An examiner doesn’t ask, “Is your firm secure?” They say, “Prove your firm is compliant with all cybersecurity regulations.” The proof is not the policies. It is the records showing the policies were implemented and the controls operated. Examiners read the policies. They do not stop there.
The mechanism is the initial document request. Shortly after the notice of examination, the Division of Examinations sends a list of information and documents, usually with about two weeks to respond. The Division published what that list typically contains as an attachment to its September 2023 risk alert on scoping adviser exams (sec.gov, PDF). The cybersecurity portion of the file answers a handful of lines on that list.
This article walks the five documents that answer those lines, using a concrete firm. Tradecraft Advisors LLC is a $750 million SEC-registered adviser with 22 employees in two Texas offices, one CCO who also runs operations, an outsourced IT provider, and a familiar stack: Microsoft 365, a cloud CRM, a portfolio platform, a custodian portal, e-signature. Tradecraft Advisors does not exist. We invented it so that a complete compliance file could be published without touching a real client’s records, with every assumption printed next to the documents. The full file is at mtradecraft.com/sample-firm.
The article covers five documents in the order the request list reaches them: the written cybersecurity program, the employee training record, the vendor due diligence file, the incident response plan with its log and incident record, and the gap report from the firm’s own testing. Each section quotes the line on the SEC’s request list that the document answers, explains what the examiner is checking when it arrives, cites the rule behind it (Rule 206(4)-7, Regulation S-P as amended in 2024, Regulation S-ID, and Rule 204-2), and shows the corresponding page from Tradecraft Advisors’ file. It closes with a one-page table mapping all five documents to their request-list items and rules.
The rest of this article is free to read with a BrainTrust account. Free members also get every Insight, the Securing Compliance exam report, the Mock SEC Cyber Exam, and the Document Review Matrix — name and email, no card.