What we hand clients
before the exam.
Reports, frameworks, and working references written for chief compliance officers, IT leads, and managing partners at SEC-registered advisers. Every document is free to read; downloading the PDF creates your free BrainTrust account.
Core reference documents
Four documents covering the full arc of SEC cybersecurity compliance — from understanding what examiners expect, to building the program, to governing AI, to stress-testing your readiness.
Securing Compliance
What SEC cybersecurity examinations actually ask for, drawn from real examination request lists. Covers the rules behind each request, an aggregation of real examination requests organized as a checklist, and the text of a redacted 2023 examination notice.
Read & download → Blueprint · OperationsSEC Cybersecurity Compliance Blueprint
A three-phase operations guide for the person responsible for running cybersecurity compliance at an RIA — whether CCO, IT lead, or COO. Phase 1 covers immediate foundation. Phase 2 covers ongoing operations. Phase 3 covers continuous improvement. Includes checklists, deliverables, and evidence cadences for each phase.
Read & download → Framework · 2026AI Compliance Framework
Six control areas for governing AI at an SEC-registered adviser, separating what Reg S-P, the Marketing Rule, and Rule 204-2 require from recommended practice. Covers inventory, vendor oversight, client communications, records and meeting tools, access, and training.
Read & download → Tool · Self-AssessmentMock SEC Cyber Exam
Walk through the document requests SEC examiners actually send — including thirteen reproduced verbatim — and answer for your own firm. The exam scores what you could produce today and returns a readiness report you can work from.
Take the exam →Templates and tools
Cybersecurity Policies & Procedures Manual
What a compliant P&P manual must cover, how to structure it, and the evidence it needs to generate. The full template — including the Reg S-P revision — is available to BrainTrust Premium subscribers.
Read the guide → Calendar · ChecklistCompliance Calendar
The recurring obligations an SEC-registered adviser carries through the year — annual reviews, filings, ADV deliveries, and the cybersecurity tasks that sit alongside them, organized by quarter.
View & download → ReferenceRegulations Reference
A practitioner breakdown of SEC, FINRA, NYDFS, and state cybersecurity rules — each rule reduced to its obligation, the control that satisfies it, and the evidence an examiner expects.
Open reference →Commentary & analysis
Positions on SEC cybersecurity enforcement, MSP dependency, vendor concentration, and the practical side of running a defensible compliance program. Each piece takes a view rather than summarizing the news.
Want the analysis as it’s published —
not after the fact?
BrainTrust Free delivers the newsletter and the starter template library to your inbox. No charge, and the same email unlocks every PDF on this page.
See what's in BrainTrust Free →