Active Incident? 24/7 Response →
SleuthX

Managed Security & Compliance

Security and Compliance for a Firm of About Ten People

Monthly security monitoring, day-to-day IT, and a written compliance program for firms of about ten people. Run by a digital-forensics practice.

Two people will ask your firm to prove it

Not to promise it. To prove it, with dated records, on the day they ask. Everything in these plans exists to answer one of them.

Plans start at $995 per month. Every plan price on this page is stated at the same size: up to 10 named users and 12 protected devices, on a 12 month term, billed monthly.

Who asks, and what they ask for

The examiner. The SEC’s Division of Examinations lists Regulation S-P in its own named section of the 2026 examination priorities, with a stated focus on firms’ policies and procedures, internal controls, oversight of third-party vendors, and governance practices. After the compliance dates, the Division says it will examine whether firms have developed, implemented and maintained policies and procedures in accordance with the rule’s new provisions.

The underwriter. No cyber insurer binds a policy on a promise. One carrier’s own bind-condition sheet marks three controls as required prior to binding coverage: multi-factor authentication, endpoint protection, and backups held offline and tested for recovery. The answers you give on that application are incorporated into the policy. If an answer is wrong, the policy can be rescinded after a loss, which means cancelled from the beginning, as if it never existed, so it pays nothing.

Regulation S-P is the SEC rule that says a firm must protect its customers’ information and must have a written plan for what happens when someone breaks in. Six obligations sit in it. Written safeguards at 17 CFR 248.30(a)(1). An incident response program at 248.30(a)(3). Customer notification at 248.30(a)(4), which requires notice as soon as practicable and no later than 30 days after the firm becomes aware that unauthorized access to sensitive customer information has occurred or is reasonably likely to have occurred, with eight required contents. Service provider oversight at 248.30(a)(5). Recordkeeping at Rule 204-2(a)(25), six categories retained five years, the first two readily accessible. Disposal at 248.30(b).

Notice runs to affected individuals, and the rule presumes you will give it. The SEC’s own words are that the amendments reflect a presumption of notification. A firm may determine that sensitive information was not accessed, and so that notice is not required, but only after a reasonable investigation, and it has to keep the reasoning. Silence with no paper behind it is the failure the rule is written to catch.

The compliance dates have passed. Advisers at $1.5 billion or more in assets under management were due on December 3, 2025. Everyone else was due on June 3, 2026.

The four plans

What each plan includes, feature by feature.
What you get
Monitor
$995 per month
Up to 10 named users and 12 protected devices
You have IT covered and your compliance paperwork is current.
Managed IT
$1,595 per month
Up to 10 named users and 12 protected devices
You want us to be your IT department, and your paperwork is current.
Monitor + Comply
$1,950 per month
Up to 10 named users and 12 protected devices
Recommended
You have IT covered but need the compliance program built and kept.
Complete
$2,495 per month
Up to 10 named users and 12 protected devices
You want one firm accountable for all of it.
Protection
Backup of every server, laptop and mailboxIncludedIncludedIncludedIncluded
Managed detection and response on every deviceIncludedIncludedIncludedIncluded
Multi-factor authentication across all five access pointsIncludedIncludedIncludedIncluded
Email filtering and security awareness trainingNot includedIncludedNot includedIncluded
Patch management to a stated targetNot includedIncludedNot includedIncluded
Proof
Dated monthly evidence pack for your recordsIncludedIncludedIncludedIncluded
Quarterly restore test, documentedIncludedIncludedIncludedIncluded
Quarterly privileged access and patch compliance reportIncludedIncludedIncludedIncluded
Cyber insurance application support, from recordsIncludedIncludedIncludedIncluded
Day-to-day IT
Helpdesk for your staffNot includedIncludedNot includedIncluded
New starters, leavers and device setupNot includedIncludedNot includedIncluded
Remediation and hardening hours included each monthNot included2 hrsNot included2 hrs
Regulation S-P compliance program
Written incident response program, reviewed annuallyNot includedNot includedIncludedIncluded
Client notification decision file, including reasons not to notifyNot includedNot includedIncludedIncluded
Vendor inventory, due diligence and 72-hour notice termsNot includedNot includedIncludedIncluded
Annual tabletop exercise with written after-action reportNot includedNot includedIncludedIncluded
Records schedule and examiner-ready document packNot includedNot includedIncludedIncluded

Getting started: deployment and a first verified restore is a one time $9,500. The compliance program build is a one time $12,500, required once on the two plans that include it.

Your insurance application, control by control

Must have

One carrier's own bind-condition sheet marks controls of this kind as required before it will bind coverage. These are the ones that stop a deal.

Changes the price

You can get a policy without it, but it costs more, or you get lower limits.

On the form

They ask, and the answer goes on file, but on its own it rarely stops anything.

What a cyber insurance application asks about, and which plan answers it.
What the application asksMonitorManaged ITMonitor + ComplyComplete
Must have
Two-step login (MFA) on emailCoveredCoveredCoveredCovered
Two-step login on any way in from outside the officeCoveredCoveredCoveredCovered
Security software on every laptop and serverCoveredCoveredCoveredCovered
Backups an attacker cannot reach or overwrite, and proven to restoreCoveredCoveredCoveredCovered
Calling to confirm a payment before you send it, and a second person approving large onesA must-have for the part of the policy that covers being tricked into sending money, rather than for the policy as a whole.CoveredCoveredCoveredCovered
Changes the price
Two-step login on the accounts that can change everything, and on the backup systemCoveredCoveredCoveredCovered
What share of devices are covered, and whether the software cuts an infected one off the network by itselfCoveredCoveredCoveredCovered
Backups kept apart from the day-to-day network, so one break-in cannot take bothCoveredCoveredCoveredCovered
Someone has actually restored a file from backup and written down that it workedCoveredCoveredCoveredCovered
Email screened before it arrives, and attachments opened somewhere safe firstNot coveredCoveredNot coveredCovered
How fast you install urgent security updates, and how often you hit that targetNot coveredCoveredNot coveredCovered
How many accounts can change anything, and why each one needs toCoveredCoveredCoveredCovered
On the form
Software the maker has stopped fixing, still in useCoveredCoveredCoveredCovered
Staff training, and test phishing emails sent to see who clicksNot coveredCoveredNot coveredCovered
A written plan for a break-in, rehearsed once a yearNot coveredNot coveredCoveredCovered
Checking the outside companies that touch your client dataNot coveredNot coveredCoveredCovered

These are questions from real insurance applications. Where a plan does not cover something, we say so here rather than let you find out on the form.

The one that matters most for an advisory firm is the wire procedure. Every plan includes a written wire verification procedure: call-backs to a number agreed at the time of onboarding rather than a number supplied in the request, and dual control on transfers above ten thousand dollars, approved by someone other than the person who initiated it, on a different device.

What we do, and how often

Every month

  • Control drift reviewProduces: A triaged, recorded list of what stopped reporting and what was escalated
  • Backup verificationProduces: Confirmation that every server, laptop and mailbox is backed up
  • Evidence packProduces: A dated snapshot of every device and user, filed to your archive

Every quarter

  • Restore testProduces: A written result for a real file set restored from backup
  • Patch compliance reportProduces: Performance against a stated target, with the rolling twelve-month rate
  • Access exception reviewProduces: A record of new devices, bypass codes and administrator accounts
  • Report to your chief compliance officerProduces: One page: what changed, what lapsed, what needs a decision

Every year

  • Privileged account reviewProduces: Every administrator account listed with a written reason it still exists
  • End-of-life inventoryProduces: A written statement of what protects anything the maker no longer supports
  • Insurance evidence packProduces: The control sections of your application or renewal, supported by dated records

The compliance program

Included in Monitor + Comply and Complete. This is the part that produces the documents themselves, not just the evidence that controls are running. The incident response program is written to the rule with its three parts kept separate and visible: assessment, containment and control, and notification. The notification decision file is a template for the decision, with the eight required contents pre-tested, and a filing structure that records the reason you decided not to notify where that was the outcome. The service provider program is the inventory, the due diligence file, the 72-hour notification expectation put to each provider in writing, and a monitoring cadence, because the rule asks for oversight as an activity rather than a policy on a shelf.

An annual tabletop exercise and a written after-action report are also included. That one is not required by the rule text, and we say so plainly rather than imply otherwise. It is what turns a written plan into a tested one. The records schedule maps all six categories to the recordkeeping rule, and the exam readiness pack is assembled directly against the SEC’s published document request, so the answer to “please provide” is a folder rather than a fire drill.

An honest boundary. We prepare these documents for your compliance officer and your counsel to review, revise and adopt. We are not your lawyers and we do not give legal or regulatory advice. Where a judgment call belongs to your firm, we set it up so the decision is easy to make and easy to evidence, and then you make it.

What this means for you

What is included, what is not, and what stays yours

We do

  • Configure, monitor and maintain every product in your plan
  • The monthly, quarterly and annual work in the service calendar above
  • Deliver a dated evidence pack to your archive every month
  • Support one insurance application or renewal each year
  • Escalate anything we find, with a written record
  • On Managed IT and Complete: helpdesk, new starters and leavers, device setup, and two hours of remediation and hardening every month

We do not

  • Helpdesk on the two Monitor plans, which stays with your own IT
  • Incident response and forensics inside the monthly fee, which is billed separately
  • Buying or owning your hardware, software licenses, phones or cabling
  • Legal, regulatory or insurance advice
  • Writing or sending your breach notifications
  • Acting as, or standing in for, your chief compliance officer
  • Work on site or outside business hours, except by arrangement

You do

  • Name a primary and a backup technical contact, and tell us if that changes
  • Respond within four business hours when we escalate something urgent
  • Adopt the policies we prepare, with your counsel
  • Own the accuracy of anything you file with a regulator or an insurer
  • Tell us before you add people, offices, systems or vendors
  • Keep your own IT resource in place on the Monitor plans, or tell us if that ends

Written plainly here so nothing is a surprise in month three. The agreement carries the same boundaries in full.

If the worst happens

Most providers hand you off at the worst possible moment. We do not. The people who protect your firm are the same people who examine the devices and accounts and write the report, and stand behind it if it is ever challenged.

Hour one to day ten

  1. Hour one, contain and preserve. We take your call and stop the bleeding. We capture evidence to forensic standard from the first minute, with chain of custody intact. Most of what is lost in a breach is lost in the first few hours, by well-meaning people rebooting machines.
  2. Days one to five, examine. Our examiners work the images and the logs. What got in, how, what it touched, what left the building, and whether client information was actually reached. Those are the questions your notification decision turns on.
  3. By day ten, report. A written forensic report your compliance officer, your counsel, your insurer and a regulator can all read. Written to be defensible, because we write reports that go to court.
  4. Then notify, rebuild, and if needed testify. The report feeds your 30-day notification decision and the record behind it. We rebuild the environment. If the matter is litigated, our examiners give evidence.

Who does the work

A digital forensics practice. Quinn holds a degree in cybersecurity from SANS Technology Institute and 9 active GIAC certifications across GIAC, including incident handling, intrusion analysis and mobile forensics. That credential mix is what supports qualification as an expert witness under the Daubert and Frye standards.

Two things we put in writing. Where privilege matters, and in a serious incident it usually does, we take our instructions through your lawyer rather than direct. That is the arrangement that gives the report the best chance of staying protected, and we set it up at onboarding so it is ready rather than improvised at 2am. And you can always get a second opinion: you may bring in an independent examiner at any point, for any reason, and we will hand over the images, the logs and our working papers to help them.

Chain of custody is the unbroken written record of who held a piece of evidence and when, which is what stops the other side arguing it was altered. Privilege means the other side in a lawsuit cannot demand to see a document.

A great deal of what we are called for is not a hacker at all. A departing employee who copied the client file to a personal drive. A dispute where the record sits in a mailbox or on a phone. A preservation request that needs a defensible extraction. And the most common loss an advisory firm actually suffers, a wire that went to the wrong account after a convincing email. Tracing where the money went is a different discipline from reading a firewall log, and it is what this firm was built to do.

The first ninety days

  1. Days 1 to 10, discovery and paperwork. We inventory every device, user, mailbox and vendor. You get our own due diligence pack: our controls, our insurance, our subprocessors, our incident plan. Reg S-P at 17 CFR 248.30(a)(5) requires you to have written policies for vetting and monitoring your service providers, so we hand ours over before you ask.
  2. Days 10 to 30, deployment. Backup, endpoint protection and monitoring on every device. Multi-factor login across all five access points. First backup taken and first restore proven, not assumed.
  3. Days 30 to 60, the program. On the Comply plans: incident response program drafted, notification templates tested, vendor inventory built and the 72-hour expectation put to each provider in writing. Your counsel reviews. Your compliance officer adopts.
  4. Days 60 to 90, proof and rehearsal. First full evidence pack delivered. First tabletop exercise run, with the written after-action report. If you are placing insurance, we assemble the control evidence for your broker.

What we need from you to start: a named technical contact and a backup, administrative access to your Microsoft or Google tenant, a list of every vendor that touches client information, your current policies however incomplete, your penetration test report if you have one, and your counsel’s name so the program is prepared under their review.

On the penetration test. If you have had one, the findings are a separate project scoped finding by finding against an agreed cap. We do not fold open-ended remediation into a fixed monthly fee, because that is how a fixed fee stops being fixed.

Rates, growth and the small print

Project and hourly rates

Hourly rates, standard and on a plan.
WorkStandardOn a plan
Remediation beyond the included allowance$400/hr$195/hr
Security consulting, assessment and hardening$400/hr$275/hr
Incident response, containment and rebuild$400/hr$275/hr
Forensic examination and written report$400/hr$325/hr
Deposition and trial testimony, four-hour minimum$400/hr$400/hr Same as the standard rate.
Done-for-you device forensicsfrom $3,000from $3,000 Same as the standard rate.
Refundable engagement retainer$5,000Waived

All rates per hour unless stated. There is no surge for nights, weekends or holidays, on either column. Court time is never discounted, because the hour is the same hour whoever is paying for it.

As your firm grows

Additional named user

$35/mo

Additional workstation

$25/mo

Additional server

$70/mo

New user setup

$150

User departure and offboarding

$100

New device deployment

$200

Term

Twelve months, billed monthly, renewing unless either of us gives 60 days' notice.

Your data

Your tenants are yours. On exit we return your records in a usable format within 30 days and certify what we destroyed.

Our duty to you

We are a service provider under the rule. We will tell you within 72 hours of becoming aware of a breach affecting a system holding your customer information.

Insurance

We recommend you carry cyber cover and we supply the control evidence to your broker. We are not licensed in insurance and give no insurance advice.

Growth is reviewed quarterly, effective from the date of the change. Devices count by type, because a server costs several times what a laptop does. Where a vendor sells licenses in blocks, that block is invoiced in full when it is bought.

How an engagement begins

  1. A scoping call. Forty-five minutes. We walk your environment, tell you what an examiner would ask for that you cannot currently produce, and put a fixed number against it. There is no charge and no obligation.
  2. Written scope. Deliverables, timeline and price, approved by you before any work begins.
  3. Discovery, deployment and the program. The ninety days above, with a dated record at every step.

Why this work matters

A firm of ten people carries the same obligations as a firm of a thousand, with none of the staff to meet them. What an examiner and an underwriter both want is not a promise but a dated record, and producing that record every month is the whole of this offering.

Plain terms

What we are, and what we are not

What we are

A digital forensics practice with an AI investigator at the center. Credentialed examiners, documented chain of custody, explainable findings you can verify, and court-admissible reports under FRE 901/902. When field work is needed — backgrounds, locates, physical surveillance — we coordinate with licensed private investigators. Lawful, confidential, on your side.

What we are not

Spyware, stalkerware, or a way to secretly monitor another person. We do not “hack back,” promise guaranteed money recovery, or touch any account or device without its owner's lawful authorization. We decline engagements that ask us to.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Certified Expertise

GIAC

Frequently asked about managed security and compliance

We already have an IT person. Does this replace them?
Not on the Monitor plans. They keep the day to day and we sit above it, watching the controls and producing the record. That is usually the cheapest and least disruptive arrangement. On Managed IT and Complete we do take the day to day, which firms choose when their IT person leaves or when one person is carrying too much.
Can we just buy the software ourselves?
Yes, and the prices are public. The licence cost is not the control, though. Running it is. In practice the firms that contain an incident are the ones with a person actually watching what the software reports, and the ones that avoid an email break-in are the ones that had multi-factor login switched on before it mattered.
Are we going to be fined?
Probably not, and we would rather tell you that than sell you fear. The SEC has never charged a standalone investment adviser under the safeguards rule. The realistic exposure is a deficiency letter at your next examination, and the remediation and disruption that follows it. That is what these plans are built for.
What if we get breached and you missed it?
Then the record shows it. Every plan produces a dated monthly account of what was running, what drifted and what we escalated. That record protects you in an examination and it also holds us to account. We would rather be measured than trusted.
Do you work with our existing insurance broker?
Yes, and we prefer to. Your broker places the policy and advises you on it. We supply factual, dated evidence of your control environment so their questions are answered from records. We do not take a commission from any carrier and we do not recommend policies.
How quickly can you start?
Discovery within a week of signature. Full deployment inside thirty days for a firm of this size. The compliance program takes another thirty, because your counsel needs time to review it properly.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management