Cybersecurity Compliance for RIAs · Broker-Dealers · Funds · Family Offices

The SEC and FINRA do not ask
if you are secure.

They ask you to show how your program aligns with current regulations. MTradecraft produces the documents that show a firm is both secure and compliant, and names what is missing in either column.

What We Do

One thing.
Cybersecurity compliance for financial institutions.

Not general IT. Not a product line. The documents and evidence a regulated firm has to produce, mapped to the rule each one answers.

Secure

We test what your IT provider reports.

External attack surface, Microsoft 365 and Azure, internal network. Findings are observable: a configuration, a scan result, a log.

Compliant

We map the work to the rule.

Reg S-P, Reg S-ID, Rule 206(4)-7, Rule 204-2. Every policy, record, and finding carries the citation an examiner will ask about.

Honest

We say what is missing, and how to fix it.

If a firm is short in either column, the report says so in plain language, with a fix plan. We do not perform the remediation and we sell nothing that would benefit from the finding.

The BrainTrust Membership

Start with what the examiner will ask for.
Free, today.

The free tier is real material, not a newsletter. Premium is the full library and the tools that build the documents.

Free Tier 01

The BrainTrust, free.

$0 name and email, no credit card

  • Mock SEC Cyber Exam: 30 real request-list items, scored
  • Securing Compliance: what SEC examiners actually ask for
  • Cybersecurity Compliance Document Review Matrix
  • SEC Exam Cybersecurity Preparedness Brief
  • Reg S-P 2024 Compliance Impact Summary
  • Every Insight, including SEC enforcement updates
  • Preview of the full vendor catalog
Why Firms Call

The request arrives.
Your program has to answer.

Most engagements begin with a deadline, a questionnaire, or a concern that the current documentation will not survive scrutiny.

Managed Engagement

Want us to
run it instead?

For firms with a CCO and outsourced IT but no one whose job is to connect controls, documentation, and regulatory evidence. MTradecraft becomes that function.

Flat fee, per year$36k / $72k
  1. 01

    Exam evidence file, maintained all year

    Produced on demand, not assembled under a deadline.

  2. 02

    Independent testing

    Attack surface, Microsoft 365 and Azure, and internal network, verifying what your IT provider reports.

  3. 03

    Documentation kept current

    Policies, vendor oversight file, incident response plan, and the Rule 206(4)-7 cybersecurity review.

  4. 04

    Remote CISO tier

    Named CISO, DDQ and insurance answers, incident coordination, annual pen test and tabletop.

Our Standard

Evidence proves the work.
Vendor incentives never shape it.

The same discipline runs through every membership tool and every engagement we put our name on.

Compliance

Obligations drive the work.

We start from the duties, risks, and exam expectations that apply to your firm — then decide which controls and tools they require. Not a generic checklist. Not a product looking for a reason to be sold.

Evidence

Evidence proves the work.

Every finding is backed by something observable — a configuration, a scan result, a record, a log. Remediation is documented the same way, so your file shows what was tested, what changed, and when.

Independence

Vendor incentives never shape it.

We resell no hardware, bundle no MSP services, and take no commissions or referral fees. What we recommend is driven by your obligations and your risk — never by what we could sell you next.

300+audits & security reviews
2009advising regulated firms since
600+vendors researched for members
0vendor commissions — ever
Start Here

Factual information that identifies problems.
Solutions that fit the firm.

Create a free account and score your program against the request list an examiner sends. Upgrade when you want the documents already drafted.

Questions first? Email info@mtradecraft.com