Two people will ask your firm to prove it
Not to promise it. To prove it, with dated records, on the day they ask. Everything in these plans exists to answer one of them.
Plans start at $995 per month. Every plan price on this page is stated at the same size: up to 10 named users and 12 protected devices, on a 12 month term, billed monthly.
Who asks, and what they ask for
The examiner. The SEC’s Division of Examinations lists Regulation S-P in its own named section of the 2026 examination priorities, with a stated focus on firms’ policies and procedures, internal controls, oversight of third-party vendors, and governance practices. After the compliance dates, the Division says it will examine whether firms have developed, implemented and maintained policies and procedures in accordance with the rule’s new provisions.
The underwriter. No cyber insurer binds a policy on a promise. One carrier’s own bind-condition sheet marks three controls as required prior to binding coverage: multi-factor authentication, endpoint protection, and backups held offline and tested for recovery. The answers you give on that application are incorporated into the policy. If an answer is wrong, the policy can be rescinded after a loss, which means cancelled from the beginning, as if it never existed, so it pays nothing.
Regulation S-P is the SEC rule that says a firm must protect its customers’ information and must have a written plan for what happens when someone breaks in. Six obligations sit in it. Written safeguards at 17 CFR 248.30(a)(1). An incident response program at 248.30(a)(3). Customer notification at 248.30(a)(4), which requires notice as soon as practicable and no later than 30 days after the firm becomes aware that unauthorized access to sensitive customer information has occurred or is reasonably likely to have occurred, with eight required contents. Service provider oversight at 248.30(a)(5). Recordkeeping at Rule 204-2(a)(25), six categories retained five years, the first two readily accessible. Disposal at 248.30(b).
Notice runs to affected individuals, and the rule presumes you will give it. The SEC’s own words are that the amendments reflect a presumption of notification. A firm may determine that sensitive information was not accessed, and so that notice is not required, but only after a reasonable investigation, and it has to keep the reasoning. Silence with no paper behind it is the failure the rule is written to catch.
The compliance dates have passed. Advisers at $1.5 billion or more in assets under management were due on December 3, 2025. Everyone else was due on June 3, 2026.
- A direct line to Quinn, the founder, not a sales pipeline.
- Worked in-house by the examiner who scoped it.
- Explainable findings you can verify, with the methodology shown.
The four plans
| What you get | Monitor $995 per month Up to 10 named users and 12 protected devices You have IT covered and your compliance paperwork is current. | Managed IT $1,595 per month Up to 10 named users and 12 protected devices You want us to be your IT department, and your paperwork is current. | Monitor + Comply $1,950 per month Up to 10 named users and 12 protected devices Recommended You have IT covered but need the compliance program built and kept. | Complete $2,495 per month Up to 10 named users and 12 protected devices You want one firm accountable for all of it. |
|---|---|---|---|---|
| Protection | ||||
| Backup of every server, laptop and mailbox | Included | Included | Included | Included |
| Managed detection and response on every device | Included | Included | Included | Included |
| Multi-factor authentication across all five access points | Included | Included | Included | Included |
| Email filtering and security awareness training | Not included | Included | Not included | Included |
| Patch management to a stated target | Not included | Included | Not included | Included |
| Proof | ||||
| Dated monthly evidence pack for your records | Included | Included | Included | Included |
| Quarterly restore test, documented | Included | Included | Included | Included |
| Quarterly privileged access and patch compliance report | Included | Included | Included | Included |
| Cyber insurance application support, from records | Included | Included | Included | Included |
| Day-to-day IT | ||||
| Helpdesk for your staff | Not included | Included | Not included | Included |
| New starters, leavers and device setup | Not included | Included | Not included | Included |
| Remediation and hardening hours included each month | Not included | 2 hrs | Not included | 2 hrs |
| Regulation S-P compliance program | ||||
| Written incident response program, reviewed annually | Not included | Not included | Included | Included |
| Client notification decision file, including reasons not to notify | Not included | Not included | Included | Included |
| Vendor inventory, due diligence and 72-hour notice terms | Not included | Not included | Included | Included |
| Annual tabletop exercise with written after-action report | Not included | Not included | Included | Included |
| Records schedule and examiner-ready document pack | Not included | Not included | Included | Included |
Getting started: deployment and a first verified restore is a one time $9,500. The compliance program build is a one time $12,500, required once on the two plans that include it.
Your insurance application, control by control
Must have
One carrier's own bind-condition sheet marks controls of this kind as required before it will bind coverage. These are the ones that stop a deal.
Changes the price
You can get a policy without it, but it costs more, or you get lower limits.
On the form
They ask, and the answer goes on file, but on its own it rarely stops anything.
| What the application asks | Monitor | Managed IT | Monitor + Comply | Complete |
|---|---|---|---|---|
| Must have | ||||
| Two-step login (MFA) on email | Covered | Covered | Covered | Covered |
| Two-step login on any way in from outside the office | Covered | Covered | Covered | Covered |
| Security software on every laptop and server | Covered | Covered | Covered | Covered |
| Backups an attacker cannot reach or overwrite, and proven to restore | Covered | Covered | Covered | Covered |
| Calling to confirm a payment before you send it, and a second person approving large onesA must-have for the part of the policy that covers being tricked into sending money, rather than for the policy as a whole. | Covered | Covered | Covered | Covered |
| Changes the price | ||||
| Two-step login on the accounts that can change everything, and on the backup system | Covered | Covered | Covered | Covered |
| What share of devices are covered, and whether the software cuts an infected one off the network by itself | Covered | Covered | Covered | Covered |
| Backups kept apart from the day-to-day network, so one break-in cannot take both | Covered | Covered | Covered | Covered |
| Someone has actually restored a file from backup and written down that it worked | Covered | Covered | Covered | Covered |
| Email screened before it arrives, and attachments opened somewhere safe first | Not covered | Covered | Not covered | Covered |
| How fast you install urgent security updates, and how often you hit that target | Not covered | Covered | Not covered | Covered |
| How many accounts can change anything, and why each one needs to | Covered | Covered | Covered | Covered |
| On the form | ||||
| Software the maker has stopped fixing, still in use | Covered | Covered | Covered | Covered |
| Staff training, and test phishing emails sent to see who clicks | Not covered | Covered | Not covered | Covered |
| A written plan for a break-in, rehearsed once a year | Not covered | Not covered | Covered | Covered |
| Checking the outside companies that touch your client data | Not covered | Not covered | Covered | Covered |
These are questions from real insurance applications. Where a plan does not cover something, we say so here rather than let you find out on the form.
The one that matters most for an advisory firm is the wire procedure. Every plan includes a written wire verification procedure: call-backs to a number agreed at the time of onboarding rather than a number supplied in the request, and dual control on transfers above ten thousand dollars, approved by someone other than the person who initiated it, on a different device.
What we do, and how often
Every month
- Control drift reviewProduces: A triaged, recorded list of what stopped reporting and what was escalated
- Backup verificationProduces: Confirmation that every server, laptop and mailbox is backed up
- Evidence packProduces: A dated snapshot of every device and user, filed to your archive
Every quarter
- Restore testProduces: A written result for a real file set restored from backup
- Patch compliance reportProduces: Performance against a stated target, with the rolling twelve-month rate
- Access exception reviewProduces: A record of new devices, bypass codes and administrator accounts
- Report to your chief compliance officerProduces: One page: what changed, what lapsed, what needs a decision
Every year
- Privileged account reviewProduces: Every administrator account listed with a written reason it still exists
- End-of-life inventoryProduces: A written statement of what protects anything the maker no longer supports
- Insurance evidence packProduces: The control sections of your application or renewal, supported by dated records
The compliance program
Included in Monitor + Comply and Complete. This is the part that produces the documents themselves, not just the evidence that controls are running. The incident response program is written to the rule with its three parts kept separate and visible: assessment, containment and control, and notification. The notification decision file is a template for the decision, with the eight required contents pre-tested, and a filing structure that records the reason you decided not to notify where that was the outcome. The service provider program is the inventory, the due diligence file, the 72-hour notification expectation put to each provider in writing, and a monitoring cadence, because the rule asks for oversight as an activity rather than a policy on a shelf.
An annual tabletop exercise and a written after-action report are also included. That one is not required by the rule text, and we say so plainly rather than imply otherwise. It is what turns a written plan into a tested one. The records schedule maps all six categories to the recordkeeping rule, and the exam readiness pack is assembled directly against the SEC’s published document request, so the answer to “please provide” is a folder rather than a fire drill.
An honest boundary. We prepare these documents for your compliance officer and your counsel to review, revise and adopt. We are not your lawyers and we do not give legal or regulatory advice. Where a judgment call belongs to your firm, we set it up so the decision is easy to make and easy to evidence, and then you make it.
What this means for you
- Written scope before any work. You see a written scope covering deliverables, timeline, and price, and you approve it before we begin. You are never billed for work you did not authorize.
- We commit to findings, not outcomes. We tell you up front what the evidence can and cannot establish. Recovery, attribution, and prosecution are decided by banks, platforms, insurers, and courts. We produce the record they act on, and we put that distinction in writing.
- Every case is investigated, not just scanned. A credentialed examiner reviews every case before findings leave the practice. You get a documented investigation to court-admissible standards, not a single automated scan and a one-line answer.
- We will tell you if you do not need us. If a free or simpler step would resolve your situation, whether a police report, an IC3 filing, or a platform's own recovery flow, we point you there first.
What is included, what is not, and what stays yours
We do
- Configure, monitor and maintain every product in your plan
- The monthly, quarterly and annual work in the service calendar above
- Deliver a dated evidence pack to your archive every month
- Support one insurance application or renewal each year
- Escalate anything we find, with a written record
- On Managed IT and Complete: helpdesk, new starters and leavers, device setup, and two hours of remediation and hardening every month
We do not
- Helpdesk on the two Monitor plans, which stays with your own IT
- Incident response and forensics inside the monthly fee, which is billed separately
- Buying or owning your hardware, software licenses, phones or cabling
- Legal, regulatory or insurance advice
- Writing or sending your breach notifications
- Acting as, or standing in for, your chief compliance officer
- Work on site or outside business hours, except by arrangement
You do
- Name a primary and a backup technical contact, and tell us if that changes
- Respond within four business hours when we escalate something urgent
- Adopt the policies we prepare, with your counsel
- Own the accuracy of anything you file with a regulator or an insurer
- Tell us before you add people, offices, systems or vendors
- Keep your own IT resource in place on the Monitor plans, or tell us if that ends
Written plainly here so nothing is a surprise in month three. The agreement carries the same boundaries in full.
If the worst happens
Most providers hand you off at the worst possible moment. We do not. The people who protect your firm are the same people who examine the devices and accounts and write the report, and stand behind it if it is ever challenged.
Hour one to day ten
- Hour one, contain and preserve. We take your call and stop the bleeding. We capture evidence to forensic standard from the first minute, with chain of custody intact. Most of what is lost in a breach is lost in the first few hours, by well-meaning people rebooting machines.
- Days one to five, examine. Our examiners work the images and the logs. What got in, how, what it touched, what left the building, and whether client information was actually reached. Those are the questions your notification decision turns on.
- By day ten, report. A written forensic report your compliance officer, your counsel, your insurer and a regulator can all read. Written to be defensible, because we write reports that go to court.
- Then notify, rebuild, and if needed testify. The report feeds your 30-day notification decision and the record behind it. We rebuild the environment. If the matter is litigated, our examiners give evidence.
Who does the work
A digital forensics practice. Quinn holds a degree in cybersecurity from SANS Technology Institute and 9 active GIAC certifications across GIAC, including incident handling, intrusion analysis and mobile forensics. That credential mix is what supports qualification as an expert witness under the Daubert and Frye standards.
Two things we put in writing. Where privilege matters, and in a serious incident it usually does, we take our instructions through your lawyer rather than direct. That is the arrangement that gives the report the best chance of staying protected, and we set it up at onboarding so it is ready rather than improvised at 2am. And you can always get a second opinion: you may bring in an independent examiner at any point, for any reason, and we will hand over the images, the logs and our working papers to help them.
Chain of custody is the unbroken written record of who held a piece of evidence and when, which is what stops the other side arguing it was altered. Privilege means the other side in a lawsuit cannot demand to see a document.
A great deal of what we are called for is not a hacker at all. A departing employee who copied the client file to a personal drive. A dispute where the record sits in a mailbox or on a phone. A preservation request that needs a defensible extraction. And the most common loss an advisory firm actually suffers, a wire that went to the wrong account after a convincing email. Tracing where the money went is a different discipline from reading a firewall log, and it is what this firm was built to do.
The first ninety days
- Days 1 to 10, discovery and paperwork. We inventory every device, user, mailbox and vendor. You get our own due diligence pack: our controls, our insurance, our subprocessors, our incident plan. Reg S-P at 17 CFR 248.30(a)(5) requires you to have written policies for vetting and monitoring your service providers, so we hand ours over before you ask.
- Days 10 to 30, deployment. Backup, endpoint protection and monitoring on every device. Multi-factor login across all five access points. First backup taken and first restore proven, not assumed.
- Days 30 to 60, the program. On the Comply plans: incident response program drafted, notification templates tested, vendor inventory built and the 72-hour expectation put to each provider in writing. Your counsel reviews. Your compliance officer adopts.
- Days 60 to 90, proof and rehearsal. First full evidence pack delivered. First tabletop exercise run, with the written after-action report. If you are placing insurance, we assemble the control evidence for your broker.
What we need from you to start: a named technical contact and a backup, administrative access to your Microsoft or Google tenant, a list of every vendor that touches client information, your current policies however incomplete, your penetration test report if you have one, and your counsel’s name so the program is prepared under their review.
On the penetration test. If you have had one, the findings are a separate project scoped finding by finding against an agreed cap. We do not fold open-ended remediation into a fixed monthly fee, because that is how a fixed fee stops being fixed.
Rates, growth and the small print
Project and hourly rates
| Work | Standard | On a plan |
|---|---|---|
| Remediation beyond the included allowance | $400/hr | $195/hr |
| Security consulting, assessment and hardening | $400/hr | $275/hr |
| Incident response, containment and rebuild | $400/hr | $275/hr |
| Forensic examination and written report | $400/hr | $325/hr |
| Deposition and trial testimony, four-hour minimum | $400/hr | $400/hr Same as the standard rate. |
| Done-for-you device forensics | from $3,000 | from $3,000 Same as the standard rate. |
| Refundable engagement retainer | $5,000 | Waived |
All rates per hour unless stated. There is no surge for nights, weekends or holidays, on either column. Court time is never discounted, because the hour is the same hour whoever is paying for it.
As your firm grows
Additional named user
$35/mo
Additional workstation
$25/mo
Additional server
$70/mo
New user setup
$150
User departure and offboarding
$100
New device deployment
$200
Term
Twelve months, billed monthly, renewing unless either of us gives 60 days' notice.
Your data
Your tenants are yours. On exit we return your records in a usable format within 30 days and certify what we destroyed.
Our duty to you
We are a service provider under the rule. We will tell you within 72 hours of becoming aware of a breach affecting a system holding your customer information.
Insurance
We recommend you carry cyber cover and we supply the control evidence to your broker. We are not licensed in insurance and give no insurance advice.
Growth is reviewed quarterly, effective from the date of the change. Devices count by type, because a server costs several times what a laptop does. Where a vendor sells licenses in blocks, that block is invoiced in full when it is bought.
How an engagement begins
- A scoping call. Forty-five minutes. We walk your environment, tell you what an examiner would ask for that you cannot currently produce, and put a fixed number against it. There is no charge and no obligation.
- Written scope. Deliverables, timeline and price, approved by you before any work begins.
- Discovery, deployment and the program. The ninety days above, with a dated record at every step.
Why this work matters
A firm of ten people carries the same obligations as a firm of a thousand, with none of the staff to meet them. What an examiner and an underwriter both want is not a promise but a dated record, and producing that record every month is the whole of this offering.

















