The Compliance Deadline Passed. Now What?
The SEC's amended Regulation S-P went fully live on June 3. Two weeks ago. Every registered investment adviser, broker-dealer, and transfer agent — regardless of size — now needs a written incident response program, must notify customers of breaches within 30 days, and has to document the whole thing.
No more grace period.
If you're a board member at a financial services firm and you haven't asked your CISO whether you're compliant, you're already behind.
France Deployed a "Secure" Messaging Tool. It Wasn't Enough.
The same week that deadline landed, France gave us a case study in what happens when you confuse deploying a secure tool with being secure.
On June 7, an attacker breached Tchap — the French government's official encrypted messaging platform, mandated for all public officials since September 2025. Tchap served over 825,000 civil servants across every major ministry. Defense, Interior, Finance, Foreign Affairs.
The attacker, going by "misere," didn't use some exotic zero-day. They social-engineered a single account in an education environment, hijacked it, and used that foothold to extract 73,467 user accounts, over 643,000 messages, and 13.5 GB of data — including documents marked with France's restricted-distribution classification.
Here's what should bother every executive reading this: private messages were encrypted. Public chat rooms were not. And nobody had apparently asked whether 876 government chat rooms full of operational discussions counted as "public" in any meaningful sense.
That's a governance failure. The technology did what it was configured to do. The humans never asked the right question.
Liability Has Moved
I talk about this in Cyber Risk Is Business Risk: the question isn't whether your organization will face a cyber incident. It's whether your board can demonstrate it was paying attention before the incident happened.
Courts are now applying the Caremark standard — a fiduciary duty framework — to cybersecurity oversight. Directors face personal liability if they fail to implement reporting systems for cyber risk. Not "the company." Directors, personally.
Seventy-eight percent of large-cap companies now house cybersecurity oversight in their audit committee. Fine. But housing it somewhere and actually exercising oversight are different things. The SEC expects detailed briefings on risk assessments, tabletop exercises, and third-party oversight. Meeting minutes serve as evidence. If those minutes say "CISO gave a presentation, no questions asked," that's not oversight. That's attendance.
AI Is Widening the Gap
While boards are still figuring out basic cyber governance, AI is making the problem bigger.
A Cloud Security Alliance survey released last month found that 92% of security professionals are concerned about AI agents operating across their enterprise. Sixty-three percent of organizations can't enforce purpose limitations on AI tools. Sixty percent can't terminate a misbehaving AI agent. Fifty-three percent can't recover training data after an incident.
Colorado's AI Act takes effect on June 30 — twelve days from now. It adds another layer of compliance requirements for any organization deploying AI that affects consumers. If you're operating in financial services, healthcare, or any regulated sector, the overlap between your cyber obligations and your AI governance obligations is about to land hard.
In my experience, most boards are treating AI governance as a separate conversation from cybersecurity. That's a mistake. The attack surface is the same. The data exposure is the same.
What I'd Be Asking This Week
If you're an executive or board member, three questions.
First — get a written answer from your CISO on Regulation S-P compliance. Not a verbal update in a meeting. A documented assessment. If your incident response program isn't written down and tested, you're exposed.
Second — ask about your messaging and collaboration platforms. Who has access? What's encrypted and what isn't? The Tchap breach happened because nobody drew a clear line between "encrypted by default" and "actually protected." Your Slack, your Teams, your internal wikis — same question applies.
Third — start connecting your AI governance conversations to your cyber risk conversations. Every AI tool your employees are using is a potential data exposure point, and your current cybersecurity framework probably doesn't cover it.
The SEC isn't waiting. The attackers aren't waiting.