Skip to main content

RIA Cybersecurity: Passing ODD and DDQ Scrutiny

Key Takeaways

Institutional allocators are asking tougher cybersecurity questions during due diligence, and RIAs that aren't prepared risk losing deals mid-raise. This article breaks down exactly what ODD professionals and DDQs are looking for today, from written security policies to penetration testing. Understanding these requirements has become a core capital-raising operational necessity for hedge funds, private equity managers, and wealth management firms.

Institutional allocators are asking harder cybersecurity questions than they were three years ago — and a growing number of RIAs are discovering that mid-raise is the wrong time to find out their answers don’t hold up.

Operational due diligence, or ODD, was once dominated by questions about trading infrastructure, counterparty risk, and fund administration. Cybersecurity lived somewhere at the bottom of the checklist, if it appeared at all. That has changed. Today, a weak showing on a cybersecurity DDQ (due diligence questionnaire — the written assessment allocators send before and after initial investment) can delay a close, trigger a follow-up site visit, or quietly end a conversation that seemed to be progressing well.

For RIAs managing institutional capital — hedge funds, private equity managers, and wealth management firms serving high-net-worth and family office clients — understanding what ODD cybersecurity scrutiny actually looks like is no longer optional. It’s a capital-raising operational requirement.


What Investors Are Actually Asking in DDQs Today

DDQ due diligence questionnaires have evolved from checkbox exercises into structured risk assessments. Sophisticated allocators — pension funds, endowments, funds of funds — have either hired dedicated ODD professionals or engaged third-party operational risk consultants who know exactly what to look for.

The questions arriving in your inbox today are more specific than ever:

  • Who is responsible for cybersecurity at your firm? (A named individual, not just “our IT provider”)
  • Do you maintain a written information security policy, and when was it last reviewed?
  • Have you experienced any security incidents or data breaches in the past 24 months? If so, describe them.
  • Do you conduct annual penetration testing (simulated cyberattacks by independent experts) and provide results to investors on request?
  • Are employees required to complete cybersecurity awareness training, and how is completion tracked?
  • What is your process if a key vendor — prime broker, fund administrator, transfer agent — suffers a breach that affects your data?

That last question reflects a broader shift. Allocators are no longer just evaluating the RIA — they’re evaluating the RIA’s entire third-party vendor ecosystem. A firm that has done everything right internally but can’t articulate its vendor risk management process will still raise flags.


The Cybersecurity Controls Investors Expect to See

ODD cybersecurity reviews are increasingly benchmarked against recognized frameworks. The most commonly referenced is the NIST Cybersecurity Framework, a set of voluntary standards developed by the National Institute of Standards and Technology that organizes security practices into five functions: identify, protect, detect, respond, and recover. Allocators familiar with this framework will expect RIAs to at least understand it, even if they haven’t formally adopted it.

Beyond frameworks, certain baseline technical controls have become table stakes for institutional-quality managers:

  • Multi-factor authentication (MFA) — requiring a second form of verification beyond a password — applied to email, cloud systems, and remote access. Allocators increasingly ask whether MFA is enforced, not merely available.
  • Endpoint detection and response (EDR) — software that monitors firm devices in real time for signs of malicious activity — deployed across all firm-managed computers.
  • Encrypted email and file transfer for anything involving investor data, portfolio information, or deal documents.
  • A documented, tested incident response plan that specifies who gets notified, when, and how — including investor notification timelines.
  • Cyber insurance coverage with policy limits and exclusions that have been reviewed recently.

That last point matters more than many managers realize. Allocators and their ODD teams are increasingly asking to review cyber insurance policy summaries, and some are specifically flagging firms that carry coverage limits they consider insufficient for the volume of sensitive data under management.


Where RIAs Most Often Fall Short During ODD

The gap between what a firm believes its security posture looks like and what ODD scrutiny reveals can be significant. A few patterns appear repeatedly.

The Policy-Practice Gap

Many RIAs have written security policies — but policies that haven’t been updated since they were initially drafted, or that describe procedures nobody actually follows. An ODD analyst who asks to see your information security policy and then asks a few follow-up questions about how it’s implemented will surface this gap quickly. Documentation that doesn’t match actual practice is often more damaging than having no documentation — it raises questions about governance and oversight.

Over-Reliance on a Single Vendor

Outsourcing IT to a managed service provider is common and entirely appropriate for firms without internal IT staff. The problem arises when the RIA cannot speak to what that provider actually does — what systems they monitor, how they respond to incidents, what their own security posture looks like. Allocators want to know that someone at the firm is accountable for understanding and overseeing the IT program, not just paying an invoice.

Incident History Handled Poorly

Every firm experiences some form of security incident over a multi-year period — a phishing email that tricked an employee, a compromised password, a vendor notification of a third-party breach. Allocators understand this. What they’re evaluating is how the firm handled it: Was there a response? Was leadership informed? Were controls improved afterward? An incident candidly described with a clear remediation narrative is far less damaging than an incident that surfaces through follow-up questions after an initial “no incidents” response.

Compliance-First, Security-Second Thinking

Satisfying SEC examination requirements and passing ODD cybersecurity scrutiny overlap significantly but are not identical. A firm that has organized its security program entirely around regulatory compliance may find it has gaps that sophisticated allocators — who are not bound by the same examination scope as regulators — will identify. Institutional investors are asking about security outcomes, not just policy checklists.


Building a Due-Diligence-Ready Security Program

The goal isn’t to build a security program in response to DDQ questions — it’s to build one that genuinely manages risk, and then be able to articulate it clearly when allocators ask. Those are different orientations, and experienced ODD professionals can tell them apart.

A few practical starting points:

  • Require your IT team or MSP to produce a written annual security review — a plain-language summary of what was tested, what was found, and what was changed. This becomes the foundation of your ODD narrative.
  • Ask your provider whether penetration testing is conducted by a genuinely independent third party, and whether you receive a formal report. Many allocators ask for this report directly.
  • Add cybersecurity to your vendor risk review process — at minimum, require your key service providers to complete a security questionnaire annually and document how you evaluated their responses.
  • Review your incident response plan against a realistic scenario. If a senior partner’s email account were compromised today, does everyone know their role? Could you tell an allocator how long it would take to detect, contain, and notify?
  • Ensure your cyber insurance policy is reviewed by someone who understands what it actually covers — exclusions around social engineering, ransomware sublimits, and retroactive coverage dates are frequently misunderstood until a claim is filed.

RIA investor due diligence is becoming a recurring process, not a one-time closing hurdle. Many institutional allocators conduct annual or biennial ODD reviews of existing managers. That means the cybersecurity conversation doesn’t end at first close — it continues as long as the capital relationship does.


Final Thought

Institutional capital comes with institutional expectations. Allocators who survived 2020, navigated the ransomware surge that followed, and now operate under their own regulatory obligations around manager oversight are not going to accept vague assurances about cybersecurity. They’re asking specific questions, they’re evaluating the answers against a growing body of experience, and they’re making allocation decisions accordingly.

The RIAs that handle ODD cybersecurity reviews most effectively aren’t necessarily those with the largest IT budgets. They’re the ones where leadership understands what their security program actually does — and can explain it clearly to someone who is paid to be skeptical. That combination of substance and clarity is what due-diligence-ready really means.

Frequently Asked Questions

What cybersecurity controls do institutional allocators expect RIAs to have during ODD reviews?

Institutional allocators conducting ODD cybersecurity reviews now treat several controls as baseline requirements for institutional-quality managers: enforced multi-factor authentication (MFA) on email, cloud systems, and remote access; endpoint detection and response (EDR) software across all firm-managed devices; encrypted email and file transfer for investor and portfolio data; a documented and tested incident response plan with defined notification timelines; and active cyber insurance with reviewed policy limits and exclusions. Allocators are increasingly asking to review cyber insurance policy summaries directly, and some flag firms carrying coverage limits they consider insufficient for the volume of sensitive data under management. These controls are often benchmarked against the NIST Cybersecurity Framework, which organizes security practices into five functions: identify, protect, detect, respond, and recover.

How do ODD analysts detect the gap between an RIA’s written security policies and its actual practices?

ODD analysts surface policy-practice gaps by requesting the firm’s written information security policy and then asking targeted follow-up questions about how specific procedures are implemented day-to-day. Documentation that describes controls nobody actually follows is frequently more damaging to an ODD review than having no documentation at all, because it raises direct questions about governance and oversight. Analysts with operational risk backgrounds are trained to probe whether policies have been updated since initial drafting and whether the staff responsible for executing them can speak to them accurately.

Why does a past security incident hurt an RIA less than an undisclosed one during due diligence?

Allocators understand that virtually every firm experiences some form of security incident over a multi-year period — phishing attempts, compromised credentials, or third-party breach notifications are common. What ODD professionals are evaluating is the firm’s response: whether leadership was informed, whether a structured remediation followed, and whether controls were improved afterward. An incident candidly described with a clear remediation narrative is substantially less damaging than one that surfaces through follow-up questions after an initial ‘no incidents’ response, which raises concerns about transparency and internal oversight.

What specific cybersecurity questions are allocators sending in DDQs to hedge funds and RIAs today?

Current DDQs from pension funds, endowments, and funds of funds ask for a named individual responsible for cybersecurity (not just a vendor reference), confirmation that a written information security policy exists and has been recently reviewed, a 24-month incident and breach history, whether annual independent penetration testing is conducted and results are available to investors, how employee cybersecurity training completion is tracked, and how the firm responds if a key vendor — prime broker, fund administrator, or transfer agent — suffers a breach affecting the firm’s data. The vendor ecosystem question reflects a broader shift: allocators are evaluating the RIA’s third-party risk management process, not just the RIA’s internal controls.

Can an RIA pass ODD cybersecurity scrutiny if it outsources all IT to a managed service provider?

Outsourcing IT to a managed service provider (MSP) is common and acceptable to allocators, but only if someone at the RIA can speak substantively to what that provider actually does — which systems are monitored, how incidents are escalated, and what the MSP’s own security posture looks like. The failure mode allocators flag is not outsourcing itself, but an RIA that cannot demonstrate internal accountability for understanding and overseeing the outsourced program. Paying an MSP invoice without being able to describe the program’s substance raises red flags about governance regardless of what the MSP is actually doing.

How does SEC cybersecurity compliance differ from what institutional allocators evaluate in ODD?

SEC examination requirements and ODD cybersecurity scrutiny overlap significantly but are not identical in scope or orientation. A security program built entirely around satisfying SEC examination checklists may still have gaps that sophisticated institutional allocators — who are not bound by the same regulatory examination scope — will identify. Allocators evaluate security outcomes and the firm’s ability to articulate how its program actually manages risk, not just whether required policies exist. RIAs that treat cybersecurity as a compliance checkbox exercise rather than an operational risk discipline tend to underperform in ODD reviews conducted by dedicated operational risk professionals.

How often do institutional allocators review an existing manager’s cybersecurity posture after the initial investment close?

Many institutional allocators conduct annual or biennial ODD reviews of managers already in their portfolio, meaning cybersecurity due diligence is a recurring process rather than a one-time closing requirement. RIAs should expect the cybersecurity conversation to continue for the duration of the capital relationship, with allocators tracking whether controls have been updated, whether incidents have occurred, and whether the firm’s vendor risk management has evolved. A security program that was sufficient at first close may not satisfy the same allocator two years later if the firm’s data footprint or AUM has grown materially.

What should an RIA ask its IT provider or MSP to produce to prepare for ODD cybersecurity questions?

RIAs should require their IT team or MSP to produce a written annual security review — a plain-language document summarizing what was tested during the year, what vulnerabilities or gaps were found, and what changes were implemented in response. This document becomes the foundation of the firm’s ODD narrative and demonstrates that someone at the firm is actively overseeing the security program rather than passively delegating it. RIAs should also confirm whether penetration testing is conducted by a genuinely independent third party and whether a formal report is produced, since allocators frequently ask to review that report directly.

What cyber insurance policy details do allocators focus on when reviewing an RIA’s coverage during due diligence?

Allocators and their ODD teams review cyber insurance policy summaries with attention to coverage limits relative to the volume of sensitive data under management, and specifically to exclusions and sublimits that are frequently misunderstood. Common problem areas include exclusions around social engineering losses, sublimits on ransomware payments, and retroactive coverage dates that leave prior incidents uninsured. RIAs should have their cyber insurance policy reviewed by someone who understands what the policy actually covers before an ODD review surfaces gaps — discovering a material exclusion during due diligence is a harder conversation than having addressed it proactively.