Remote CISO & Cybersecurity Compliance for RIAs

Your cybersecurity documentation should match your cybersecurity reality.

Every firm we work with shares the same problem: a gap between the two. The engagements below close the gap on an annual cadence and keep it closed for as long as the relationship runs.

Tier One

Cyber Compliance Consultant — $36,000 / year

A full cybersecurity compliance program operated on an annual cadence, built for firms that have a Chief Compliance Officer and an outsourced IT provider but no internal cybersecurity function. We run that function with and through your CCO; your IT provider continues to operate the environment.

What's Included
  • Evidence file, maintained all year
    Policies, assessment results, remediation records, vendor reviews, and the annual-review workpaper retained and indexed throughout the year — so an examination notice, insurance renewal, or DDQ does not start a document hunt.
  • Independent testing of your environment
    Quarterly external attack-surface assessment (domain enumeration, exposed services, DNS, certificates, breach exposure), annual credentialed internal vulnerability scan, and a Microsoft 365 / Azure configuration audit (MFA coverage, conditional access, logging, retention, sharing, admin oversight) — verifying what your IT provider reports. Gaps prioritized, assigned to the firm or MSP owner, and retested.
  • Cybersecurity policy and procedure manual
    Drafted to firm specifics, maintained, and updated as SEC examination priorities move.
  • Rule 206(4)-7 annual review — cybersecurity workpaper
    Documented assessment of the adequacy and implementation of the firm's cybersecurity policies, organized for examination production and management review. Your CCO retains the complete annual review.
  • Vendor oversight file
    Due-diligence requests issued to in-scope providers, responses evaluated, risks and follow-up documented, and the record retained. Management approves vendor acceptance.
  • Incident response plan
    Drafted to firm specifics, with notification matrix and escalation procedures.
  • SEC examination readiness
    When an examination notice arrives, materials are already in order. If you want MTradecraft in the room during the exam — assembling the production set, reviewing responses, joining examiner calls — examination response support is available at $250 / hour, billed as needed.
  • Quarterly advisory call · five-business-day response
    One scheduled advisory call per quarter. Email and other non-incident questions answered within five business days.
Quarterly Delivery Rhythm
  • Q1 Full assessment. External attack surface map, internal vulnerability scan, Microsoft 365 and Azure configuration audit, and policy review against current SEC examination priorities.
  • Q2 Attack surface reassessment and an M365 configuration re-check. First advisory review of remediation progress against the Q1 baseline.
  • Q3 Mid-year compliance file review. Documentation cross-checked against this year's exam priority letter; any drift in M365 configuration flagged, assigned, and retested.
  • Q4 Annual policy refresh and exam-readiness review. Cybersecurity policy, incident response plan, and vendor procedures updated for the coming year.
Best Fit

SEC-registered investment advisers and private fund managers with a Chief Compliance Officer, an outsourced IT provider, and no internal cybersecurity function. Subject to SEC examination.

Tier Two — Most Comprehensive

Remote CISO — $72,000 / year

Everything in the Cyber Compliance Consultant program, plus a named Chief Information Security Officer designation for your firm. The Remote CISO is the right engagement when an insurance carrier, prime broker, custodian, or institutional investor has asked who the firm's CISO is — and the firm needs the answer to be a name, not a role.

Engagement Annual Cost What It Adds
Cyber Compliance Consultant $36,000 Full compliance program operation. No named CISO. No pen testing or tabletop.
Remote CISO $72,000 Everything above, plus named CISO, AI compliance governance, annual pen test, annual tabletop, and 24-hour response on non-incident questions.
Additional Scope
  • Named CISO with defined responsibility
    Brian Hahn serves as the firm's external Chief Information Security Officer, with responsibilities, reporting line, and escalation authority documented in the engagement and on the governance chart — so insurer, custodian, and investor questionnaires get a name with defined duties behind it.
  • DDQ, attestation, and insurance application support
    Institutional DDQs, custodian attestations, and cyber-insurance applications answered from the firm's actual controls and retained evidence, with unsupported claims flagged before submission. Management approves every representation.
  • Incident coordination
    If an incident occurs, the CISO convenes the firm, IT provider, insurer-designated responders, and counsel; tracks decisions and evidence; and documents the file. Notification decisions remain with the firm and its counsel.
  • Board and management reporting
    Quarterly cybersecurity reports for board, audit committee, or partner meetings: open findings and owners, overdue remediation, accepted risks, incidents, vendor issues, and decisions requiring approval.
  • Annual penetration test and tabletop exercise
    A qualified third-party penetration test against the firm's external surface, plus an executive tabletop exercise built against the firm's actual environment. Both documented for the evidence file.
  • AI governance and compliance oversight
    AI use policy drafted to firm specifics, vendor AI risk assessment for tools touching client data, review of existing Form ADV and marketing disclosures for consistency with actual AI use (the CCO and counsel determine required disclosure), and mapping of AI tool use to the firm’s obligations under Rule 204-2 and Rule 206(4)-7.
  • Direct access · 24-hour response on non-incident questions
    Direct line for compliance and security questions throughout the year, answered within 24 hours. Incident escalation follows the response commitments set out in the engagement.
When the Remote CISO Engagement Is the Right Call
  • An institutional investor or pension consultant DDQ asks whether the firm has a designated CISO.
  • A cyber insurance application requires the name and role of the individual responsible for information security.
  • A prime broker or custodian has flagged the absence of named cybersecurity leadership in their annual attestation.
  • An annual penetration test is requested — by an insurance carrier, custodian, or institutional investor — or adopted by the firm as a testing control.
  • The firm has grown to a size where board-level cybersecurity reporting is expected but no internal hire is justified.
  • The firm has experienced a cybersecurity incident and wants ongoing senior oversight without a full-time hire.
  • The firm has deployed or is evaluating AI tools that touch client data, communications, or investment decisions and needs a documented governance framework.
À La Carte

One-time engagements.

Not every firm is ready for an annual engagement. The work below is sold as discrete, scoped engagements with a written statement of work and a defined deliverable. Each is examination-ready and produced to the same evidentiary standard as the subscription tiers above.

Engagement What you receive Fee
Cyber Risk & Vulnerability Threat Assessment (CRVT) The flagship one-time assessment. External attack surface mapping, internal vulnerability scanning, M365 / Azure configuration audit, OSINT and breach exposure analysis, and policy review — combined into a single examination-ready report with executive summary, regulatory mapping, evidence archive, and remediation roadmap. Starting at $10,000
External Penetration Test Adversarial testing against internet-facing systems — active exploitation of identified vulnerabilities to demonstrate real-world impact. Scope agreed in writing before engagement. Report includes exploitation evidence, proof-of-concept documentation, risk-rated findings, and remediation guidance. Suitable for board reporting and SEC examination. Starting at $8,000
Tabletop Exercise Executive tabletop built against the firm's actual environment — incident scenario design, facilitated walkthrough with named participants, and written after-action report. Documented for the evidence file and the firm's cybersecurity training record. Starting at $5,000
AI Compliance Framework Build One-time AI governance build for firms deploying AI tools without an existing framework. Includes AI use policy drafted to firm specifics, vendor AI risk assessment for up to three AI tools touching client data or firm operations, Form ADV AI disclosure review, and a written mapping of AI tool use to the firm’s obligations under Rule 204-2 books and records and Rule 206(4)-7 supervision. Delivered as a complete policy document and evidence file. Additional vendor assessments beyond three available at additional cost. Starting at $35,000
M365 / Azure Configuration Audit Benchmark scan of the firm's Microsoft 365 and Azure environment with pass / fail results mapped to SEC-relevant controls — Regulation S-P, Rule 206(4)-7, Rule 204-2. Written report with screenshots for every finding, regulatory mapping for every failure, and a prioritized remediation roadmap. Starting at $5,000
Internal Network Vulnerability Scan Credentialed Nessus scan of the firm's internal network — patch status, exposed services, misconfigurations, and policy violations across workstations, servers, and network devices. Findings report with severity-ranked vulnerabilities, patch gap analysis, and remediation guidance mapped to SEC examination expectations. Starting at $4,000 per location
External Attack Surface Assessment OSINT, DNS and certificate transparency analysis, and breach exposure check across all internet-facing systems and services associated with the firm. Identifies exposed services, credential leaks, subdomain enumeration, and OSINT-visible risk. Written report with attack surface inventory, prioritized findings, and remediation roadmap. Starting at $4,000
Policy & Documentation Review Review of the firm's cybersecurity policy, incident response plan, vendor risk procedures, and employee technology usage agreement against current SEC examination priorities. Written gap analysis with finding-by-finding regulatory mapping and example corrective language ready for insertion into existing documents. Starting at $3,000
Examination Response Support
Any firm
Active support during a live SEC or FINRA examination — assembling and indexing the cybersecurity production set, flagging inconsistencies before submission, drafting cybersecurity responses for CCO and counsel approval, and joining examiner calls on request. Available to engagement clients and non-clients alike. Exam readiness is included in the Cyber Compliance Consultant and Remote CISO engagements; response time is billed as used. $250 / hour
As needed · no minimum
Incident Response Coordination
Non-subscribers
For firms not on a Cyber Compliance Consultant or Remote CISO engagement who are managing a confirmed or suspected security incident. MTradecraft provides coordination and regulatory management — initial triage, insurance carrier activation, Regulation S-P notification analysis and deadline tracking, legal coordination, and post-incident documentation. Technical forensics and remediation handled by the firm's insurance-panel IR provider. $300 / hour
4-hour minimum

Final fee reflects scope — number of domains, locations, vendors, or systems involved. One-time engagements are fixed-fee and scoped in writing before work begins.

A Note on Economics

A firm purchasing three à la carte engagements — M365 audit, external attack surface assessment, and policy review — starts at $12,000 and scales up from there. The Cyber Compliance Consultant engagement is $36,000 and includes all three in Q1, plus a full year of quarterly attack-surface reassessment, advisory calls, an annual Rule 206(4)-7 review, and a maintained evidence file. At the point a firm is buying multiple one-time engagements in the same year, the subscription is the economically rational choice.

The AI Compliance Framework Build is sold as a one-time policy and vendor assessment engagement. Firms that want ongoing AI governance — continued vendor reviews as new tools are adopted, annual policy refresh against evolving SEC guidance, and AI risk integration into the broader compliance program — should engage the Remote CISO tier, which maintains AI compliance year-round as part of the standard scope.

Self-Serve

The BrainTrust — $2,500 / year

Some firms are not ready for a full engagement, but still need the documentation. The BrainTrust is MTradecraft's resource library — policy templates, frameworks, the AI compliance framework, incident response materials, and FieldCraft Security Awareness Training — sold as an annual membership for firms doing the work themselves.

Common Questions

Frequently asked questions

What is the difference between the Cyber Compliance Consultant and Remote CISO engagements?

The Cyber Compliance Consultant ($36,000/year) operates a full cybersecurity compliance program on an annual cadence for SEC-registered firms that have a Chief Compliance Officer and outsourced IT but no internal security function. The Remote CISO ($72,000/year) includes everything in that program and adds a named Chief Information Security Officer designation, AI compliance governance, an annual penetration test, an annual tabletop exercise, board and management briefings, and 24-hour response.

What does a Remote CISO do for an SEC-registered investment adviser?

A Remote CISO provides named cybersecurity leadership without a full-time hire: the individual serves as the firm's external Chief Information Security Officer, documented on its governance chart, prepares quarterly board and management briefings, answers institutional DDQs, custodian attestations, and insurance applications with consistent language, leads incident response, and oversees AI governance. It is the right engagement when an insurance carrier, prime broker, custodian, or institutional investor has asked who the firm's CISO is and the answer needs to be a name, not a role.

How much does cybersecurity compliance cost for an RIA?

MTradecraft's annual engagements are the Cyber Compliance Consultant at $36,000/year and the Remote CISO at $72,000/year, plus a self-serve BrainTrust membership at $2,500/year. One-time engagements are scoped individually and range from $3,000 for a policy and documentation review to $35,000 for an AI Compliance Framework build; the flagship Cyber Risk & Vulnerability Threat Assessment starts at $10,000.

What is a Cyber Risk & Vulnerability Threat Assessment (CRVT)?

The CRVT is MTradecraft's flagship one-time assessment. It combines external attack surface mapping, internal vulnerability scanning, a Microsoft 365 and Azure configuration audit, OSINT and breach-exposure analysis, and a policy review into a single examination-ready report with an executive summary, regulatory mapping, an evidence archive, and a remediation roadmap. It starts at $10,000.

Does MTradecraft offer one-time engagements or only annual programs?

Both. À la carte engagements are scoped in writing with a defined deliverable and produced to the same evidentiary standard as the annual tiers. They include the CRVT, external penetration testing, tabletop exercises, Microsoft 365 and Azure configuration audits, internal vulnerability scans, policy and documentation reviews, vendor due diligence questionnaires, and incident response coordination for non-subscribers at $300/hour.

Next Step

Tell us what's driving the timing — and we'll tell you which engagement fits.

Examination notice, insurance renewal, DDQ, custodian attestation, post-incident — every engagement starts with a real trigger. The first call is twenty minutes and there is no obligation on either side.

Book the 20-minute call →