Category: Insights
-
The Unseen Risk of a Stolen iPhone to Your Firm’s Network
How a single stolen iPhone plus its unlock PIN can cascade into a corporate network compromise under BYOD — and the layered mitigations for both employees and institutional policy.
-
You Can’t Prove Cybersecurity Compliance Without Internal Vulnerability Scans
A vulnerability scan run remotely through a tunnel is not the same as one run inside the network. Why the difference matters for SEC compliance, and the questions executives should ask their IT team.
-
What a Cyber Risk Vulnerability Threat Assessment Actually Involves
The written risk and threat assessment is the single most-requested document in an SEC cyber exam. What a Cyber Risk Vulnerability Threat Assessment (CRVT) covers, how it is performed, and what it produces.
-
Cufflinks or Handcuffs: The New Era of Executive Cybersecurity Liability
Cybersecurity has moved from a delegated IT function to a personal executive liability issue. What the SolarWinds action signals, why the MSP is usually the weakest link, and five ways executives protect themselves.
-
Why Email Is Still Broken — and What You Can Do About It
SPF, DKIM, and DMARC explained — and why the real weakness is inconsistent enforcement across providers. A practical tightening checklist for RIAs, plus how to use DMARC reporting as an intelligence tool.
-
Performing a Cyber Risk and Threat Assessment Using Shodan
A compliance-aligned guide to external visibility: using Shodan to document what the outside world can already see — without crossing into penetration testing — and turning it into the written risk assessment examiners request.
-
The Great Data Reclamation: The Future of RIA Operations, Infrastructure, and Security
Three converging forces — vendor concentration, AI data absorption, and the quantum decryption threat — are reshaping RIA risk. The case for reclaiming control over mission-critical data.
-
How a Spy Would Conduct Vendor Due Diligence
In intelligence work you never rely on what a subject tells you — you validate the story through independent collection. The same discipline applied to RIA vendor oversight, using OSINT.
-
How RIAs Should Configure Microsoft for SEC Exams
Microsoft 365 already contains the controls an RIA needs to meet its SEC cybersecurity obligations. The gap is configuration, evidence, and the space between the MSP and the CCO.
-
How the SEC Expects RIAs to Supervise AI — Today
AI does not trigger a new regulatory regime — it operates within the one that already exists. The ten questions RIAs ask about supervising AI under current SEC rules, answered.