A person has established an IA as a sole proprietorship and works as an IAR out of his home office. To help promote and manage the IA, he has set up a website which contains personal information about his clients. A few weeks after setting up the website, the IAR discovers that the website has been hacked and his customers' account information has been stolen. What is the primary regulatory concern?