Pro Blog | PK Tech

LPL's Cybersecurity Mandate: What Advisors Need to Know Before the September Deadline

Written by Jordan Hetrick | August 12, 2026

Disclaimer: This post is not legal, tax, or compliance advice. Regulatory questions should go to your attorney and compliance consultant. Some of the operational detail below comes from public discussions among IT providers on Reddit and cannot be fully verified. Confirm current requirements directly with LPL before making decisions about your practice.

The LPL cybersecurity mandate requires affiliated advisors to run LPL-selected software on the devices they use for firm business. Advisors have been told enforcement tightens at the end of September 2026. If you already work with an IT provider, the requirements overlap with, and in some cases replace, protections you already pay for.

Below is what LPL is requiring, why they moved, and what still sits with the advisor either way.

What the LPL Cybersecurity Mandate Requires

Three pieces, installed together:

  • The LPL Business Browser, which becomes the required path into ClientWorks. LPL confirmed the browser publicly in its July 2026 Latitude announcement and states it has blocked thousands of attacks since deployment began.
  • A NinjaOne agent, installed first, because the browser is delivered through it. NinjaOne is a remote monitoring and management (RMM) platform. An RMM agent can inventory software, change settings, control patching, and run scripts on the machine.
  • An LPL-managed endpoint detection and response (EDR) agent.

Installation requires local administrator rights on the device.

The requirements have shifted since spring. LPL's original FAQ language, circulated to advisors in May, said existing RMM and security tools had to be removed. By August, IT providers on the r/msp forum were reporting a softer position: a non-NinjaOne RMM may stay, but EDR and SIEM tooling must go, and LPL's stack wins any conflict. Advisors have also been told different things about which EDR product is being deployed. If your understanding of the requirement dates from spring, confirm it in writing before you plan around it.

Why LPL is Doing This

Two things happened, and they matter for how you respond.

First, the breach. In April 2026, Wealth Management reported that LPL notified regulators of an incident in which malware delivered through phishing reached a limited number of individual advisor devices. Attackers used that access to reach those advisors' accounts on LPL's web portal, which produced unauthorized securities transactions and financial transfers affecting 1,581 clients. A separate filing months earlier described compromised advisor accounts used in a securities manipulation scheme. The entry point in both cases was the advisor's own device, not LPL's core infrastructure.

Second, the regulation. Amendments to SEC Regulation S-P took effect for smaller entities on June 3, 2026. Covered firms must maintain a written incident response program, notify affected customers, oversee service providers, and keep records proving all of it. FINRA issued its own advisory on the compliance dates, and the SEC's Division of Examinations named Reg S-P a 2026 exam priority.

A broker-dealer supervising 32,000 advisors, most of whom handle their own IT, has a defensible reason to standardize endpoints. Whether the specific approach is the right one is a separate question from whether the motivation is real.

What the LPL Stack Does Not Cover

LPL's requirements are endpoint controls. Your regulatory obligations under Reg S-P are broader than your endpoints.

Nothing in the mandate addresses:

  • Your firewall, network segmentation, or guest Wi-Fi
  • Backups, restore testing, and recoverability of your business data
  • Microsoft 365 tenant configuration, conditional access, and mailbox auditing
  • Email security and phishing simulation for your staff
  • Employee onboarding, offboarding, and access reviews
  • Your written information security program and written supervisory procedures
  • Your own incident response plan, tested and documented, as Reg S-P now requires
  • Vendor due diligence on the providers you use outside LPL
  • Physical security, mobile devices, and personal machines used for business

Installing the required agents does not make a practice Reg S-P compliant. It closes one gap that regulators and LPL both care about. Everything else still belongs to the advisor.

The Questions LPL Has Not Answered Clearly

Independent IT providers supporting LPL advisors have been asking the same questions since May, in two long public threads on the r/msp forum: the original May thread and the August follow-up. These are anonymous accounts and they contradict each other on details. Three months in, there is still no consistent answer to the following.

Who has remote access to the machine

An RMM agent can start a remote session, change settings, or run scripts. Which LPL personnel, third-party administrators, or vendor staff hold that access, and what approval is required before it happens? Ask for the answer in writing.

Who owns incident response

One IT provider reported that LPL told him the firm acts as incident response lead for any event on a covered device. Another attended LPL's May advisor webinar, asked directly who carries security liability when LPL's EDR sits alongside another provider's tools, and reported getting no answer. A Reg S-P incident response program has to name someone. Get LPL's position documented before you write yours.

Who controls patching

If LPL's RMM manages Windows updates, your existing patch reporting may go dark. One provider described a similar arrangement at another firm where the incoming platform left systems unpatched for eight months while local monitoring showed nothing wrong.

What your E&O and cyber carrier think

An insurance broker who covers both advisors and IT firms noted in the August thread that he had not been able to obtain the LPL agreement and expected it to shift burden toward the advisor. Send the requirements to your carrier and your attorney. Ask whether removing tooling you previously attested to affects your coverage or your application answers.

If You Are Staying With LPL

Treat this as a scope change to your IT services, not a tooling argument.

IT providers who have kept their LPL advisor clients are generally doing this: LPL takes endpoint detection and response, and the IT provider keeps everything else. That usually means an alternate RMM for support and monitoring, privileged access management, DNS filtering, firewall management, backup, Microsoft 365 security, and end-user support.

Ask your IT provider to document the split in a written statement of work or service agreement addendum, not just in email. That document should name who detects, who responds, who notifies clients and regulators, and in what order. Reg S-P recordkeeping requires that written procedure to exist before an incident.

If You Are Considering Leaving LPL

The mandate is prompting some advisors to look at other broker-dealers, or at going independent as an RIA. That decision turns on economics, payout, and client transition, not on browser policy. If a technology mandate is part of what is pushing you, ask the same questions of the next platform:

  • What software must be installed on devices you own?
  • Who has remote access, and under what controls?
  • Which security functions does the firm perform, and which stay with you?
  • Who is the named incident response lead, and is it in the agreement?
  • Is your existing IT provider permitted to keep their tools in place?

Independence turns on what a platform can require of the devices you own. Get those answers before you sign.

What To Do Before the September Deadline

  1. Request LPL's current written requirements. Do not plan around spring documentation.
  2. Inventory every device used for firm business, including personal machines and mobile.
  3. Identify what gets removed and what your existing IT provider still covers.
  4. Send the requirements to your attorney and your E&O and cyber carriers.
  5. Update your written information security program and incident response plan to reflect the actual split.
  6. Document the change in your written supervisory procedures with dates.
  7. Confirm in writing who at LPL can remotely access your machines.

If a regulator asks about your Reg S-P compliance next year, "the broker-dealer handles security" is not a working answer. Your firm gets examined, not LPL.

Where an Independent IT Provider Still Matters

Endpoint controls imposed by a custodian are one layer. A financial services practice still needs someone accountable for the network, the tenant, the backups, the people, and the documentation that proves it all works. PK Tech supports financial services firms and other regulated practices in Arizona and nationally, holds SOC 2 attestation, and works alongside platform-mandated tooling.

If you are working through what to keep, what to remove, and what to document before September, contact us to see if we're a fit.