Three rules, three documents, one examiner
Three different rulebooks each require a firm to have written something down. They overlap, they are not the same document, and an examiner can ask for any of them.
Most of what is published about Regulation S-P is written for investment advisers, and the citations do not carry across. The recordkeeping period is the clearest case. For a broker-dealer it lives in a different rule, with a different number of years, and the adviser figure is the one that gets repeated. This page uses the broker-dealer citations throughout.
Plans start at $995 per month. The plan built for the three obligations below is Monitor + Comply, at $1,950 per month. Every plan price on this page is stated at the same size: up to 10 named users and 12 protected devices, on a 12 month term, billed either monthly or as a year paid in advance. This page is part of our managed security and compliance offering for small regulated firms.
A boundary, stated here rather than in the footer. Everything below describes what published rules say. It is information about the law, not legal advice, and it is not a substitute for advice from your own counsel on your own firm’s facts. We prepare documents for your chief compliance officer and your counsel to review and adopt. We are not your lawyers.
Regulation S-P: the safeguards and the incident response program
Regulation S-P is the SEC rule that says a firm must protect its customers’ information and must have a written plan for what happens when someone gets in. 17 CFR 248.1 names brokers and dealers first, so it reaches a FINRA member firm directly. Six obligations sit in it.
- Written safeguards policies and procedures, addressing administrative, technical and physical safeguards, at 17 CFR 248.30(a)(1) and (a)(2). The examiner asks for the document.
- An incident response program at 248.30(a)(3), reasonably designed to detect, respond to and recover from unauthorized access to or use of customer information, including customer notification procedures. The rule sets it out in three parts and a deficiency letter picks at them separately: assessment of the nature and scope of the incident, containment and control, and notification unless a reasonable investigation determines that misuse is not reasonably likely.
- Customer notification at 248.30(a)(4), as soon as practicable and no later than 30 days after becoming aware, with eight required contents listed at (a)(4)(iv)(A) through (H). What the examiner asks for is a sent notice, or the recorded reason there was not one.
- Service provider oversight at 248.30(a)(5), through due diligence and monitoring, and reasonably designed to ensure a provider notifies the firm no later than 72 hours after becoming aware of a breach. The examiner asks for the vendor inventory and the due diligence file. This is the one obligation on the list a compliance officer cannot satisfy without the vendor’s cooperation, so our own 72-hour commitment is written into the terms further down this page and is yours to file.
- Recordkeeping, six categories, at 17 CFR 240.17a-4(e)(14). The examiner asks for the folder. The period is covered on its own below, because it is the one people get wrong.
- Disposal at 248.30(b), written policies, covering both consumer and customer information.
The notification presumption. The SEC’s own framing is that the amendments reflect a presumption of notification. A firm may determine that sensitive customer information was not accessed and that notice is not required, but only after a reasonable investigation, and it has to keep the reasoning. Silence with no paper behind it is the failure the rule is written to catch. The investigation window sits inside the 30 days rather than on top of it.
The sentence in obligation 4 that catches people out. Under 248.30(a)(5)(iii), notwithstanding the firm’s use of a service provider, the obligation to ensure affected individuals are notified stays with the firm. Outsourcing the system does not outsource the duty. Note also that the written-contract requirement in the proposal was dropped at adoption, so the final rule asks for policies and procedures rather than for contract terms. Anyone telling you the rule requires a particular clause in a vendor contract is describing the proposal rather than the rule.
Three years, and this is the one the market gets wrong. For a broker-dealer, the Regulation S-P recordkeeping amendment landed at 17 CFR 240.17a-4(e)(14). Paragraph (e) opens: every member, broker or dealer subject to 240.17a-3 must maintain and preserve in an easily accessible place. All six of (e)(14)’s subparagraphs run three years. The three policy sets and any service provider agreement run until three years after the firm stops using them. The incident documentation and the notification decision file run three years from the date the record was made.
Five years is 17 CFR 275.204-2(e), which is the investment adviser rule, paired with the adviser recordkeeping category at 275.204-2(a)(25). Six years is the registered fund number. If your firm is dually registered as an SEC investment adviser, both clocks run: the adviser side of the house is five years, the first two readily accessible. That is the most common shape of a small FINRA member firm, and it is worth writing down which record sits under which rule before an examiner asks.
Regulation S-ID: the identity theft prevention program
Regulation S-ID is the identity theft red flags rule. The core obligation at 17 CFR 248.201(d)(1) reads that each financial institution or creditor that offers or maintains one or more covered accounts must develop and implement a written Identity Theft Prevention Program designed to detect, prevent and mitigate identity theft in connection with the opening of a covered account or any existing covered account. Paragraph 248.201(a) reaches brokers and dealers registered or required to register under the Exchange Act, in the same breath as registered investment companies and registered advisers.
The qualifier. That program obligation binds a firm that offers or maintains one or more covered accounts. A covered account is one offered or maintained primarily for personal, family or household purposes that involves or is designed to permit multiple payments or transactions, plus any other account carrying a reasonably foreseeable risk of identity theft. A retail brokerage account is the paradigm case. A firm doing only institutional business may hold none.
And the duty that does not depend on the answer. 248.201(c) requires each financial institution or creditor to periodically determine whether it offers or maintains covered accounts. That one runs whether or not the firm has any, and the determination is a risk assessment rather than a formality. The rule fixes no interval. In November 2025 the SEC charged a broker-dealer partly for never having conducted one, faulting the firm for not weighing the methods it provides to open its accounts, the methods it provides to access them, and its previous experiences with identity theft. The same order records that the firm’s program provided no policies or procedures for identifying covered accounts at all. A firm that concludes it has no covered accounts still owes the determination and the record of it.
What the program has to include, at 248.201(d)(2)(i) through (iv): reasonable policies and procedures to identify relevant red flags and incorporate them into the program, to detect the red flags it has incorporated, to respond appropriately to detected red flags, and to update the program periodically as risks change.
Administration, at 248.201(e), which is the part small firms skip. The initial written program is approved by the board or an appropriate committee. The board, a committee, or a designated senior management employee is involved in oversight, development, implementation and administration. Staff are trained as necessary. And there is appropriate and effective oversight of service provider arrangements. That last item and obligation 4 of Regulation S-P are the same work looked at from two directions, so one vendor inventory answers both.
FINRA Rule 4370: the business continuity plan
FINRA Rule 4370 is the rule that requires a written plan for keeping the firm running through a disruption. Its full title is Business Continuity Plans and Emergency Contact Information. Paragraph (a) requires each member to create and maintain a written business continuity plan identifying procedures relating to an emergency or significant business disruption. The plan is reviewed annually and modified as the firm’s operations, structure, business or location change.
Paragraph (c) lists ten elements the plan must address, and the first named element is data back-up and recovery, hard copy and electronic. Read the rule’s own lead-in alongside that list, because it changes what the list means. The elements are flexible and may be tailored to the size and needs of a member, and they are addressed to the extent applicable and necessary, with a member that excludes one required to document the rationale. List position is not regulatory priority. The remaining nine, in the order the rule prints them: all mission critical systems; financial and operational assessments; alternate communications between customers and the member; alternate communications between the member and its employees; alternate physical location of employees; critical business constituent, bank and counter-party impact; regulatory reporting; communications with regulators; and how the member will assure customers’ prompt access to their funds and securities.
An honest note. Rule 4370 does not say to hire a managed service provider, and it does not say backup must be outsourced. It requires the plan to address backup and recovery. What is true and worth saying is narrower: the rule asks for a plan that is real rather than filed, and a quarterly documented restore test is the evidence of the difference. Ours is in the service calendar below.
The three are not three copies of one document. Regulation S-P is about protecting customer information and what happens when it leaks. Regulation S-ID is about spotting someone pretending to be your customer. Rule 4370 is about staying in business when the building or the systems go down. They share evidence, and the vendor inventory, the backup record and the annual review each answer to more than one of them. A firm that builds them separately builds the same file three times.
Small at FINRA is not small at the SEC
Two different definitions of a small firm sit on top of each other here, they measure different things, and they get conflated constantly. Never let a sentence about your firm use “small firm” without saying whose definition it means.
FINRA’s test is headcount. A small firm is 1 to 150, mid-size is 151 to 499, and large is 500 or more. FINRA’s firms-by-size statistics gloss the band as registered representatives. The By-Laws themselves say registered persons, which is broader and takes in registered principals, so the two are not interchangeable.
The size of the population. FINRA’s 2026 Industry Snapshot, published June 2026 for year-end 2025, reports 3,184 member firms: 2,832 small, 197 mid-size and 155 large. So roughly 89 percent of the membership is small, and the count is falling, with 163 firms leaving and 98 joining, all at the small tier.
The SEC’s test is money. Exchange Act Rule 0-10(c) makes a broker or dealer a small business only if it had total capital, meaning net worth plus subordinated liabilities, of less than $500,000 at the relevant date, and is not affiliated with any non-natural person that is not itself small. Note it is total capital rather than net capital. Those are different figures and the distinction is the whole point.
Why it mattered. For Regulation S-P compliance-date purposes, larger entities had to comply from 3 December 2025 and everyone else from 3 June 2026. Which group a broker-dealer fell into turned on 0-10(c), not on its FINRA tier. Both dates have now passed, so the rule is in force either way and there is no countdown left to sell.
We are not going to tell you which tier your firm was in. There is no published distribution of FINRA member firms banded by total capital, and any page that asserts one is guessing. The answer for your firm is on your own FOCUS report, which is where total capital already lives, so it is a question you can settle in about a minute without us.
FINRA gives you two of these free, and where that stops
FINRA publishes a free Small Firm Cybersecurity Checklist and a free Small Firm Business Continuity Plan Template, the latter revised in April 2026. There is a free anti-money laundering template and a compliance calendar in the same Compliance Tools section. They are genuinely useful, they are current, and a firm with nothing written down should start there. We would rather say that plainly than pretend they do not exist.
What FINRA says about its own tools is the part worth reading. The obligation is not one-size-fits-all, the firm has to tailor the tool to its own size and needs, and the checklist says in terms that it does not guarantee compliance. The regulator is telling you a template is a starting point. That is a stronger statement coming from FINRA than it would be coming from us.
And then there is the thing a template structurally cannot do. A completed checklist records an intention on the day it was completed. What an examiner asks for is evidence that the control was running on the day in question, month after month, and that when it stopped running somebody noticed and wrote down what they did about it. No template produces that, because a template is a document and this is a record. The service calendar below is where we show what the record looks like.
What failure has actually looked like
The most recent order is the most on-point one. On 25 November 2025 the SEC issued an order against M Holdings Securities, Inc., a dually registered broker-dealer, with a $325,000 penalty, charged under both Rule 30(a) of Regulation S-P and Rule 201 of Regulation S-ID. Two of the three obligations on this page, one broker-dealer respondent.
Its facts are the argument. The firm had adopted an information security policy requiring its member firms to put controls in place across seventeen categories, among them multi-factor authentication, written incident response policies and annual security awareness training. It then collected the compliance data, saw the gaps, and did nothing. The order finds it did not impose any consequences on member firms that did not comply with the policy and, though aware of ongoing self-reported failures, did not revise its policies and procedures. Written one thing, ran another.
Then the 2021 sweep, as history rather than as the headline. On 30 August 2021 the SEC sanctioned eight firms in three actions, $750,000 in total, all under Rule 30(a). The Cetera entities paid $300,000 after cloud email accounts of over 60 personnel were taken over between November 2017 and June 2020, exposing the personal information of at least 4,388 customers and clients. Cambridge paid $250,000 after the accounts of over 121 representatives were taken over between January 2018 and July 2021, exposing at least 2,177. KMS paid $200,000 after the accounts of 15 financial advisers or their assistants were taken over between September 2018 and December 2019, exposing approximately 4,900.
Three things about that release are worth stating plainly. The charge in each case was the written policy rather than the break-in. In the SEC’s own words, it is not enough to write a policy requiring enhanced security measures if those requirements are not implemented, or are only partly implemented, especially in the face of known attacks. At Cambridge the firm discovered the first takeover in January 2018 and did not adopt firm-wide enhanced measures until 2021. And two of the Cetera entities picked up a second charge over the notifications themselves, for language suggesting the notices went out sooner than they had, which is a direct argument for building the notification decision file before it is needed rather than drafting it at 2am.
What we are not going to sell you is a fine. There has been no enforcement under the amended rule. No action has charged the incident response program or the 30-day notification requirement. The realistic exposure for a firm of this size is an examination and a deficiency letter, and Regulation S-P has its own named section in the Division of Examinations’ fiscal-year 2026 priorities, published 17 November 2025. The Division says it will assess compliance with Regulations S-ID and S-P, as applicable, and that examinations will focus on firms’ policies and procedures, internal controls, oversight of third-party vendors, and governance practices. It also says that after the applicable compliance dates it will examine whether firms have developed, implemented and maintained policies and procedures in accordance with the rule’s new provisions.
What an examination opens with. SEC staff published a Compliance Outreach deck walking a mock examination of a $250 million, seven-employee, single-office investment adviser using a managed service provider. It is an adviser walkthrough rather than a broker-dealer one, and we are not going to pretend otherwise. The opening document request is the useful part, because it is the same list either way: the incident response plan; the policies documenting the program to detect, respond to and recover from unauthorized access, including customer notification procedures; a listing of the staff and vendors responsible for incident response; a listing of all detection and monitoring tools; the monitoring evidence itself; and, if an incident occurred, documentation that the program’s steps were followed. The interviews target the chief compliance officer, the CIO or CTO, and the outsourced IT provider. The three common observations staff recorded are that policies and procedures do not appear to be reasonably designed, do not appear to be enforced, or do not appear to exist.
- A direct line to Quinn, the founder, not a sales pipeline.
- Worked in-house by the examiner who scoped it.
- Explainable findings you can verify, with the methodology shown.
The four plans
| What you get | Monitor $995 per month Up to 10 named users and 12 protected devices You have IT covered and your compliance paperwork is current. | Managed IT $1,595 per month Up to 10 named users and 12 protected devices You want us to be your IT department, and your paperwork is current. | Monitor + Comply $1,950 per month Up to 10 named users and 12 protected devices Recommended You have IT covered but need the compliance program built and kept. | Complete $2,495 per month Up to 10 named users and 12 protected devices You want one firm accountable for all of it. |
|---|---|---|---|---|
| Protection | ||||
| Backup of every server, laptop and mailbox | Included | Included | Included | Included |
| Managed detection and response on every device | Included | Included | Included | Included |
| Multi-factor authentication across all five access points | Included | Included | Included | Included |
| Email filtering and security awareness training | Not included | Included | Not included | Included |
| Patch management to a stated target | Not included | Included | Not included | Included |
| Proof | ||||
| Dated monthly evidence pack for your records | Included | Included | Included | Included |
| Quarterly restore test, documented | Included | Included | Included | Included |
| Quarterly privileged access and patch compliance report | Included | Included | Included | Included |
| Cyber insurance application support, from records | Included | Included | Included | Included |
| Day-to-day IT | ||||
| Helpdesk for your staff | Not included | Included | Not included | Included |
| New starters, leavers and device setup | Not included | Included | Not included | Included |
| Remediation and hardening hours included each month | Not included | 2 hrs | Not included | 2 hrs |
| Written compliance program | ||||
| Written incident response program, reviewed annually | Not included | Not included | Included | Included |
| Customer notification decision file, including reasons not to notify | Not included | Not included | Included | Included |
| Vendor inventory, due diligence and 72-hour notice terms | Not included | Not included | Included | Included |
| Annual tabletop exercise with written after-action report | Not included | Not included | Included | Included |
| Records schedule and examiner-ready document pack | Not included | Not included | Included | Included |
Getting started: deployment and a first verified restore is a one time $9,500. The compliance program build is a one time $12,500, required once on the two plans that include it.
Monitor + Comply is the plan built for the three obligations above, because the rows in the written compliance program group are the ones that produce the Regulation S-P and Regulation S-ID documents rather than only the evidence that controls are running.
Your insurance application, control by control
Must have
One carrier's own bind-condition sheet marks controls of this kind as required before it will bind coverage. These are the ones that stop a deal.
Changes the price
You can get a policy without it, but it costs more, or you get lower limits.
On the form
They ask, and the answer goes on file, but on its own it rarely stops anything.
| What the application asks | Monitor | Managed IT | Monitor + Comply | Complete |
|---|---|---|---|---|
| Must have | ||||
| Two-step login (MFA) on email | Covered | Covered | Covered | Covered |
| Two-step login on any way in from outside the office | Covered | Covered | Covered | Covered |
| Security software on every laptop and server | Covered | Covered | Covered | Covered |
| Backups an attacker cannot reach or overwrite, and proven to restore | Covered | Covered | Covered | Covered |
| Calling to confirm a payment before you send it, and a second person approving large onesA must-have for the part of the policy that covers being tricked into sending money, rather than for the policy as a whole. | Covered | Covered | Covered | Covered |
| Changes the price | ||||
| Two-step login on the accounts that can change everything, and on the backup system | Covered | Covered | Covered | Covered |
| What share of devices are covered, and whether the software cuts an infected one off the network by itself | Covered | Covered | Covered | Covered |
| Backups kept apart from the day-to-day network, so one break-in cannot take both | Covered | Covered | Covered | Covered |
| Someone has actually restored a file from backup and written down that it worked | Covered | Covered | Covered | Covered |
| Email screened before it arrives, and attachments opened somewhere safe first | Not covered | Covered | Not covered | Covered |
| How fast you install urgent security updates, and how often you hit that target | Not covered | Covered | Not covered | Covered |
| How many accounts can change anything, and why each one needs to | Covered | Covered | Covered | Covered |
| On the form | ||||
| Software the maker has stopped fixing, still in use | Covered | Covered | Covered | Covered |
| Staff training, and test phishing emails sent to see who clicks | Not covered | Covered | Not covered | Covered |
| A written plan for a break-in, rehearsed once a year | Not covered | Not covered | Covered | Covered |
| Checking the outside companies that touch your customer data | Not covered | Not covered | Covered | Covered |
These are questions from real insurance applications. Where a plan does not cover something, we say so here rather than let you find out on the form.
The one that matters most for a broker-dealer is the wire procedure. Every plan includes a written wire verification procedure: call-backs to a number agreed at onboarding rather than a number supplied in the request, and dual control on transfers above ten thousand dollars, approved by someone other than the person who initiated it, on a different device.
What we do, and how often
Every month
- Control drift reviewProduces: A triaged, recorded list of what stopped reporting and what was escalated
- Backup verificationProduces: Confirmation that every server, laptop and mailbox is backed up
- Evidence packProduces: A dated snapshot of every device and user, filed to your archive
Every quarter
- Restore testProduces: A written result for a real file set restored from backup
- Patch compliance reportProduces: Performance against a stated target, with the rolling twelve-month rate
- Access exception reviewProduces: A record of new devices, bypass codes and administrator accounts
- Report to your chief compliance officerProduces: One page: what changed, what lapsed, what needs a decision
Every year
- Privileged account reviewProduces: Every administrator account listed with a written reason it still exists
- Business continuity plan reviewProduces: A dated record that the plan was reviewed and what was changed
- End-of-life inventoryProduces: A written statement of what protects anything the maker no longer supports
- Insurance evidence packProduces: The control sections of your application or renewal, supported by dated records
The compliance program
Included in Monitor + Comply and Complete. This is the part that produces the documents themselves rather than only the evidence that controls are running. The incident response program is written to the rule with its three parts kept separate and visible: assessment, containment and control, and notification. The customer notification decision file is a template for the decision, with the eight required contents pre-tested, and a filing structure that records the reason you decided not to notify where that was the outcome. The service provider program is the inventory, the due diligence file, the 72-hour notification expectation put to each provider in writing, and a monitoring cadence, because the rule asks for oversight as an activity rather than a policy on a shelf.
On the identity theft side, the same build produces the written program, the red flags your firm has actually incorporated with the reasoning behind them, and the periodic determination under 248.201(c) with its record, which is the deficiency the November 2025 order turned on. The business continuity plan is reviewed annually against Rule 4370’s ten elements, with a written rationale where an element is not applicable, because the rule asks for that rationale by name.
An annual tabletop exercise and a written after-action report are also included. That one is not required by the rule text, and we say so plainly rather than imply otherwise. It is what turns a written plan into a tested one. The records schedule maps all six Regulation S-P categories to 17a-4(e)(14) and its three-year clocks, and the examination readiness pack is assembled against the published document request, so the answer to “please provide” is a folder rather than a fire drill.
An honest boundary, repeated because it matters more here than anywhere else on this page. We prepare these documents for your chief compliance officer and your counsel to review, revise and adopt. We are not your lawyers and we do not give legal or regulatory advice. Where a judgment call belongs to your firm, we set it up so the decision is easy to make and easy to evidence, and then you make it.
What this means for you
- Written scope before any work. You see a written scope covering deliverables, timeline, and price, and you approve it before we begin. You are never billed for work you did not authorize.
- We commit to findings, not outcomes. We tell you up front what the evidence can and cannot establish. Recovery, attribution, and prosecution are decided by banks, platforms, insurers, and courts. We produce the record they act on, and we put that distinction in writing.
- Every case is investigated, not just scanned. A credentialed examiner reviews every case before findings leave the practice. You get a documented investigation to court-admissible standards, not a single automated scan and a one-line answer.
- We will tell you if you do not need us. If a free or simpler step would resolve your situation, whether a police report, an IC3 filing, or a platform's own recovery flow, we point you there first.
What is included, what is not, and what stays yours
We do
- Configure, monitor and maintain every product in your plan
- The monthly, quarterly and annual work in the service calendar above
- Deliver a dated evidence pack to your archive every month
- Support one insurance application or renewal each year
- Escalate anything we find, with a written record
- On Managed IT and Complete: helpdesk, new starters and leavers, device setup, and two hours of remediation and hardening every month
We do not
- Helpdesk on the two Monitor plans, which stays with your own IT
- Incident response and forensics inside the monthly fee, which is billed separately
- Buying or owning your hardware, software licenses, phones or cabling
- Legal, regulatory or insurance advice
- Writing or sending your customer notifications
- Acting as, or standing in for, your chief compliance officer
- Filing anything with FINRA or the SEC on your behalf
- Work on site or outside business hours, except by arrangement
You do
- Name a primary and a backup technical contact, and tell us if that changes
- Respond within four business hours when we escalate something urgent
- Adopt the policies we prepare, with your counsel and your chief compliance officer
- Own the accuracy of anything you file with a regulator or an insurer
- Tell us before you add people, offices, systems or vendors
- Keep your own IT resource in place on the Monitor plans, or tell us if that ends
Written plainly here so nothing is a surprise in month three. The agreement carries the same boundaries in full.
If the worst happens
Two things we put in writing, and the first one comes before the sales pitch. Where privilege matters, and in a serious incident it usually does, we take our instructions through your lawyer rather than direct. That is the arrangement that gives the report the best chance of staying protected, and we set it up at onboarding so it is ready rather than improvised at 2am. The forensic work is a standalone engagement kept separate from the ordinary-course IT services, which is the structure that protects privilege, and it is priced separately on the rate card below for the same reason. And you can always get a second opinion: you may bring in an independent examiner at any point, for any reason, and we will hand over the images, the logs and our working papers to help them.
The advantage of buying both from one practice is not a bundle. It is that the people who already know your environment can be retained by your counsel and start work the same day, with no discovery phase and no handover. Privilege means the other side in a lawsuit cannot demand to see a document. Chain of custody is the unbroken written record of who held a piece of evidence and when, which is what stops the other side arguing it was altered.
Hour one to day ten
- Hour one, contain and preserve. We take your call and stop the bleeding. We capture evidence to forensic standard from the first minute, with chain of custody intact. Most of what is lost in a breach is lost in the first few hours, by well-meaning people rebooting machines.
- Days one to five, examine. Our examiners work the images and the logs. What got in, how, what it touched, what left the building, and whether customer information was actually reached. Those are the questions your notification decision turns on, and the rule asks you to keep the reasoning either way.
- By day ten, report. A written forensic report your compliance officer, your counsel, your insurer and a regulator can all read. Written to be defensible, because we write reports that go to court.
- Then notify, rebuild, and if needed testify. The report feeds your 30-day notification decision and the record behind it. We rebuild the environment. If the matter is litigated, our examiners give evidence.
Who does the work
A digital forensics practice. Quinn holds a degree in cybersecurity from SANS Technology Institute and 9 active GIAC certifications across GIAC, including incident handling, intrusion analysis and mobile forensics. That credential mix is what supports qualification as an expert witness under the Daubert and Frye standards. It is evidence about the examination work, which is what it actually confers.
A great deal of what we are called for is not a hacker at all. A departing registered representative who copied the book to a personal drive. A dispute where the record sits in a mailbox or on a phone. A preservation request that needs a defensible extraction. And the most common loss a small firm actually suffers, a wire that went to the wrong account after a convincing email. Tracing where the money went is a different discipline from reading a firewall log, and it is what this firm was built to do.
The first ninety days
- Days 1 to 10, discovery and paperwork. We inventory every device, user, mailbox and vendor. You get our own due diligence pack: our controls, our insurance, our subprocessors, our incident plan. Regulation S-P at 17 CFR 248.30(a)(5) requires written policies for vetting and monitoring service providers, so we hand ours over before you ask.
- Days 10 to 30, deployment. Backup, endpoint protection and monitoring on every device. Multi-factor login across all five access points. First backup taken and first restore proven, not assumed.
- Days 30 to 60, the program. On the Comply plans: incident response program drafted, notification templates tested, the identity theft program and its periodic determination documented, the business continuity plan reviewed against Rule 4370, and the vendor inventory built with the 72-hour expectation put to each provider in writing. Your counsel reviews. Your chief compliance officer adopts.
- Days 60 to 90, proof and rehearsal. First full evidence pack delivered. First tabletop exercise run, with the written after-action report. If you are placing insurance, we assemble the control evidence for your broker.
What we need from you to start: a named technical contact and a backup, administrative access to your Microsoft or Google tenant, a list of every vendor that touches customer information, your current policies however incomplete, your penetration test report if you have one, and your counsel’s name so the program is prepared under their review.
Rates, growth and the small print
Project and hourly rates
| Work | Standard | On a plan |
|---|---|---|
| Remediation beyond the included allowance | $400/hr | $195/hr |
| Security consulting, assessment and hardening | $400/hr | $275/hr |
| Incident response, containment and rebuild | $400/hr | $275/hr |
| Forensic examination and written report | $400/hr | $325/hr |
| Deposition and trial testimony, four-hour minimum | $400/hr | $400/hr Same as the standard rate. |
| Done-for-you device forensics | from $2,000 | from $2,000 Same as the standard rate. |
| Refundable engagement retainer | $5,000 | Waived |
All rates per hour unless stated. There is no surge for nights, weekends or holidays, on either column. Court time is never discounted, because the hour is the same hour whoever is paying for it.
As your firm grows
Additional named user
$35/mo
Additional workstation
$25/mo
Additional server
$70/mo
New user setup
$150
User departure and offboarding
$100
New device deployment
$200
Term
Twelve months, billed either monthly or as a year paid in advance, renewing unless either of us gives 60 days' notice.
Your data
Your tenants are yours. On exit we return your records in a usable format within 30 days and certify what we destroyed.
Our duty to you
We are a service provider under the rule. We will tell you within 72 hours of becoming aware of a breach affecting a system holding your customer information.
Insurance
We recommend you carry cyber cover and we supply the control evidence to your broker. We are not licensed in insurance and give no insurance advice.
The “our duty to you” term above is the 72-hour service provider notice, and it pairs with obligation 4 near the top of this page. It is a written commitment from a service provider, which is the form the SEC accepted when it declined to mandate a contract clause, so it is yours to keep in your due diligence file.
Growth is reviewed quarterly, effective from the date of the change. Devices count by type, because a server costs several times what a laptop does. Where a vendor sells licenses in blocks, that block is invoiced in full when it is bought.
How an engagement begins
- A scoping call. Forty-five minutes. We walk your environment, tell you what an examiner would ask for that you cannot currently produce, and put a fixed number against it. There is no charge and no obligation.
- Written scope. Deliverables, timeline and price, approved by you before any work begins.
- Discovery, deployment and the program. The ninety days above, with a dated record at every step.
Why this work matters
A firm of ten people carries the same three written obligations as a firm of a thousand, with none of the staff to meet them. What an examiner wants is not a promise but a dated record, and producing that record every month is the whole of this offering.
















