Remote CISO & Cybersecurity Compliance for RIAs

Your cybersecurity documentation should match your cybersecurity reality.

Every firm we work with shares the same problem: a gap between the two. There are four ways to close it, from a self-serve library to a named CISO. Start with the one that matches who will do the work.

Tier One

Cyber Compliance Consultant · $36,000 / year

A full cybersecurity compliance program operated on an annual cadence, built for firms that have a Chief Compliance Officer and an outsourced IT provider but no internal cybersecurity function. We run that function with and through your CCO; your IT provider continues to operate the environment.

What's Included
  • Evidence file, maintained all year
    Policies, assessment results, remediation records, vendor reviews, and the annual-review workpaper retained and indexed throughout the year — so an examination notice, insurance renewal, or DDQ does not start a document hunt.
  • Independent testing of your environment
    Quarterly external attack-surface assessment (domain enumeration, exposed services, DNS, certificates, breach exposure), annual credentialed internal vulnerability scan, and a Microsoft 365 / Azure configuration audit (MFA coverage, conditional access, logging, retention, sharing, admin oversight) — verifying what your IT provider reports. Gaps prioritized, assigned to the firm or MSP owner, and retested.
  • Cybersecurity policy and procedure manual
    Drafted to firm specifics, maintained, and updated as SEC examination priorities move.
  • Rule 206(4)-7 annual review — cybersecurity workpaper
    Documented assessment of the adequacy and implementation of the firm's cybersecurity policies, organized for examination production and management review. Your CCO retains the complete annual review.
  • Vendor oversight file
    Due-diligence requests issued to in-scope providers, responses evaluated, risks and follow-up documented, and the record retained. Management approves vendor acceptance.
  • Incident response plan
    Drafted to firm specifics, with notification matrix and escalation procedures.
  • SEC examination readiness
    When an examination notice arrives, materials are already in order. If you want MTradecraft in the room during the exam — assembling the production set, reviewing responses, joining examiner calls — examination response support is available, billed as needed.
  • Quarterly advisory call · five-business-day response
    One scheduled advisory call per quarter. Email and other non-incident questions answered within five business days.
Quarterly Delivery Rhythm
  • Q1 Full assessment. External attack surface map, internal vulnerability scan, Microsoft 365 and Azure configuration audit, and policy review against current SEC examination priorities.
  • Q2 Attack surface reassessment and an M365 configuration re-check. First advisory review of remediation progress against the Q1 baseline.
  • Q3 Mid-year compliance file review. Documentation cross-checked against this year's exam priority letter; any drift in M365 configuration flagged, assigned, and retested.
  • Q4 Annual policy refresh and exam-readiness review. Cybersecurity policy, incident response plan, and vendor procedures updated for the coming year.
Best Fit

SEC-registered investment advisers and private fund managers with a Chief Compliance Officer, an outsourced IT provider, and no internal cybersecurity function. Subject to SEC examination.

Tier Two · Most Comprehensive

Remote CISO · $72,000 / year

Everything in the Cyber Compliance Consultant program, plus a named Chief Information Security Officer designation for your firm. The Remote CISO is the right engagement when an insurance carrier, prime broker, custodian, or institutional investor has asked who the firm's CISO is — and the firm needs the answer to be a name, not a role.

Engagement Annual Cost What It Adds
Cyber Compliance Consultant $36,000 Full compliance program operation. No named CISO. No pen testing or tabletop.
Remote CISO $72,000 Everything above, plus named CISO, AI compliance governance, annual pen test, annual tabletop, and 24-hour response on non-incident questions.
Additional Scope
  • Named CISO with defined responsibility
    Brian Hahn serves as the firm's external Chief Information Security Officer, with responsibilities, reporting line, and escalation authority documented in the engagement and on the governance chart — so insurer, custodian, and investor questionnaires get a name with defined duties behind it.
  • DDQ, attestation, and insurance application support
    Institutional DDQs, custodian attestations, and cyber-insurance applications answered from the firm's actual controls and retained evidence, with unsupported claims flagged before submission. Management approves every representation.
  • Incident coordination
    If an incident occurs, the CISO convenes the firm, IT provider, insurer-designated responders, and counsel; tracks decisions and evidence; and documents the file. Notification decisions remain with the firm and its counsel.
  • Board and management reporting
    Quarterly cybersecurity reports for board, audit committee, or partner meetings: open findings and owners, overdue remediation, accepted risks, incidents, vendor issues, and decisions requiring approval.
  • Annual penetration test and tabletop exercise
    A qualified third-party penetration test against the firm's external surface, plus an executive tabletop exercise built against the firm's actual environment. Both documented for the evidence file.
  • AI governance and compliance oversight
    AI use policy drafted to firm specifics, vendor AI risk assessment for tools touching client data, review of existing Form ADV and marketing disclosures for consistency with actual AI use (the CCO and counsel determine required disclosure), and mapping of AI tool use to the firm’s obligations under Rule 204-2 and Rule 206(4)-7.
  • Direct access · 24-hour response on non-incident questions
    Direct line for compliance and security questions throughout the year, answered within 24 hours. Incident escalation follows the response commitments set out in the engagement.
When the Remote CISO Engagement Is the Right Call
  • An institutional investor or pension consultant DDQ asks whether the firm has a designated CISO.
  • A cyber insurance application requires the name and role of the individual responsible for information security.
  • A prime broker or custodian has flagged the absence of named cybersecurity leadership in their annual attestation.
  • An annual penetration test is requested — by an insurance carrier, custodian, or institutional investor — or adopted by the firm as a testing control.
  • The firm has grown to a size where board-level cybersecurity reporting is expected but no internal hire is justified.
  • The firm has experienced a cybersecurity incident and wants ongoing senior oversight without a full-time hire.
  • The firm has deployed or is evaluating AI tools that touch client data, communications, or investment decisions and needs a documented governance framework.
À La Carte

One-time engagements.

Not every firm is ready for an annual engagement. The work below is sold as discrete, scoped engagements with a written statement of work and a defined deliverable. Each is examination-ready and produced to the same evidentiary standard as the subscription tiers above.

Engagement What you receive Fee
Cybersecurity Vulnerability Audit The flagship one-time assessment. External attack surface mapping, internal vulnerability scanning, M365 / Azure configuration audit, OSINT and breach exposure analysis, and policy review — combined into a single examination-ready report with executive summary, regulatory mapping, evidence archive, and remediation roadmap. Starting at $10,000
External Penetration Test Adversarial testing against internet-facing systems — active exploitation of identified vulnerabilities to demonstrate real-world impact. Scope agreed in writing before engagement. Report includes exploitation evidence, proof-of-concept documentation, risk-rated findings, and remediation guidance. Suitable for board reporting and SEC examination. Starting at $8,000
Tabletop Exercise Executive tabletop built against the firm's actual environment — incident scenario design, facilitated walkthrough with named participants, and written after-action report. Documented for the evidence file and the firm's cybersecurity training record. Starting at $5,000
AI Framework Assessment One-time assessment of how the firm actually uses AI tools (email assistants, Copilot, ChatGPT, Claude, Gemini) measured against its existing policies, Form ADV and marketing disclosures, and its obligations under Rule 204-2 books and records and Rule 206(4)-7 supervision. Includes a vendor AI risk review for up to three tools touching client data or firm operations. Delivered as a written findings report with a gap list, regulatory mapping, and a prioritized plan the CCO and counsel can act on. Starting at $5,000
M365 / Azure Configuration Audit Benchmark scan of the firm's Microsoft 365 and Azure environment with pass / fail results mapped to SEC-relevant controls — Regulation S-P, Rule 206(4)-7, Rule 204-2. Written report with screenshots for every finding, regulatory mapping for every failure, and a prioritized remediation roadmap. Starting at $5,000
Internal Network Vulnerability Scan Credentialed Nessus scan of the firm's internal network — patch status, exposed services, misconfigurations, and policy violations across workstations, servers, and network devices. Findings report with severity-ranked vulnerabilities, patch gap analysis, and remediation guidance mapped to SEC examination expectations. Starting at $4,000 per location
External Attack Surface Assessment OSINT, DNS and certificate transparency analysis, and breach exposure check across all internet-facing systems and services associated with the firm. Identifies exposed services, credential leaks, subdomain enumeration, and OSINT-visible risk. Written report with attack surface inventory, prioritized findings, and remediation roadmap. Starting at $4,000
Policy & Documentation Review Review of the firm's cybersecurity policy, incident response plan, vendor risk procedures, and employee technology usage agreement against current SEC examination priorities. Written gap analysis with finding-by-finding regulatory mapping and example corrective language ready for insertion into existing documents. Starting at $3,000
Examination Response Support
Any firm
Active support during a live SEC or FINRA examination — assembling and indexing the cybersecurity production set, flagging inconsistencies before submission, drafting cybersecurity responses for CCO and counsel approval, and joining examiner calls on request. Available to engagement clients and non-clients alike. Exam readiness is included in the Cyber Compliance Consultant and Remote CISO engagements; response time is billed as used. Quoted on request
Billed as used · no minimum

Final fee reflects scope — number of domains, locations, vendors, or systems involved. One-time engagements are fixed-fee and scoped in writing before work begins.

A Note on Economics

A firm purchasing three à la carte engagements — M365 audit, external attack surface assessment, and policy review — starts at $12,000 and scales up from there. The Cyber Compliance Consultant engagement is $36,000 and includes all three in Q1, plus a full year of quarterly attack-surface reassessment, advisory calls, an annual Rule 206(4)-7 review, and a maintained evidence file. At the point a firm is buying multiple one-time engagements in the same year, the subscription is the economically rational choice.

The AI Framework Assessment is a one-time findings engagement. Firms that want the AI use policy drafted and maintained, continued vendor reviews as new tools are adopted, and AI risk integrated into the broader compliance program should engage the Remote CISO tier, which maintains AI governance year-round as part of the standard scope.

Self-Serve

The BrainTrust · $2,500 / year

Some firms are not ready for an engagement but still need the documentation. The BrainTrust is the resource library behind our engagements, sold as an annual membership for firms doing the work themselves.

You own implementation, upkeep, and the evidence file. Nothing is reviewed or maintained by us unless you engage us to do it.

Policy & Procedure Manual builder Firm-specific cybersecurity policies drafted from your answers, mapped to Rule 206(4)-7 and Regulation S-P.
Quarterly External Vulnerability Scan Every quarter, a passive scan of your public footprint: look-alike domains, forgotten subdomains, email-spoofing gaps, exposed services. Summarized against Reg S-P and Reg S-ID. Nothing to install.
Mock SEC Cyber Exam A document request list and readiness scoring built from current examination priorities.
Vendor Due Diligence database Researched profiles on the vendors RIAs actually use, exportable to Word and Excel for the vendor file.
IRP Builder and IR Assistant Incident response plan generator before an incident, and a step-by-step guide that produces a timestamped record during one.
FieldCraft security awareness training Phishing simulations and training with completion records for up to 50 users.
Common Questions

Frequently asked questions

What is the difference between the Cyber Compliance Consultant and Remote CISO engagements?

The Cyber Compliance Consultant ($36,000/year) operates a full cybersecurity compliance program on an annual cadence for SEC-registered firms that have a Chief Compliance Officer and outsourced IT but no internal security function. The Remote CISO ($72,000/year) includes everything in that program and adds a named Chief Information Security Officer designation, AI compliance governance, an annual penetration test, an annual tabletop exercise, board and management briefings, and 24-hour response.

What does a Remote CISO do for an SEC-registered investment adviser?

A Remote CISO provides named cybersecurity leadership without a full-time hire: the individual serves as the firm's external Chief Information Security Officer, documented on its governance chart, prepares quarterly board and management briefings, answers institutional DDQs, custodian attestations, and insurance applications with consistent language, leads incident response, and oversees AI governance. It is the right engagement when an insurance carrier, prime broker, custodian, or institutional investor has asked who the firm's CISO is and the answer needs to be a name, not a role.

How much does cybersecurity compliance cost for an RIA?

MTradecraft's annual engagements are the Cyber Compliance Consultant at $36,000/year and the Remote CISO at $72,000/year, plus a self-serve BrainTrust membership at $2,500/year. One-time engagements are scoped individually and start at $3,000 for a policy and documentation review and $5,000 for an M365 / Azure configuration audit or an AI Framework Assessment; the flagship Cybersecurity Vulnerability Audit starts at $10,000.

What is a Cybersecurity Vulnerability Audit?

The Cybersecurity Vulnerability Audit is MTradecraft's flagship one-time assessment. It combines external attack surface mapping, internal vulnerability scanning, a Microsoft 365 and Azure configuration audit, OSINT and breach-exposure analysis, and a policy review into a single examination-ready report with an executive summary, regulatory mapping, an evidence archive, and a remediation roadmap. It starts at $10,000.

Does MTradecraft offer one-time engagements or only annual programs?

Both. À la carte engagements are scoped in writing with a defined deliverable and produced to the same evidentiary standard as the annual tiers. They include the Cybersecurity Vulnerability Audit, external penetration testing, tabletop exercises, Microsoft 365 and Azure configuration audits, AI Framework Assessments, internal vulnerability scans, policy and documentation reviews, and examination response support.

Is the BrainTrust enough on its own?

For a firm with someone able to do the work, yes. The library gives you the policies, incident response plan, vendor due diligence records, exam checklist, and training that examiners ask for, plus a Quarterly External Vulnerability Scan of your public footprint for the vulnerability-assessment record. What it does not give you is testing inside your environment (internal network, Microsoft 365 and Azure configuration) or anyone outside the firm maintaining the file. Firms that want either of those move to a one-time engagement or the Cyber Compliance Consultant program, and members can apply what they have already built.

Next Step

Tell us what's driving the timing, and we'll tell you which engagement fits.

Examination notice, insurance renewal, DDQ, custodian attestation, post-incident: every engagement starts with a real trigger. The first call is twenty minutes and there is no obligation on either side. If the BrainTrust is the right answer, we will say so.

Book the 20-minute call →