About MTradecraft

A boutique cybersecurity compliance firm — built by an operator, not a vendor.

MTradecraft serves SEC-registered investment advisers, hedge funds, broker-dealers, and family offices. The firm is independent: no hardware resale, no MSP partnerships, no vendor commissions, no managed services pass-through. Recommendations exist because they are right for the client, not because they're profitable for us.

Brian Hahn, Founder and Principal Consultant of MTradecraft

Brian Hahn

Founder & Principal Consultant

Brian Hahn founded MTradecraft to do one thing well: build cybersecurity compliance programs that hold up to an SEC examination. Every part of his background feeds that single job.

He has sat in the chair his clients sit in. At several SEC-registered firms he carried chief compliance officer responsibilities and operations management, designing the cybersecurity programs, IT policies, business continuity plans, and compliance manuals that examiners inspect — and took a firm through an SEC examination with no material findings. He knows what the regulator asks for because he has had to answer it.

That compliance work rests on two decades inside the financial industry. As head equity trader at a long/short equity fund, and earlier as an alumnus of Bridgewater Associates in CS Analytics, Brian worked where data integrity, information security, and documented process were not best practices but daily requirements. His OSINT and corporate intelligence background — built during a period of working as an intelligence analyst in Costa Rica — means each assessment is framed around what an adversary could actually exploit, not a generic control checklist.

Since 2009 he has run more than 300 SEC-style cybersecurity audits, penetration tests, and compliance reviews, and authored MTradecraft's SEC exam readiness framework and the Securing Compliance report. MTradecraft is headquartered in Dallas, TX, and works with clients across the globe.

Operating Philosophy

Three principles. No exceptions.

Principle 01

Compliance before technology

Every technical recommendation has to map to a specific regulatory obligation — Rule 206(4)-7, Regulation S-P, Regulation S-ID, Rule 204-2, or current SEC examination priorities. Generic "best practices" without a regulatory anchor are noise.

Principle 02

Evidence-driven findings

Every finding is supported by an artifact — scan output, screenshot, DNS record, log excerpt, configuration evidence. If a finding cannot be demonstrated to an SEC examiner with evidence, it did not happen.

Principle 03

Independence from vendors

MTradecraft sells no hardware, resells no MSP services, and accepts no vendor commissions. The firm has no financial reason to recommend any tool, platform, or provider it does not believe is right for the client.

Scope

What MTradecraft does, and what it does not.

A clear scope protects clients from overreach and protects MTradecraft from drift. The list below is the actual perimeter of the firm's work.

What MTradecraft Does

  • Cybersecurity compliance consulting for SEC-registered firms
  • External attack surface assessments
  • Internal vulnerability scanning (Nessus credentialed)
  • Microsoft 365 / Azure configuration audits
  • Cybersecurity policy and procedure drafting
  • Rule 206(4)-7 annual reviews
  • Incident response planning
  • Vendor due diligence questionnaire administration
  • Named CISO designation (Remote CISO tier)
  • SEC examination preparation
  • Cyber insurance application support
  • DDQ and custodian attestation support
  • Board and management cybersecurity briefings
  • Tabletop exercise design and facilitation
  • External penetration testing
  • Corporate intelligence and OSINT analysis

What MTradecraft Does Not Do

  • Sell hardware, software, or licenses of any kind
  • Function as a managed service provider or MSP
  • Operate a security operations center (SOC)
  • Provide 24/7 monitoring or incident response on retainer
  • Replace a firm's existing IT provider
  • Accept vendor commissions or referral fees
  • Provide legal advice or act as counsel
  • Provide forensic services or post-breach investigations
  • Issue cyber insurance or underwrite coverage
  • Operate a marketplace or refer clients to specific vendors
  • Provide retail or consumer cybersecurity services
  • Work with firms outside the financial services sector
Direct

If a cybersecurity firm cannot tell you what it doesn't do, it is selling you everything.

MTradecraft is built to do a specific thing well — cybersecurity compliance for SEC-registered firms — and to stay out of the work that belongs to other parties. The first call is a chance to confirm we are the right fit before either side commits.

Book an intro call →

Not ready to talk? The BrainTrust starts free →