Skip to content
Interdisciplinary CurriculumCurriculum

Your learning stays with you.

Purchase Terms

© 2026 Commensurate Ventures. All rights reserved.

Interdisciplinary CurriculumCurriculum
All Courses

Cybersecurity & Data Privacy for Financial Professionals

Essential cybersecurity training as state mandates expand. Covers NY DFS 23 NYCRR 500, SEC Reg S-P amendments, threat vectors targeting financial services, incident response planning, and building a culture of security.

10 Units
20 minutes per unit
Curriculum Map

What You Will Learn

Regulatory Framework

Navigate the overlapping cybersecurity requirements from SEC, state insurance departments, and federal agencies — and understand where they are heading.

Practical Threat Defense

Financial services is the #1 targeted industry. Learn the specific attack vectors used against advisors, agents, and their clients.

Incident Response

When a breach happens — not if — your response in the first 72 hours determines regulatory and legal consequences. Be prepared.

All Units

1
20 minutes
The Threat Landscape: Financial Services as a Target
An overview of the current cyber threat environment facing financial services professionals, including attack trends, breach statistics, and the unique vulnerabilities of advisory and insurance practices.
  • •Identify why financial services firms are disproportionately targeted by cybercriminals
  • •Describe the most prevalent cyber threat categories facing insurance agencies, RIAs, and advisory firms
  • •Quantify the financial and reputational costs of data breaches in financial services
Start learning
2
20 minutes
Regulatory Framework: SEC, State Insurance, and Federal Requirements
A detailed examination of the regulatory framework governing cybersecurity in financial services, including SEC rules, state insurance requirements, federal banking regulations, and the NAIC Model Law.
  • •Identify the primary federal and state regulations governing cybersecurity for financial services professionals
  • •Explain the key requirements of SEC Regulation S-P, the GLBA Safeguards Rule, and the NAIC Insurance Data Security Model Law
  • •Describe how NY DFS 23 NYCRR 500 established a precedent for state-level cybersecurity regulation
Start learning
3
20 minutes
Data Classification and Client Information Protection
A practical guide to identifying, classifying, and protecting the sensitive client information that financial services professionals handle daily, with specific encryption and access control requirements.
  • •Classify the types of sensitive data held by financial services firms according to regulatory categories
  • •Implement data protection strategies appropriate for each classification level
  • •Apply encryption and access control standards to client information at rest and in transit
Start learning
4
20 minutes
Common Attack Vectors: Phishing, Social Engineering, and Ransomware
A detailed examination of the attack methods most commonly used against financial services professionals, with practical recognition techniques and real-world examples from advisory and insurance practices.
  • •Recognize the primary attack methods used against financial services professionals
  • •Identify the warning signs of phishing, spear phishing, and business email compromise attacks
  • •Describe how ransomware attacks compromise financial services firms and the regulatory implications of ransom payments
Start learning
5
20 minutes
Incident Response Planning and Breach Notification
A practical guide to building and maintaining an incident response plan for financial services firms, including regulatory notification timelines, communication protocols, and post-incident remediation.
  • •Develop an incident response plan appropriate for a financial services practice
  • •Identify the specific notification timelines and requirements under SEC, state insurance, and state breach notification regulations
  • •Execute the correct sequence of actions during and after a cybersecurity incident
Start learning
6
20 minutes
Third-Party Vendor Risk Management
A practical framework for evaluating, contracting with, and monitoring third-party vendors who have access to client information, including due diligence procedures and contractual requirements.
  • •Assess the cybersecurity risks introduced by third-party vendors and service providers
  • •Implement a vendor due diligence process that satisfies regulatory expectations
  • •Establish contractual requirements and ongoing monitoring procedures for vendors with access to client data
Start learning
7
20 minutes
Remote Work Security and Mobile Device Management
Practical security controls for remote work, home offices, mobile devices, and BYOD environments, addressing the expanded attack surface facing financial professionals who work outside traditional office settings.
  • •Implement security controls for remote and hybrid work environments in financial services
  • •Establish mobile device management policies that protect client data on portable devices
  • •Evaluate the security implications of home networks, public Wi-Fi, and bring-your-own-device arrangements
Start learning
8
20 minutes
Building a Culture of Security: Training, Testing, and Compliance
Strategies for building a sustainable cybersecurity culture within financial services firms through effective training programs, regular testing, compliance documentation, and continuous improvement.
  • •Design a cybersecurity training program that meets regulatory requirements and changes employee behavior
  • •Implement phishing simulations and security testing appropriate for financial services firms
  • •Establish ongoing compliance monitoring and documentation practices that satisfy regulatory examinations
Start learning
9
20 minutes
Advanced Data Classification Frameworks for Financial Services
Builds on foundational data classification concepts to explore formal sensitivity frameworks, PII taxonomy construction, and client data tiering strategies that satisfy regulatory requirements while providing meaningful operational guidance.
  • •Apply formal data sensitivity frameworks (NIST, ISO 27001, PCI DSS) to classify client information held by financial services firms
  • •Construct a multi-tier PII taxonomy that maps data elements to regulatory obligations and breach notification triggers
  • •Design client data tiering protocols that align handling procedures with the actual risk profile of each data category
Start learning
10
20 minutes
Applied Data Protection: Encryption, Access Controls, and Cross-Border Transfer
Translates data classification tiers into concrete technical and procedural controls, covering modern encryption standards, key management, role-based access control implementation, and the increasingly important challenge of cross-border client data transfer.
  • •Select appropriate encryption standards and key management practices for protecting client financial data at rest and in transit
  • •Implement role-based and attribute-based access control models that satisfy SEC, state insurance, and GLBA examination requirements
  • •Navigate cross-border data transfer regulations including GDPR, data localization requirements, and international client data obligations
Start learning

Continuing education for financial services professionals. 4 credit hours (Cybersecurity). Accepted for insurance producers, IARs, and CFP certificants.