Information security program (WISP)
Build or refresh the written program the SEC expects, mapped to a recognised framework such as NIST CSF, and sized to your firm rather than copied from a bank.
For US Registered Investment Advisers
Under the amended Regulation S-P, every adviser is now expected to run a written information security program, an incident response plan, and real oversight of the vendors that touch client data. We help RIAs put those in place, keep them current, and explain them to a board, without the overhead of building a large security team in-house.
Regulation S-P
The SEC's amended Regulation S-P is now in effect. Under it, an adviser is expected to:
This is what examiners look for, and what your own investors ask about in their due-diligence questionnaires. Having the documents is one thing. Being able to show they work is another.
Services
We work across the areas an adviser is now expected to cover. You can start with the one that is most pressing and add others as you need them.
Build or refresh the written program the SEC expects, mapped to a recognised framework such as NIST CSF, and sized to your firm rather than copied from a bank.
A written plan your team can actually follow, with the roles, steps, and the 30-day client-notification process Regulation S-P requires, then tested with a tabletop exercise so it holds up under pressure.
A practical process for assessing the providers that touch your data, and the 72-hour incident-reporting terms your contracts now need. We also help you answer the security questionnaires your clients and allocators send you.
Reviews of how your core platforms are configured and secured, including Microsoft 365, Google Workspace, your CRM, and custodial connections. The focus is identity, access, multi-factor authentication, and the account settings attackers exploit, such as weak logins and malicious mailbox forwarding rules. We assess how the environment is secured, not the contents of your email.
A clear read of where you stand against the SEC's expectations and a recognised framework, with findings ranked by real impact and a remediation order you can work through.
Web, application, and infrastructure testing when you need technical assurance, delivered as risk-ranked findings and fixes rather than raw scanner output.
Training built for an adviser's staff, focused on the phishing and wire-fraud attempts that target the industry.
Senior security guidance on a continuing basis: keeping your program current, preparing updates for your board and committees, and being the person your team calls when something looks wrong. This is a relationship, not a one-time report.
Our approach
Compliance expectations do not reset each year, and neither should your security. Most of our work with advisers is a continuing arrangement: we keep your program current as your firm and the rules change, rather than handing you a report and moving on.
The person who scopes your work is the person who does it. You deal directly with a senior practitioner.
Findings and updates are written so your compliance, operations, and leadership can all act on them, and so you can put them in front of your board or produce them when asked.
We size the work to an adviser your size. You pay for what reduces your risk and meets the expectation, not for a program built for a bank.
Get Started
Tell us where your firm is today: what you already have in place, what an examiner or investor has asked for, and what is worrying you. We will come back with a clear next step and an honest view of what you actually need. No sales pitch.