Category: Insights
-
What Your Cyber Insurance Application Promised — and Whether Your Environment Agrees
The premium was priced on your application’s answers; the claim will be adjusted against them. An annual reconciliation closes the gap between what the firm represented and what the environment does.
-
Cyber for Family Offices: No Examiner, Same Adversaries
Institutional-sized assets, household-sized security programs, and no SEC examination program forcing the issue. The five documents that cover the losses family offices actually take.
-
How a Spy Would Conduct Vendor Due Diligence
In intelligence work you never rely on what a subject tells you — you validate the story through independent collection. The same discipline applied to RIA vendor oversight, using OSINT.
-
How RIAs Should Configure Microsoft for SEC Exams
Microsoft 365 already contains the controls an RIA needs to meet its SEC cybersecurity obligations. The gap is configuration, evidence, and the space between the MSP and the CCO.
-
How the SEC Expects RIAs to Supervise AI — Today
AI does not trigger a new regulatory regime — it operates within the one that already exists. The ten questions RIAs ask about supervising AI under current SEC rules, answered.
-
Your Identity Theft Red Flags Program Is Probably a Dead Document
Regulation S-ID requires a written Identity Theft Prevention Program — but the SEC now treats identity theft as a cyber-first risk. Why most Red Flags programs are static documents that no longer survive an exam, and how to fix them.
-
“We Have a Plan” Is Not the Same as “We Tested It”: Incident Response Tabletops for RIAs
The amended Regulation S-P requires a workable incident response program — and the SEC judges incident response by how a firm reacts, not what is in the binder. What a tabletop exercise is, why it matters, and what evidence of testing looks like.
-
Microsoft 365 and Azure for RIAs: The Deployment Mistakes I Find Almost Every Time
Five recurring Microsoft 365 and Azure deficiencies I find in nearly every RIA assessment — half-enabled MFA, DLP in name only, unreviewed logs, untuned Defender, and exposed Azure workloads — and the benchmark that fixes them.
-
The New SEC Regulation S-P Amendments: What Every RIA Needs to Know
A plain-language briefing on the 2024 Regulation S-P amendments: the written incident response program, the 30-day notification clock, 72-hour vendor breach standard, expanded definitions, and five-year recordkeeping.
-
The Perimeter Is Gone: What AI-Driven Vulnerability Discovery Means for Small RIAs
When AI systems can autonomously find and exploit vulnerabilities at scale, the patch-and-respond timeline defenders have always relied on collapses. What that means for small RIAs — and why documenting your reasoning now matters.