Category: Microsoft 365 & Infrastructure Security

  • Deploying Microsoft 365 as an SEC-Defensible Compliance Platform

    Most RIAs already own Microsoft 365. Far fewer have configured it to do the one thing the SEC now expects it to do: enforce, evidence, and retain the safeguards your written policies promise. The gap between “we have M365” and “we can demonstrate the safeguards rule to an examiner” is almost entirely a deployment problem […]

  • Deploying Google Workspace as an SEC-Defensible Compliance Platform

    Google Workspace is a capable compliance platform for an RIA — but only at the right edition, and only when the security controls that ship switched off are deliberately switched on. The single most expensive mistake advisers make here is assuming a Business-tier plan is enough. It is not: the controls the safeguards rule effectively […]

  • The Attack That Doesn’t Need Your Password

    A subscription phishing kit (FBI Alert I-052126-PSA) hijacks Microsoft 365 OAuth tokens with no password and no MFA prompt. Why it is a Reg S-P and 206(4)-7 problem, and the Conditional Access change to make this week.

  • Why Email Is Still Broken — and What You Can Do About It

    SPF, DKIM, and DMARC explained — and why the real weakness is inconsistent enforcement across providers. A practical tightening checklist for RIAs, plus how to use DMARC reporting as an intelligence tool.

  • How RIAs Should Configure Microsoft for SEC Exams

    Microsoft 365 already contains the controls an RIA needs to meet its SEC cybersecurity obligations. The gap is configuration, evidence, and the space between the MSP and the CCO.

  • Microsoft 365 and Azure for RIAs: The Deployment Mistakes I Find Almost Every Time

    Five recurring Microsoft 365 and Azure deficiencies I find in nearly every RIA assessment — half-enabled MFA, DLP in name only, unreviewed logs, untuned Defender, and exposed Azure workloads — and the benchmark that fixes them.

  • The Unseen Risk of a Stolen iPhone to Your Firm’s Network

    How a single stolen iPhone plus its unlock PIN can cascade into a corporate network compromise under BYOD — and the layered mitigations for both employees and institutional policy.