01
RIA Cybersecurity Assessment
An evidence-based view of the program and how well it holds up under scrutiny.
A focused, management-level assessment of the firm's cybersecurity program and its ability to demonstrate that program to regulators. It draws on recognized cybersecurity practices and the realities of SEC examination readiness. The result is an executive assessment of current posture, identified gaps and a prioritized remediation roadmap. It is not a penetration test, vulnerability scan, compliance certification or legal opinion.
- Cybersecurity governance and accountability
- Policies and procedures
- Identity and access controls
- Protection of sensitive client and firm information
- Vendor and third-party risk
- Incident preparedness, business continuity and recovery
- Employee awareness and training
- Evidence supporting the firm's cybersecurity practices and readiness for SEC examination requests