
Kovack Financial, LLC, the Fort Lauderdale parent of broker-dealer Kovack Securities, mailed breach notices on August 10, 2026. The sample letter filed with the California Attorney General says Kovack "became aware of suspicious activity on our computer network on or around August 28, 2025," that an unknown actor "gained access to files within our network between August 8, 2025 to August 27, 2025," and that "On July 16, 2026, it was determined that information related to you was contained within the files and may have been accessed."
Awareness to determination: 322 days. Determination to letter: 25 days. Vermont's filing lists the exposed fields as Social Security numbers, government ID numbers and financial account information. As of August 12, 2026, Kovack has not disclosed the initial access vector, so none of what follows is about how the actor got in.
The 25 days were fine. The 322 were the incident.
Most compliance programs are built around that second interval, and Kovack met it comfortably. The first is where the year went, and it is not a forensics number. Forensic questions have log-shaped answers: which host, which account, how many bytes, when. Answering "whose Social Security number was in that share" means opening the documents, because after the fact there is no other method.
That is a document review project and it is paced like one. This is the second time Kovack has run it. After an intrusion identified on September 5, 2023, notification began July 9, 2024 — 308 days, 43,324 individuals, per the firm's Maine filing. Two incidents, two file reviews, both landing around ten months. At three Florida behavioral health providers the same interval ran 380 days. Ten months is a property of the file share, not of the firm.

Regulation S-P deleted the delay without deleting the work
Both Kovack incidents predate the amended Regulation S-P compliance dates — December 3, 2025 for larger covered institutions, June 3, 2026 for the rest — so neither is a violation of anything. What matters is what the rule does to that timeline going forward.
Two provisions do the work. The first sets the clock: a covered institution must notify affected individuals "as soon as practicable, but not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred" (17 CFR 248.30(a)(4)(iii)). The trigger is awareness. That is the opposite of HIPAA, where the 60-day clock starts at determination and a year-long review can be compliant.
The second closes the obvious escape. Where an institution "is unable to identify which specific individuals' sensitive customer information has been accessed or used without authorization," the rule requires notice to all individuals whose sensitive customer information resides in the affected customer information system (248.30(a)(4)(ii)).
Read together, finishing the file review no longer determines when you notify. It only determines how many people you notify. Run Kovack's August 2025 incident under today's rule and day 30 does not produce an extension — it produces a notification list the size of every customer with sensitive data on that file server.
Industry commenters told the SEC this was impossible, arguing remediation, investigation and list-building could not fit inside 30 days. The Commission kept 30 days, and said the all-individuals default was meant to push firms toward limiting what one breach can reach, naming least privilege as its example.
The practice: make the affected system smaller than the firm
The lever is not review speed. It is how much of the firm one intrusion puts in scope.
Get the copies off the general share. Most Social Security numbers on a broker-dealer's file server sit in ad-hoc copies — new-account packets, scanned IDs saved out of email, spreadsheets exported from the book of record for a project in 2019. The system of record is usually already segmented and logged; the copies are what turn a contained incident into a firm-wide notification. Finding them costs someone several weeks and a run of unpopular conversations with producers who made them for good reasons.
Keep a per-repository headcount. For each place holding sensitive customer information, answer one question inside an hour: if this were breached tomorrow and we could not narrow it, how many notices is that? If the answer takes a week, that week comes out of the 30.
Turn on object access auditing, but only on those paths. Enabled globally it is unusable — Event ID 4663 at volume nobody reads. Narrow it to a SACL on the two or three paths holding regulated records. That converts scoping from a document review into a query, and a query fits in 30 days.
If none of this happens before your next incident, price the default now. Get a real number for notifying every customer on your largest share — mailing, call center, credit monitoring — and treat it as the figure the file review was buying down. Firms that have that number fund the segmentation work.
What to check this week
- Which repositories hold Social Security numbers or account numbers, and how many individuals is that per repository? How long would producing that list take today?
- Does your incident response plan start the clock at discovery of the intrusion, or at determination of affected data? Under Regulation S-P it is the first one.
- Is there file access logging on the shares holding customer records, or would scoping mean opening files?
- Which compliance date applied to you — December 3, 2025 or June 3, 2026 — and has your written incident response program been revised since?
North InfoSec runs AI-assisted penetration testing and security assessments, including the kind of exposure review described above. northinfosec.com