Category: SEC Examinations & Assessments
-
We Read Every SEC Enforcement Document Since 2010. Here Is What They Actually Charge.
Lately I have been getting a lot of requests to demonstrate how a local AI program actually works. So I built the demonstration: a local AI lab, the kind I walked through in What It Actually Looks Like to Run a Local LLM at Your Firm, loaded with a dataset I can share freely because […]
-
SEC Exam Priorities 2026: The Cybersecurity Items
The Division of Examinations published its FY2026 priorities. Translated from priority language into evidence requests: governance, DLP, access controls, ransomware recovery, Reg S-ID, Reg S-P, and AI.
-
How to Run the Cybersecurity Section of Your Annual 206(4)-7 Review
What reviewing cybersecurity actually means when you aren’t a technician: the evidence to pull, the three sentences every finding reduces to, and the calendar that makes year two take half the time.
-
Off-Channel Communications: The Sweep That Reached RIAs
More than $2 billion in penalties later, the off-channel communications sweep reached investment advisers. The violation is not using WhatsApp — it is conducting business in a channel the firm does not capture.
-
You Can’t Prove Cybersecurity Compliance Without Internal Vulnerability Scans
A vulnerability scan run remotely through a tunnel is not the same as one run inside the network. Why the difference matters for SEC compliance, and the questions executives should ask their IT team.
-
Performing a Cyber Risk and Threat Assessment Using Shodan
A compliance-aligned guide to external visibility: using Shodan to document what the outside world can already see — without crossing into penetration testing — and turning it into the written risk assessment examiners request.
-
The SEC Exam Is No Longer Your Biggest Problem
The client mix has shifted from proactive audit work to reactive breach response. Why phishing still wins, why MFA so often has holes around it, and why the endpoint is where programs fall apart.
-
What an SEC Examiner Actually Asks For: The Cybersecurity Document Request List
When an SEC examiner asks about cybersecurity, the answer should be a folder, not a conversation. The documents firms are actually asked to produce — and what each one proves.
-
What a Cyber Risk Vulnerability Threat Assessment Actually Involves
The written risk and threat assessment is the single most-requested document in an SEC cyber exam. What a Cyber Risk Vulnerability Threat Assessment (CRVT) covers, how it is performed, and what it produces.