Category: Vendor Due Diligence & Executive Liability
-
Offboarding: The 48 Hours That Decide Whether a Departure Becomes an Incident
Most departing employees take nothing. The procedure exists because you cannot know in advance which departure is the exception — and the window between resignation and access removal is where it goes wrong.
-
How to Read a SOC 2 Report in 30 Minutes — and the Gaps Most Firms Miss
Type and period, scope, subservice organizations, exceptions, CUECs: the thirty-minute method that turns a vendor’s SOC 2 from a filed PDF into an operating control.
-
What Your Cyber Insurance Application Promised — and Whether Your Environment Agrees
The premium was priced on your application’s answers; the claim will be adjusted against them. An annual reconciliation closes the gap between what the firm represented and what the environment does.
-
Cyber for Family Offices: No Examiner, Same Adversaries
Institutional-sized assets, household-sized security programs, and no SEC examination program forcing the issue. The five documents that cover the losses family offices actually take.
-
The Betterment Breach: How Modern RIA Breaches Actually Happen
The January 2026 Betterment incident broke no encryption and hacked no infrastructure. An attacker socially engineered a third-party communications platform — the modern pattern every RIA should understand.
-
Cufflinks or Handcuffs: The New Era of Executive Cybersecurity Liability
Cybersecurity has moved from a delegated IT function to a personal executive liability issue. What the SolarWinds action signals, why the MSP is usually the weakest link, and five ways executives protect themselves.
-
How a Spy Would Conduct Vendor Due Diligence
In intelligence work you never rely on what a subject tells you — you validate the story through independent collection. The same discipline applied to RIA vendor oversight, using OSINT.