Active Incident? 24/7 Response →

Managed Security & Compliance

Reg S-P Compliance for a Small Broker-Dealer

The three written programs a small FINRA member firm must produce on request, and a monthly service that keeps them current. From a digital forensics practice.

Three rules, three documents, one examiner

Three different rulebooks each require a firm to have written something down. They overlap, they are not the same document, and an examiner can ask for any of them.

Most of what is published about Regulation S-P is written for investment advisers, and the citations do not carry across. The recordkeeping period is the clearest case. For a broker-dealer it lives in a different rule, with a different number of years, and the adviser figure is the one that gets repeated. This page uses the broker-dealer citations throughout.

Plans start at $995 per month. The plan built for the three obligations below is Monitor + Comply, at $1,950 per month. Every plan price on this page is stated at the same size: up to 10 named users and 12 protected devices, on a 12 month term, billed either monthly or as a year paid in advance. This page is part of our managed security and compliance offering for small regulated firms.

A boundary, stated here rather than in the footer. Everything below describes what published rules say. It is information about the law, not legal advice, and it is not a substitute for advice from your own counsel on your own firm’s facts. We prepare documents for your chief compliance officer and your counsel to review and adopt. We are not your lawyers.

Regulation S-P: the safeguards and the incident response program

Regulation S-P is the SEC rule that says a firm must protect its customers’ information and must have a written plan for what happens when someone gets in. 17 CFR 248.1 names brokers and dealers first, so it reaches a FINRA member firm directly. Six obligations sit in it.

  1. Written safeguards policies and procedures, addressing administrative, technical and physical safeguards, at 17 CFR 248.30(a)(1) and (a)(2). The examiner asks for the document.
  2. An incident response program at 248.30(a)(3), reasonably designed to detect, respond to and recover from unauthorized access to or use of customer information, including customer notification procedures. The rule sets it out in three parts and a deficiency letter picks at them separately: assessment of the nature and scope of the incident, containment and control, and notification unless a reasonable investigation determines that misuse is not reasonably likely.
  3. Customer notification at 248.30(a)(4), as soon as practicable and no later than 30 days after becoming aware, with eight required contents listed at (a)(4)(iv)(A) through (H). What the examiner asks for is a sent notice, or the recorded reason there was not one.
  4. Service provider oversight at 248.30(a)(5), through due diligence and monitoring, and reasonably designed to ensure a provider notifies the firm no later than 72 hours after becoming aware of a breach. The examiner asks for the vendor inventory and the due diligence file. This is the one obligation on the list a compliance officer cannot satisfy without the vendor’s cooperation, so our own 72-hour commitment is written into the terms further down this page and is yours to file.
  5. Recordkeeping, six categories, at 17 CFR 240.17a-4(e)(14). The examiner asks for the folder. The period is covered on its own below, because it is the one people get wrong.
  6. Disposal at 248.30(b), written policies, covering both consumer and customer information.

The notification presumption. The SEC’s own framing is that the amendments reflect a presumption of notification. A firm may determine that sensitive customer information was not accessed and that notice is not required, but only after a reasonable investigation, and it has to keep the reasoning. Silence with no paper behind it is the failure the rule is written to catch. The investigation window sits inside the 30 days rather than on top of it.

The sentence in obligation 4 that catches people out. Under 248.30(a)(5)(iii), notwithstanding the firm’s use of a service provider, the obligation to ensure affected individuals are notified stays with the firm. Outsourcing the system does not outsource the duty. Note also that the written-contract requirement in the proposal was dropped at adoption, so the final rule asks for policies and procedures rather than for contract terms. Anyone telling you the rule requires a particular clause in a vendor contract is describing the proposal rather than the rule.

Three years, and this is the one the market gets wrong. For a broker-dealer, the Regulation S-P recordkeeping amendment landed at 17 CFR 240.17a-4(e)(14). Paragraph (e) opens: every member, broker or dealer subject to 240.17a-3 must maintain and preserve in an easily accessible place. All six of (e)(14)’s subparagraphs run three years. The three policy sets and any service provider agreement run until three years after the firm stops using them. The incident documentation and the notification decision file run three years from the date the record was made.

Five years is 17 CFR 275.204-2(e), which is the investment adviser rule, paired with the adviser recordkeeping category at 275.204-2(a)(25). Six years is the registered fund number. If your firm is dually registered as an SEC investment adviser, both clocks run: the adviser side of the house is five years, the first two readily accessible. That is the most common shape of a small FINRA member firm, and it is worth writing down which record sits under which rule before an examiner asks.

Regulation S-ID: the identity theft prevention program

Regulation S-ID is the identity theft red flags rule. The core obligation at 17 CFR 248.201(d)(1) reads that each financial institution or creditor that offers or maintains one or more covered accounts must develop and implement a written Identity Theft Prevention Program designed to detect, prevent and mitigate identity theft in connection with the opening of a covered account or any existing covered account. Paragraph 248.201(a) reaches brokers and dealers registered or required to register under the Exchange Act, in the same breath as registered investment companies and registered advisers.

The qualifier. That program obligation binds a firm that offers or maintains one or more covered accounts. A covered account is one offered or maintained primarily for personal, family or household purposes that involves or is designed to permit multiple payments or transactions, plus any other account carrying a reasonably foreseeable risk of identity theft. A retail brokerage account is the paradigm case. A firm doing only institutional business may hold none.

And the duty that does not depend on the answer. 248.201(c) requires each financial institution or creditor to periodically determine whether it offers or maintains covered accounts. That one runs whether or not the firm has any, and the determination is a risk assessment rather than a formality. The rule fixes no interval. In November 2025 the SEC charged a broker-dealer partly for never having conducted one, faulting the firm for not weighing the methods it provides to open its accounts, the methods it provides to access them, and its previous experiences with identity theft. The same order records that the firm’s program provided no policies or procedures for identifying covered accounts at all. A firm that concludes it has no covered accounts still owes the determination and the record of it.

What the program has to include, at 248.201(d)(2)(i) through (iv): reasonable policies and procedures to identify relevant red flags and incorporate them into the program, to detect the red flags it has incorporated, to respond appropriately to detected red flags, and to update the program periodically as risks change.

Administration, at 248.201(e), which is the part small firms skip. The initial written program is approved by the board or an appropriate committee. The board, a committee, or a designated senior management employee is involved in oversight, development, implementation and administration. Staff are trained as necessary. And there is appropriate and effective oversight of service provider arrangements. That last item and obligation 4 of Regulation S-P are the same work looked at from two directions, so one vendor inventory answers both.

FINRA Rule 4370: the business continuity plan

FINRA Rule 4370 is the rule that requires a written plan for keeping the firm running through a disruption. Its full title is Business Continuity Plans and Emergency Contact Information. Paragraph (a) requires each member to create and maintain a written business continuity plan identifying procedures relating to an emergency or significant business disruption. The plan is reviewed annually and modified as the firm’s operations, structure, business or location change.

Paragraph (c) lists ten elements the plan must address, and the first named element is data back-up and recovery, hard copy and electronic. Read the rule’s own lead-in alongside that list, because it changes what the list means. The elements are flexible and may be tailored to the size and needs of a member, and they are addressed to the extent applicable and necessary, with a member that excludes one required to document the rationale. List position is not regulatory priority. The remaining nine, in the order the rule prints them: all mission critical systems; financial and operational assessments; alternate communications between customers and the member; alternate communications between the member and its employees; alternate physical location of employees; critical business constituent, bank and counter-party impact; regulatory reporting; communications with regulators; and how the member will assure customers’ prompt access to their funds and securities.

An honest note. Rule 4370 does not say to hire a managed service provider, and it does not say backup must be outsourced. It requires the plan to address backup and recovery. What is true and worth saying is narrower: the rule asks for a plan that is real rather than filed, and a quarterly documented restore test is the evidence of the difference. Ours is in the service calendar below.

The three are not three copies of one document. Regulation S-P is about protecting customer information and what happens when it leaks. Regulation S-ID is about spotting someone pretending to be your customer. Rule 4370 is about staying in business when the building or the systems go down. They share evidence, and the vendor inventory, the backup record and the annual review each answer to more than one of them. A firm that builds them separately builds the same file three times.

Small at FINRA is not small at the SEC

Two different definitions of a small firm sit on top of each other here, they measure different things, and they get conflated constantly. Never let a sentence about your firm use “small firm” without saying whose definition it means.

FINRA’s test is headcount. A small firm is 1 to 150, mid-size is 151 to 499, and large is 500 or more. FINRA’s firms-by-size statistics gloss the band as registered representatives. The By-Laws themselves say registered persons, which is broader and takes in registered principals, so the two are not interchangeable.

The size of the population. FINRA’s 2026 Industry Snapshot, published June 2026 for year-end 2025, reports 3,184 member firms: 2,832 small, 197 mid-size and 155 large. So roughly 89 percent of the membership is small, and the count is falling, with 163 firms leaving and 98 joining, all at the small tier.

The SEC’s test is money. Exchange Act Rule 0-10(c) makes a broker or dealer a small business only if it had total capital, meaning net worth plus subordinated liabilities, of less than $500,000 at the relevant date, and is not affiliated with any non-natural person that is not itself small. Note it is total capital rather than net capital. Those are different figures and the distinction is the whole point.

Why it mattered. For Regulation S-P compliance-date purposes, larger entities had to comply from 3 December 2025 and everyone else from 3 June 2026. Which group a broker-dealer fell into turned on 0-10(c), not on its FINRA tier. Both dates have now passed, so the rule is in force either way and there is no countdown left to sell.

We are not going to tell you which tier your firm was in. There is no published distribution of FINRA member firms banded by total capital, and any page that asserts one is guessing. The answer for your firm is on your own FOCUS report, which is where total capital already lives, so it is a question you can settle in about a minute without us.

FINRA gives you two of these free, and where that stops

FINRA publishes a free Small Firm Cybersecurity Checklist and a free Small Firm Business Continuity Plan Template, the latter revised in April 2026. There is a free anti-money laundering template and a compliance calendar in the same Compliance Tools section. They are genuinely useful, they are current, and a firm with nothing written down should start there. We would rather say that plainly than pretend they do not exist.

What FINRA says about its own tools is the part worth reading. The obligation is not one-size-fits-all, the firm has to tailor the tool to its own size and needs, and the checklist says in terms that it does not guarantee compliance. The regulator is telling you a template is a starting point. That is a stronger statement coming from FINRA than it would be coming from us.

And then there is the thing a template structurally cannot do. A completed checklist records an intention on the day it was completed. What an examiner asks for is evidence that the control was running on the day in question, month after month, and that when it stopped running somebody noticed and wrote down what they did about it. No template produces that, because a template is a document and this is a record. The service calendar below is where we show what the record looks like.

What failure has actually looked like

The most recent order is the most on-point one. On 25 November 2025 the SEC issued an order against M Holdings Securities, Inc., a dually registered broker-dealer, with a $325,000 penalty, charged under both Rule 30(a) of Regulation S-P and Rule 201 of Regulation S-ID. Two of the three obligations on this page, one broker-dealer respondent.

Its facts are the argument. The firm had adopted an information security policy requiring its member firms to put controls in place across seventeen categories, among them multi-factor authentication, written incident response policies and annual security awareness training. It then collected the compliance data, saw the gaps, and did nothing. The order finds it did not impose any consequences on member firms that did not comply with the policy and, though aware of ongoing self-reported failures, did not revise its policies and procedures. Written one thing, ran another.

Then the 2021 sweep, as history rather than as the headline. On 30 August 2021 the SEC sanctioned eight firms in three actions, $750,000 in total, all under Rule 30(a). The Cetera entities paid $300,000 after cloud email accounts of over 60 personnel were taken over between November 2017 and June 2020, exposing the personal information of at least 4,388 customers and clients. Cambridge paid $250,000 after the accounts of over 121 representatives were taken over between January 2018 and July 2021, exposing at least 2,177. KMS paid $200,000 after the accounts of 15 financial advisers or their assistants were taken over between September 2018 and December 2019, exposing approximately 4,900.

Three things about that release are worth stating plainly. The charge in each case was the written policy rather than the break-in. In the SEC’s own words, it is not enough to write a policy requiring enhanced security measures if those requirements are not implemented, or are only partly implemented, especially in the face of known attacks. At Cambridge the firm discovered the first takeover in January 2018 and did not adopt firm-wide enhanced measures until 2021. And two of the Cetera entities picked up a second charge over the notifications themselves, for language suggesting the notices went out sooner than they had, which is a direct argument for building the notification decision file before it is needed rather than drafting it at 2am.

What we are not going to sell you is a fine. There has been no enforcement under the amended rule. No action has charged the incident response program or the 30-day notification requirement. The realistic exposure for a firm of this size is an examination and a deficiency letter, and Regulation S-P has its own named section in the Division of Examinations’ fiscal-year 2026 priorities, published 17 November 2025. The Division says it will assess compliance with Regulations S-ID and S-P, as applicable, and that examinations will focus on firms’ policies and procedures, internal controls, oversight of third-party vendors, and governance practices. It also says that after the applicable compliance dates it will examine whether firms have developed, implemented and maintained policies and procedures in accordance with the rule’s new provisions.

What an examination opens with. SEC staff published a Compliance Outreach deck walking a mock examination of a $250 million, seven-employee, single-office investment adviser using a managed service provider. It is an adviser walkthrough rather than a broker-dealer one, and we are not going to pretend otherwise. The opening document request is the useful part, because it is the same list either way: the incident response plan; the policies documenting the program to detect, respond to and recover from unauthorized access, including customer notification procedures; a listing of the staff and vendors responsible for incident response; a listing of all detection and monitoring tools; the monitoring evidence itself; and, if an incident occurred, documentation that the program’s steps were followed. The interviews target the chief compliance officer, the CIO or CTO, and the outsourced IT provider. The three common observations staff recorded are that policies and procedures do not appear to be reasonably designed, do not appear to be enforced, or do not appear to exist.

The four plans

What each plan includes, feature by feature.
What you get
Monitor
$995 per month
Up to 10 named users and 12 protected devices
You have IT covered and your compliance paperwork is current.
Managed IT
$1,595 per month
Up to 10 named users and 12 protected devices
You want us to be your IT department, and your paperwork is current.
Monitor + Comply
$1,950 per month
Up to 10 named users and 12 protected devices
Recommended
You have IT covered but need the compliance program built and kept.
Complete
$2,495 per month
Up to 10 named users and 12 protected devices
You want one firm accountable for all of it.
Protection
Backup of every server, laptop and mailboxIncludedIncludedIncludedIncluded
Managed detection and response on every deviceIncludedIncludedIncludedIncluded
Multi-factor authentication across all five access pointsIncludedIncludedIncludedIncluded
Email filtering and security awareness trainingNot includedIncludedNot includedIncluded
Patch management to a stated targetNot includedIncludedNot includedIncluded
Proof
Dated monthly evidence pack for your recordsIncludedIncludedIncludedIncluded
Quarterly restore test, documentedIncludedIncludedIncludedIncluded
Quarterly privileged access and patch compliance reportIncludedIncludedIncludedIncluded
Cyber insurance application support, from recordsIncludedIncludedIncludedIncluded
Day-to-day IT
Helpdesk for your staffNot includedIncludedNot includedIncluded
New starters, leavers and device setupNot includedIncludedNot includedIncluded
Remediation and hardening hours included each monthNot included2 hrsNot included2 hrs
Written compliance program
Written incident response program, reviewed annuallyNot includedNot includedIncludedIncluded
Customer notification decision file, including reasons not to notifyNot includedNot includedIncludedIncluded
Vendor inventory, due diligence and 72-hour notice termsNot includedNot includedIncludedIncluded
Annual tabletop exercise with written after-action reportNot includedNot includedIncludedIncluded
Records schedule and examiner-ready document packNot includedNot includedIncludedIncluded

Getting started: deployment and a first verified restore is a one time $9,500. The compliance program build is a one time $12,500, required once on the two plans that include it.

Monitor + Comply is the plan built for the three obligations above, because the rows in the written compliance program group are the ones that produce the Regulation S-P and Regulation S-ID documents rather than only the evidence that controls are running.

Your insurance application, control by control

Must have

One carrier's own bind-condition sheet marks controls of this kind as required before it will bind coverage. These are the ones that stop a deal.

Changes the price

You can get a policy without it, but it costs more, or you get lower limits.

On the form

They ask, and the answer goes on file, but on its own it rarely stops anything.

What a cyber insurance application asks about, and which plan answers it.
What the application asksMonitorManaged ITMonitor + ComplyComplete
Must have
Two-step login (MFA) on emailCoveredCoveredCoveredCovered
Two-step login on any way in from outside the officeCoveredCoveredCoveredCovered
Security software on every laptop and serverCoveredCoveredCoveredCovered
Backups an attacker cannot reach or overwrite, and proven to restoreCoveredCoveredCoveredCovered
Calling to confirm a payment before you send it, and a second person approving large onesA must-have for the part of the policy that covers being tricked into sending money, rather than for the policy as a whole.CoveredCoveredCoveredCovered
Changes the price
Two-step login on the accounts that can change everything, and on the backup systemCoveredCoveredCoveredCovered
What share of devices are covered, and whether the software cuts an infected one off the network by itselfCoveredCoveredCoveredCovered
Backups kept apart from the day-to-day network, so one break-in cannot take bothCoveredCoveredCoveredCovered
Someone has actually restored a file from backup and written down that it workedCoveredCoveredCoveredCovered
Email screened before it arrives, and attachments opened somewhere safe firstNot coveredCoveredNot coveredCovered
How fast you install urgent security updates, and how often you hit that targetNot coveredCoveredNot coveredCovered
How many accounts can change anything, and why each one needs toCoveredCoveredCoveredCovered
On the form
Software the maker has stopped fixing, still in useCoveredCoveredCoveredCovered
Staff training, and test phishing emails sent to see who clicksNot coveredCoveredNot coveredCovered
A written plan for a break-in, rehearsed once a yearNot coveredNot coveredCoveredCovered
Checking the outside companies that touch your customer dataNot coveredNot coveredCoveredCovered

These are questions from real insurance applications. Where a plan does not cover something, we say so here rather than let you find out on the form.

The one that matters most for a broker-dealer is the wire procedure. Every plan includes a written wire verification procedure: call-backs to a number agreed at onboarding rather than a number supplied in the request, and dual control on transfers above ten thousand dollars, approved by someone other than the person who initiated it, on a different device.

What we do, and how often

Every month

  • Control drift reviewProduces: A triaged, recorded list of what stopped reporting and what was escalated
  • Backup verificationProduces: Confirmation that every server, laptop and mailbox is backed up
  • Evidence packProduces: A dated snapshot of every device and user, filed to your archive

Every quarter

  • Restore testProduces: A written result for a real file set restored from backup
  • Patch compliance reportProduces: Performance against a stated target, with the rolling twelve-month rate
  • Access exception reviewProduces: A record of new devices, bypass codes and administrator accounts
  • Report to your chief compliance officerProduces: One page: what changed, what lapsed, what needs a decision

Every year

  • Privileged account reviewProduces: Every administrator account listed with a written reason it still exists
  • Business continuity plan reviewProduces: A dated record that the plan was reviewed and what was changed
  • End-of-life inventoryProduces: A written statement of what protects anything the maker no longer supports
  • Insurance evidence packProduces: The control sections of your application or renewal, supported by dated records

The compliance program

Included in Monitor + Comply and Complete. This is the part that produces the documents themselves rather than only the evidence that controls are running. The incident response program is written to the rule with its three parts kept separate and visible: assessment, containment and control, and notification. The customer notification decision file is a template for the decision, with the eight required contents pre-tested, and a filing structure that records the reason you decided not to notify where that was the outcome. The service provider program is the inventory, the due diligence file, the 72-hour notification expectation put to each provider in writing, and a monitoring cadence, because the rule asks for oversight as an activity rather than a policy on a shelf.

On the identity theft side, the same build produces the written program, the red flags your firm has actually incorporated with the reasoning behind them, and the periodic determination under 248.201(c) with its record, which is the deficiency the November 2025 order turned on. The business continuity plan is reviewed annually against Rule 4370’s ten elements, with a written rationale where an element is not applicable, because the rule asks for that rationale by name.

An annual tabletop exercise and a written after-action report are also included. That one is not required by the rule text, and we say so plainly rather than imply otherwise. It is what turns a written plan into a tested one. The records schedule maps all six Regulation S-P categories to 17a-4(e)(14) and its three-year clocks, and the examination readiness pack is assembled against the published document request, so the answer to “please provide” is a folder rather than a fire drill.

An honest boundary, repeated because it matters more here than anywhere else on this page. We prepare these documents for your chief compliance officer and your counsel to review, revise and adopt. We are not your lawyers and we do not give legal or regulatory advice. Where a judgment call belongs to your firm, we set it up so the decision is easy to make and easy to evidence, and then you make it.

What this means for you

What is included, what is not, and what stays yours

We do

  • Configure, monitor and maintain every product in your plan
  • The monthly, quarterly and annual work in the service calendar above
  • Deliver a dated evidence pack to your archive every month
  • Support one insurance application or renewal each year
  • Escalate anything we find, with a written record
  • On Managed IT and Complete: helpdesk, new starters and leavers, device setup, and two hours of remediation and hardening every month

We do not

  • Helpdesk on the two Monitor plans, which stays with your own IT
  • Incident response and forensics inside the monthly fee, which is billed separately
  • Buying or owning your hardware, software licenses, phones or cabling
  • Legal, regulatory or insurance advice
  • Writing or sending your customer notifications
  • Acting as, or standing in for, your chief compliance officer
  • Filing anything with FINRA or the SEC on your behalf
  • Work on site or outside business hours, except by arrangement

You do

  • Name a primary and a backup technical contact, and tell us if that changes
  • Respond within four business hours when we escalate something urgent
  • Adopt the policies we prepare, with your counsel and your chief compliance officer
  • Own the accuracy of anything you file with a regulator or an insurer
  • Tell us before you add people, offices, systems or vendors
  • Keep your own IT resource in place on the Monitor plans, or tell us if that ends

Written plainly here so nothing is a surprise in month three. The agreement carries the same boundaries in full.

If the worst happens

Two things we put in writing, and the first one comes before the sales pitch. Where privilege matters, and in a serious incident it usually does, we take our instructions through your lawyer rather than direct. That is the arrangement that gives the report the best chance of staying protected, and we set it up at onboarding so it is ready rather than improvised at 2am. The forensic work is a standalone engagement kept separate from the ordinary-course IT services, which is the structure that protects privilege, and it is priced separately on the rate card below for the same reason. And you can always get a second opinion: you may bring in an independent examiner at any point, for any reason, and we will hand over the images, the logs and our working papers to help them.

The advantage of buying both from one practice is not a bundle. It is that the people who already know your environment can be retained by your counsel and start work the same day, with no discovery phase and no handover. Privilege means the other side in a lawsuit cannot demand to see a document. Chain of custody is the unbroken written record of who held a piece of evidence and when, which is what stops the other side arguing it was altered.

Hour one to day ten

  1. Hour one, contain and preserve. We take your call and stop the bleeding. We capture evidence to forensic standard from the first minute, with chain of custody intact. Most of what is lost in a breach is lost in the first few hours, by well-meaning people rebooting machines.
  2. Days one to five, examine. Our examiners work the images and the logs. What got in, how, what it touched, what left the building, and whether customer information was actually reached. Those are the questions your notification decision turns on, and the rule asks you to keep the reasoning either way.
  3. By day ten, report. A written forensic report your compliance officer, your counsel, your insurer and a regulator can all read. Written to be defensible, because we write reports that go to court.
  4. Then notify, rebuild, and if needed testify. The report feeds your 30-day notification decision and the record behind it. We rebuild the environment. If the matter is litigated, our examiners give evidence.

Who does the work

A digital forensics practice. Quinn holds a degree in cybersecurity from SANS Technology Institute and 9 active GIAC certifications across GIAC, including incident handling, intrusion analysis and mobile forensics. That credential mix is what supports qualification as an expert witness under the Daubert and Frye standards. It is evidence about the examination work, which is what it actually confers.

A great deal of what we are called for is not a hacker at all. A departing registered representative who copied the book to a personal drive. A dispute where the record sits in a mailbox or on a phone. A preservation request that needs a defensible extraction. And the most common loss a small firm actually suffers, a wire that went to the wrong account after a convincing email. Tracing where the money went is a different discipline from reading a firewall log, and it is what this firm was built to do.

The first ninety days

  1. Days 1 to 10, discovery and paperwork. We inventory every device, user, mailbox and vendor. You get our own due diligence pack: our controls, our insurance, our subprocessors, our incident plan. Regulation S-P at 17 CFR 248.30(a)(5) requires written policies for vetting and monitoring service providers, so we hand ours over before you ask.
  2. Days 10 to 30, deployment. Backup, endpoint protection and monitoring on every device. Multi-factor login across all five access points. First backup taken and first restore proven, not assumed.
  3. Days 30 to 60, the program. On the Comply plans: incident response program drafted, notification templates tested, the identity theft program and its periodic determination documented, the business continuity plan reviewed against Rule 4370, and the vendor inventory built with the 72-hour expectation put to each provider in writing. Your counsel reviews. Your chief compliance officer adopts.
  4. Days 60 to 90, proof and rehearsal. First full evidence pack delivered. First tabletop exercise run, with the written after-action report. If you are placing insurance, we assemble the control evidence for your broker.

What we need from you to start: a named technical contact and a backup, administrative access to your Microsoft or Google tenant, a list of every vendor that touches customer information, your current policies however incomplete, your penetration test report if you have one, and your counsel’s name so the program is prepared under their review.

Rates, growth and the small print

Project and hourly rates

Hourly rates, standard and on a plan.
WorkStandardOn a plan
Remediation beyond the included allowance$400/hr$195/hr
Security consulting, assessment and hardening$400/hr$275/hr
Incident response, containment and rebuild$400/hr$275/hr
Forensic examination and written report$400/hr$325/hr
Deposition and trial testimony, four-hour minimum$400/hr$400/hr Same as the standard rate.
Done-for-you device forensicsfrom $2,000from $2,000 Same as the standard rate.
Refundable engagement retainer$5,000Waived

All rates per hour unless stated. There is no surge for nights, weekends or holidays, on either column. Court time is never discounted, because the hour is the same hour whoever is paying for it.

As your firm grows

Additional named user

$35/mo

Additional workstation

$25/mo

Additional server

$70/mo

New user setup

$150

User departure and offboarding

$100

New device deployment

$200

Term

Twelve months, billed either monthly or as a year paid in advance, renewing unless either of us gives 60 days' notice.

Your data

Your tenants are yours. On exit we return your records in a usable format within 30 days and certify what we destroyed.

Our duty to you

We are a service provider under the rule. We will tell you within 72 hours of becoming aware of a breach affecting a system holding your customer information.

Insurance

We recommend you carry cyber cover and we supply the control evidence to your broker. We are not licensed in insurance and give no insurance advice.

The “our duty to you” term above is the 72-hour service provider notice, and it pairs with obligation 4 near the top of this page. It is a written commitment from a service provider, which is the form the SEC accepted when it declined to mandate a contract clause, so it is yours to keep in your due diligence file.

Growth is reviewed quarterly, effective from the date of the change. Devices count by type, because a server costs several times what a laptop does. Where a vendor sells licenses in blocks, that block is invoiced in full when it is bought.

How an engagement begins

  1. A scoping call. Forty-five minutes. We walk your environment, tell you what an examiner would ask for that you cannot currently produce, and put a fixed number against it. There is no charge and no obligation.
  2. Written scope. Deliverables, timeline and price, approved by you before any work begins.
  3. Discovery, deployment and the program. The ninety days above, with a dated record at every step.

Why this work matters

A firm of ten people carries the same three written obligations as a firm of a thousand, with none of the staff to meet them. What an examiner wants is not a promise but a dated record, and producing that record every month is the whole of this offering.

Plain terms

What we are, and what we are not

What we are

A private investigation agency in the making, with full digital forensics included. SleuthX is not yet a licensed private investigation agency; licensure is in progress. Credentialed examiners, documented chain of custody, explainable findings you can verify, and court-admissible reports under FRE 901/902. Where a matter needs field work today, whether backgrounds, locates or physical surveillance, we coordinate with licensed private investigators. Lawful, confidential, on your side.

What we are not

Spyware, stalkerware, or a way to secretly monitor another person. We do not “hack back,” promise guaranteed money recovery, or touch any account or device without its owner's lawful authorization. We decline engagements that ask us to.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Certified Expertise

GIAC

Frequently asked about Reg S-P compliance for broker-dealers

We are a FINRA small firm. Didn't we get the later compliance date?
Not necessarily, and the two tests get conflated constantly. FINRA's small-firm test is 150 or fewer registered representatives. The SEC's test, for Regulation S-P compliance-date purposes, is total capital under $500,000 under Exchange Act Rule 0-10(c), and it is total capital rather than net capital. Those measure different things, so your FINRA tier did not decide your date. Your own FOCUS report answers it in about a minute, because total capital already lives there. Both dates have now passed, so the practical question is not which one applied to you but whether the documents exist.
FINRA gives us a free checklist and a free BCP template. Why would we pay for this?
Start with them. They are good, they are current, and if your firm has nothing written down they are the fastest way to have something. What FINRA says about them is the part worth reading: the obligation is not one-size-fits-all, the tool has to be tailored to your firm, and the checklist does not guarantee compliance. And a completed checklist records an intention. What an examiner asks for is evidence that the control was actually running on the day in question, which is the part no template produces.
We have an outsourced IT provider already. Isn't this their job?
Some of it. What the rules ask for that an IT contract usually does not produce is the written program, the vendor file, the dated evidence, and the record of the decisions you did not make. The mock examination SEC staff published interviews the outsourced IT provider directly, so your provider will be in the room either way. The question is whether they arrive with records.
Are we going to be fined?
Probably not, and we would rather tell you that than sell you fear. No case has yet been brought under the amended safeguards rule. Cases have been brought under the rule as it stood before. In September 2022 Morgan Stanley settled safeguards and disposal charges, and in November 2025 the SEC charged M Holdings Securities, a dually registered broker-dealer, under both the safeguards rule and the identity theft rule. Each of those turned on the same thing, a written policy the firm did not actually run. The realistic exposure for a firm your size is a deficiency letter at your next examination and the remediation that follows it. That is what these plans are built for.
How long do we have to keep the Regulation S-P records?
Three years, under Rule 17a-4(e)(14), in an easily accessible place. The policy sets run three years from when you stop using them. The incident documentation and the notification decision file run three years from the date the record was made. If your firm is also registered as an investment adviser, that side runs five years under the adviser recordkeeping rule, the first two readily accessible. Six years is the registered fund number and it gets quoted at broker-dealers constantly.
Does the identity theft rule actually apply to us?
The program obligation applies if you offer or maintain a covered account, which means an account held mainly for personal, family or household purposes that allows multiple payments or transactions. Ordinary retail brokerage accounts are covered. If your firm is purely institutional you may hold none. Either way the rule asks you to check: 248.201(c) requires a firm to periodically determine whether it offers or maintains covered accounts, weighing how accounts are opened, how they are accessed, and your own history of identity theft. That determination is owed whether the answer turns out to be yes or no, and in November 2025 the SEC charged a broker-dealer partly for never having made it.
What do you actually hand us each month?
A dated evidence pack: what was running, what stopped reporting, what we escalated, and what we did about it. Quarterly, a documented restore test and a patch compliance report. Annually, the privileged account review, the business continuity plan review, and the tabletop exercise with a written after-action report. The point of all of it is that when someone asks you to prove something, the answer is a folder.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management