What a mock SEC cyber exam is — and what this one covers
A mock SEC cybersecurity examination puts your firm through the document requests an examiner would actually send — before the real letter arrives. Consulting firms typically deliver this as a multi-week paid engagement. This version is a free, self-administered drill for SEC-registered investment advisers: thirty document requests across six categories, thirteen of them in the SEC’s own wording, drawn from real examination request lists.
The requests cover the ground a cybersecurity-focused exam covers: the written policies and procedures and annual review Rule 206(4)-7 requires; the safeguards program, incident response program, and service-provider oversight procedures under amended Regulation S-P (17 CFR 248.30); the identity theft prevention program under Regulation S-ID; and the books-and-records trail Rule 204-2 expects behind all of it. For each request you answer the way you would have to answer the staff: the document exists and is current, it exists but is stale or partial, or it does not exist.
The result is an Examination Readiness Report: every open item, mapped to the rule behind the request, in priority order — a remediation worklist rather than a score. Your answers never leave your browser; nothing you enter is transmitted to or stored on our servers. The drill takes about seven minutes, and viewing the report requires only a free BrainTrust account.
If you are preparing for a real examination, start with SEC cybersecurity exam readiness for what the process looks like end to end, and the free Securing Compliance report for the request lists this drill is built from. The templates that close the gaps the report surfaces — policy manuals, incident response plans, vendor oversight files — live in The BrainTrust library.