to implement written policies and procedures for protecting customer information, insufficient access controls (e.g., allowing shared credentials, failing to implement multi-factor authentication), failure to detect and respond to known vulnerabilities, and misleading disclosures about cybersecurity practices following a breach.
Incident Response Requirements
Regulatory expectations require financial firms to maintain comprehensive incident response capabilities.
Written Incident Response Plan. The SEC expects registered firms to maintain a written incident response plan that includes: designation of an incident response team with clear roles and escalation authority; procedures for detecting and classifying incidents by severity; containment procedures to limit the scope and impact of an incident; evidence preservation protocols (forensic imaging, log retention, chain of custody documentation); eradication and recovery procedures; internal escalation and reporting timelines (to senior management, the board, legal counsel, and the compliance department); external notification procedures (to customers, regulators, and law enforcement as required); and a post-incident review process to identify root causes and remediation actions.
Customer Notification. Under the 2024 Reg S-P amendments, covered institutions must notify affected individuals within 30 days of becoming aware that sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization (compliance required since December 3, 2025 for larger entities and June 3, 2026 for smaller entities). Notification is not required if the institution determines, after a reasonable investigation, that the sensitive customer information has not been and is not reasonably likely to be used in a manner that would result in substantial harm or inconvenience. State breach notification laws apply on top of the federal requirement in all 50 states, the District of Columbia, and U.S. territories, with varying triggers and content requirements. Most states require notification within 30 to 60 days of discovery; some states, such as Florida (30 days under Fla. Stat. 501.171) and Colorado (30 days under C.R.S. 6-1-716), impose shorter deadlines. Firms operating in multiple states must comply with the notification requirements of each state where affected individuals reside, which often means designing to the most restrictive standard alongside the federal 30-day clock.
Regulatory Notification. Beyond customer notification, certain circumstances trigger reporting to regulators: (a) if the breach involves potential financial crime, SAR filing obligations under BSA/AML rules may apply; (b) FINRA expects member firms to notify FINRA of significant cybersecurity incidents; and (c) New York DFS-regulated entities must notify DFS within 72 hours of a cybersecurity event that has a reasonable likelihood of materially harming normal operations (23 NYCRR 500.17).
Law Enforcement Coordination. Firms should establish relationships with relevant law enforcement agencies (FBI, Secret Service, state attorneys general) before an incident occurs. In the event of a breach, law enforcement may request a delay in public notification to avoid compromising an investigation; firms should work with counsel to balance this request against state breach notification deadlines.
SAR Filing. If a cybersecurity incident involves or is connected to potential financial crime — for example, unauthorized access leading to theft of funds, account takeovers, or identity theft used to facilitate fraudulent transactions — the firm must evaluate whether a Suspicious Activity Report should be filed under its BSA/AML obligations. The SAR should describe the cybersecurity incident, the nature of the suspected criminal activity, and the impact on customer accounts.
State Privacy Laws
Financial firms face a layered regulatory environment where federal securities privacy rules intersect with state privacy and cybersecurity legislation.
California (CCPA/CPRA). The California Consumer Privacy Act (Cal. Civ. Code 1798.100 et seq.), as amended by the California Privacy Rights Act (effective January 1, 2023), grants California residents broad rights over their personal information, including rights to know, delete, correct, and opt out of the sale or sharing of personal information. Financial institutions are partially exempt from the CCPA/CPRA to the extent they are subject to the GLBA and collect, process, sell, or disclose personal information pursuant to GLBA. However, the exemption applies only to information collected, processed, sold, or disclosed subject to GLBA — information outside the GLBA's scope (e.g., employee data, website tracking data, marketing data) may still be subject to CCPA/CPRA. Firms must carefully analyze which data falls within the GLBA exemption and which does not.
New York (DFS 23 NYCRR 500). The New York Department of Financial Services cybersecurity regulation applies to all entities operating under or required to operate under a DFS license, registration, or charter, or that are otherwise DFS-regulated. This includes many broker-dealers and investment advisers operating in New York. Key requirements include: designation of a Chief Information Security Officer (CISO); establishment and maintenance of a cybersecurity program based on a risk assessment; written cybersecurity policies covering 14 specified areas (information security, data governance and classification, asset inventory, access controls, business continuity, systems and network security, monitoring, incident response, vendor management, encryption, and others); annual penetration testin
…
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: JoelLewis
- Source: JoelLewis/finance_skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.