Category: Insights
-
How a Spy Would Conduct Vendor Due Diligence
In intelligence work you never rely on what a subject tells you — you validate the story through independent collection. The same discipline applied to RIA vendor oversight, using OSINT.
-
How RIAs Should Configure Microsoft for SEC Exams
Microsoft 365 already contains the controls an RIA needs to meet its SEC cybersecurity obligations. The gap is configuration, evidence, and the space between the MSP and the CCO.