We test what your IT provider reports.
External attack surface, Microsoft 365 and Azure, internal network. Findings are observable: a configuration, a scan result, a log.
They ask you to show how your program aligns with current regulations. MTradecraft produces the documents that show a firm is both secure and compliant, and names what is missing in either column.
Need someone to run the program for you? Book a 20-minute fit call.
Not general IT. Not a product line. The documents and evidence a regulated firm has to produce, mapped to the rule each one answers.
External attack surface, Microsoft 365 and Azure, internal network. Findings are observable: a configuration, a scan result, a log.
Reg S-P, Reg S-ID, Rule 206(4)-7, Rule 204-2. Every policy, record, and finding carries the citation an examiner will ask about.
If a firm is short in either column, the report says so in plain language, with a fix plan. We do not perform the remediation and we sell nothing that would benefit from the finding.
The free tier is real material, not a newsletter. Premium is the full library and the tools that build the documents.
$0 name and email, no credit card
$2,500 per year, flat. Cancel anytime.
Most engagements begin with a deadline, a questionnaire, or a concern that the current documentation will not survive scrutiny.
You need a defensible evidence file, not a binder of policies nobody has tested.
Start free: Mock SEC Cyber Exam, scored against 30 real request items →The carrier wants precise answers on MFA, backups, response plans, and who owns each control.
Start free: Document Review Matrix →A custodian, prime broker, or investor expects controls documented in a form your IT provider was never asked to produce.
Start with Premium: the vendor due diligence portal →An incident or exposure revealed the distance between the written policy and what actually runs.
Start with Premium: IRP Builder and Incident Response Assistant →For firms with a CCO and outsourced IT but no one whose job is to connect controls, documentation, and regulatory evidence. MTradecraft becomes that function.
Produced on demand, not assembled under a deadline.
Attack surface, Microsoft 365 and Azure, and internal network, verifying what your IT provider reports.
Policies, vendor oversight file, incident response plan, and the Rule 206(4)-7 cybersecurity review.
Named CISO, DDQ and insurance answers, incident coordination, annual pen test and tabletop.
The same discipline runs through every membership tool and every engagement we put our name on.
We start from the duties, risks, and exam expectations that apply to your firm — then decide which controls and tools they require. Not a generic checklist. Not a product looking for a reason to be sold.
Every finding is backed by something observable — a configuration, a scan result, a record, a log. Remediation is documented the same way, so your file shows what was tested, what changed, and when.
We resell no hardware, bundle no MSP services, and take no commissions or referral fees. What we recommend is driven by your obligations and your risk — never by what we could sell you next.
Create a free account and score your program against the request list an examiner sends. Upgrade when you want the documents already drafted.
Questions first? Email info@mtradecraft.com