Category: Insights
-
A Model Was Pulled Overnight. Was Your Firm Running On It?
On June 12, 2026, a US government directive forced two AI models offline for every customer with no notice and no restoration date. For any firm that had built a workflow on one of them, the lesson is not that a model disappeared. The lesson is that AI governance has to operate in real time.
-
The Reg S-P Deadline Just Passed for Small Firms. Here’s What Examiners Ask For First.
The June 3 compliance date for the amended Regulation S-P has passed for smaller firms. The five documents an examiner will request first — and the 30-day clock most incident response plans still don’t mention.
-
SEC Exam Priorities 2026: The Cybersecurity Items
The Division of Examinations published its FY2026 priorities. Translated from priority language into evidence requests: governance, DLP, access controls, ransomware recovery, Reg S-ID, Reg S-P, and AI.
-
How to Run the Cybersecurity Section of Your Annual 206(4)-7 Review
What reviewing cybersecurity actually means when you aren’t a technician: the evidence to pull, the three sentences every finding reduces to, and the calendar that makes year two take half the time.
-
Off-Channel Communications: The Sweep That Reached RIAs
More than $2 billion in penalties later, the off-channel communications sweep reached investment advisers. The violation is not using WhatsApp — it is conducting business in a channel the firm does not capture.
-
The Wire Transfer Call-Back: The Procedure That Stops One of the Most Preventable RIA Losses
The fraudulent wire request arrives in a genuine thread, from the genuine address, referencing genuine details. The only control that catches it is one that never trusts email at all.
-
You Can’t Protect Data You Haven’t Mapped
Every safeguards obligation shares one silent prerequisite: knowing where customer information actually lives. A five-column worksheet beats a data-governance platform — if it gets maintained.
-
Offboarding: The 48 Hours That Decide Whether a Departure Becomes an Incident
Most departing employees take nothing. The procedure exists because you cannot know in advance which departure is the exception — and the window between resignation and access removal is where it goes wrong.
-
How to Read a SOC 2 Report in 30 Minutes — and the Gaps Most Firms Miss
Type and period, scope, subservice organizations, exceptions, CUECs: the thirty-minute method that turns a vendor’s SOC 2 from a filed PDF into an operating control.
-
Your Vendors Already Turned AI On For You
Your AI policy may say the firm doesn’t use generative AI. Your vendor stack disagrees. Five questions to send every vendor that touches client data — and the tenant audit that takes one afternoon.