Bart McDonough Quoted in InvestmentNews: Cybersecurity Lessons for Investment Advisers

Explore Bart McDonough’s InvestmentNews commentary and practical cybersecurity lessons for investment advisers, from vendor risk and device updates to protecting client data.

Updated October 7, 2026

An investment adviser’s cybersecurity program is tested when a client’s email account is compromised, a technology provider reports a breach, or an employee loses access to critical records. At that moment, written policies matter—but so do working safeguards, clear responsibilities, and rehearsed decisions.

Those practical concerns connect Bart McDonough’s historical commentary in InvestmentNews with the challenges advisory firms face today. The publication quoted McDonough on cybersecurity fundamentals, vendor risk, and the difficulty of turning regulatory expectations into effective protection. It identified him at the time as Agio’s founder and CEO; he is now its former CEO. This coverage concerned protecting advisory businesses and client information, not stock-market predictions.

Editorial note: This is a newly written article summarizing verified coverage and providing current guidance. Multiple InvestmentNews stories contain McDonough’s comments, so the unavailable page cannot confidently be associated with a single article. This content does not reconstruct or reproduce that page.

Where InvestmentNews Quoted Bart McDonough

The following publisher articles provide verified starting points for readers seeking McDonough’s cybersecurity commentary:

The consistent theme is implementation: advisers need security measures that operate in daily business, not merely policies that describe what should happen.

The sections below are current editorial guidance based on federal resources, not new quotations or commentary attributed to McDonough.

Build a Security Program Around Responsibilities and Evidence

Start with ownership and an inventory

Before purchasing another tool, establish what the firm must protect. Inventory devices, applications, sensitive information, administrative accounts, and important service providers. Assign an accountable business owner who can approve priorities, resolve competing demands, and track progress.

The NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide organizes this work around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is adaptable guidance, not a certification or guarantee of regulatory compliance.

For example, an adviser might discover that its client relationship management platform, document storage, and email service contain overlapping client information. Naming an owner for each system makes it easier to review access, identify unnecessary copies, and determine who acts when something goes wrong.

Keep an action register with four fields: the issue, its owner, its deadline, and the evidence needed to close it. “Enable MFA” is a task; a report showing enrollment and unresolved exceptions is evidence.

Protect identities and keep systems supported

CISA recommends multifactor authentication, beginning with administrative accounts and people handling sensitive information. Extend protection to email, remote access, and file storage—not just financial platforms. Prefer phishing-resistant methods, such as appropriately implemented security keys, where supported.

The tradeoff: Stronger authentication requires enrollment, training, and reliable recovery procedures. Use the strongest available MFA while improving systems that cannot yet support phishing-resistant methods. Delaying all protection until every application is ready creates avoidable exposure.

Updates require similar discipline. Follow CISA’s Cyber Essentials guidance by maintaining supported technology and deploying updates appropriately. Ask for a device-level report rather than assuming a managed-service agreement covers every laptop.

Some patches need testing to avoid disrupting essential applications. That operational concern should produce a documented deployment plan and temporary safeguards—not indefinite postponement.

Ask Better Questions About Vendors and Cloud Services

Match scrutiny to access and potential harm

McDonough’s July 2019 InvestmentNews commentary emphasized that vendors differ in both security practices and access to information. A provider administering email and backups presents a different exposure from a supplier with no access to client records.

For important providers, ask:

  • What client information can you access, store, or process?
  • Which personnel have administrative access, and how is that access restricted?
  • Who handles updates, monitoring, backups, and incident response?
  • What triggers an incident notification, and how quickly will we receive it?
  • What evidence supports your security claims?
  • How can we retrieve our information and terminate access when the relationship ends?

Document responsibilities and escalation contacts. When reviewing an assessment or assurance report, check its scope, date, exclusions, and relevance to the service being purchased. A security document is useful evidence, but it is not a substitute for understanding the relationship.

NIST’s guidance on building a cybersecurity team recommends considering providers’ experience and ability to support specific requirements, not simply price. Outsourcing can supply expertise a small firm cannot maintain internally, but it does not transfer the firm’s responsibility for protecting its information.

Treat cloud migration as a change in responsibilities

The October 2019 InvestmentNews article reported McDonough’s recommendation that advisers consider cloud technologies. Current CISA ransomware guidance also encourages reputable managed cloud services where maintaining internet-facing systems is difficult.

Cloud adoption can reduce infrastructure maintenance, but identity management, access permissions, logging, and recovery still require attention. For example, moving documents into a cloud platform does not make an employee’s broadly shared folder appropriate.

Before migrating, request a responsibility matrix showing what the cloud provider handles, what the IT provider handles, and what remains with the advisory firm. Compare costs against that division of work. A lower subscription price may exclude monitoring, recovery assistance, or configuration support the firm still needs.

Test Response and Recovery Before an Incident

A completed backup job does not demonstrate that an adviser can restore usable records. CISA’s ransomware guidance recommends protecting backups and testing their availability and integrity. Its small-business resources also address logging, encryption, phishing awareness, and other foundational safeguards.

Run a practical exercise using a hypothetical compromised email account. Ask who can disable access, preserve relevant logs, contact the provider and counsel, assess affected information, and authorize communications. Keep emergency contact information accessible if normal email becomes unavailable.

Then test restoration of a critical system or representative data set. Record what worked, what failed, and who owns corrective actions. Recovery planning should account for both security and business continuity: restoring quickly is not enough if the restored environment remains compromised.

A useful security review asks not only whether a safeguard exists, but whether the firm can show that it works.

Current Regulatory Context: Regulation S-P

As of October 7, 2026, both compliance dates for the SEC’s 2024 Regulation S-P amendments have passed: December 3, 2025, for larger entities and June 3, 2026, for smaller entities. For investment advisers, the amendments cover SEC-registered advisers; state-only registration does not automatically place a firm within that category. Other applicable obligations still require review.

The SEC’s Small Entity Compliance Guide explains requirements for written incident-response policies and procedures, service-provider oversight, and compliance records. Provider oversight must address notification as soon as possible, but no later than 72 hours after the provider becomes aware of a qualifying breach involving unauthorized access to its customer information system.

According to the SEC’s announcement of the amendments, affected-individual notice generally must occur as soon as practicable, and no later than 30 days after awareness of the relevant incident, subject to the rule’s conditions and exceptions.

These are distinct requirements, not interchangeable deadlines. Do not treat 30 days as permission to delay investigation. Have qualified counsel confirm applicability, notification decisions, and required records before an incident forces those questions.

Investment Adviser Cybersecurity Checklist

Use this checklist as a review aid, not a compliance certification:

  • Ownership: Assign an accountable business leader and maintain a prioritized action register.
  • Inventory: Identify sensitive information, systems, accounts, and providers.
  • Authentication: Require MFA for email, remote access, and privileged accounts; prefer phishing-resistant methods.
  • Maintenance: Verify patch coverage and replace unsupported technology.
  • Access: Remove unnecessary permissions and review provider access.
  • Vendor oversight: Document responsibilities, evidence, notification expectations, and exit procedures.
  • Detection: Establish who reviews alerts and how urgent issues are escalated.
  • Recovery: Protect backups and demonstrate restoration.
  • Response: Exercise incident procedures with actual decision-makers.
  • Obligations: Confirm applicable rules and retain required documentation.

Turn Cybersecurity Commentary Into Action

The verified InvestmentNews coverage connects Bart McDonough with practical cybersecurity concerns facing investment advisers. Its enduring value is the emphasis on fundamentals, informed vendor decisions, and implementation.

Start with a focused review: choose a critical system, verify its authentication and update coverage, confirm provider responsibilities, and test recovery. Assign owners to every gap. The objective is not another policy on file—it is a firm that can protect client information, respond decisively, and demonstrate that its safeguards work.

Browse all insights · Contact Bart McDonough