For RIAs · Broker-Dealers · Funds · Family Offices

When the examiner asks,
your evidence is ready.

We build, test, and maintain cybersecurity compliance programs that your SEC or FINRA examiner wants to see, your insurer asks about, and your clients and investors assume you already have.

Our Standard

Three principles.
No exceptions.

The same discipline runs through every engagement — every recommendation, finding, and deliverable we put our name on.

Compliance

Obligations drive the work.

We start from the duties, risks, and exam expectations that apply to your firm — then decide which controls and tools they require. Not a generic checklist. Not a product looking for a reason to be sold.

Evidence

Evidence proves the work.

Every finding is backed by something observable — a configuration, a scan result, a record, a log. Remediation is documented the same way, so your file shows what was tested, what changed, and when.

Independence

Vendor incentives never shape it.

We resell no hardware, bundle no MSP services, and take no commissions or referral fees. What we recommend is driven by your obligations and your risk — never by what we could sell you next.

300+audits & security reviews
2009advising regulated firms since
600+vendors researched for members
0vendor commissions — ever
Why Firms Call Us

The request arrives.
Your program has to answer.

Most engagements begin with a deadline, a questionnaire, or a concern that the current documentation will not survive scrutiny.

01

An exam is coming

You need a defensible evidence file — not a last-minute binder of policies nobody has tested. Already have the notice? Examination response support is available to any firm at $250 / hour, no engagement required.

02

Insurance is renewing

The carrier wants precise answers on MFA, backups, response plans, controls, and ownership.

03

A DDQ is blocking growth

A custodian, prime broker, or investor expects controls your MSP cannot credibly document.

04

A gap has surfaced

An incident or exposure revealed the distance between written policy and operational reality.

The MTradecraft Method

Built once.
Maintained every quarter.

Cybersecurity compliance is not a document purchase. It is a repeatable operating discipline with proof attached.

Explore the Engagements
  1. 01

    Find what is exposed

    Assess the public attack surface, cloud configuration, credentials, vendors, and internal controls the way an adversary — and examiner — would.

  2. 02

    Map the rule to the work

    Turn findings into policies, procedures, accountable owners, and evidence mapped to Reg S-P, Reg S-ID, Rule 206(4)-7, and Rule 204-2.

  3. 03

    Keep the file current

    Test, update, and retain evidence throughout the year so readiness does not depend on a scramble when the request arrives.

Choose Your Operating Model

We can run the program.
Or give you the playbook.

Two paths for two kinds of firm. Both use the same examiner-focused methodology and working materials.

Self-Directed Membership 02

Run it in-house with The BrainTrust.

For CCOs and IT leaders who need the same policies, frameworks, training, and readiness tools we use in client engagements.

  • Reg S-P vendor due-diligence portal — 600+ researched vendors with cited evidence; select your stack, print your vendor file
  • Security awareness training with completion records for up to 50 staff
  • Incident Response Plan Builder, plus a live Incident Response Assistant if one happens
  • 60 editable templates mapped to the rule each supports — policies, annual review, exam checklists
  • AI governance kit, quarterly external exposure snapshot (beta), and email support from the practice
Start With the Trigger

Tell us what is driving the timing.
We'll tell you honestly if we can help.

An exam, a renewal, a DDQ, a custodian attestation, or a concern you cannot quite dismiss. Twenty minutes is enough to establish fit.

Prefer to run it yourself? Start free — the templates, the mock exam, and the report are waiting →