We operate as a BrainTrust to our clients — someone who sits at their table, knows the regulations cold, and has no product to sell them.

MTradecraft builds the cybersecurity compliance program your SEC examiner, your insurance carrier, and your institutional investors expect to see — and maintains it year-round.

Engagements

Two tiers. One discipline.

Most firms come to us for one of two reasons — an upcoming SEC examination, or a request from their cyber insurance carrier, a custodian, or an institutional DDQ they cannot answer with what they currently have on file. Both engagements are built to close that gap and keep it closed.

Tier One

Cyber Compliance Consultant

$36,000 per year

A full cybersecurity compliance program operated on an annual cadence. Quarterly attack surface assessments, documented policy and procedure updates, vendor oversight, and exam-ready evidence retention. Built for firms that have a CCO and an outsourced IT provider but no internal cybersecurity function.

  • Quarterly external attack surface assessment with documented findings
  • Monthly Microsoft 365 / Azure configuration drift report
  • Continuous breach and credential exposure monitoring
  • Annual cybersecurity policy and procedure refresh
  • Vendor due diligence questionnaire administration and review
  • Year-round evidence file maintained for SEC examination
  • One advisory call per quarter · five-business-day response
Full Scope
What Drives Cybersecurity Compliance

Five parties write the test.

The actual pressure on a firm's cybersecurity program comes from five places, and they are the five things our engagements are designed to answer for:

Driver 01

Cyber insurance carriers

Renewal applications now run 40 to 80 questions on access controls, MFA coverage, backup posture, incident response procedures, and named security leadership. The answers determine whether a firm gets coverage, what it pays, and what is excluded.

Driver 02

Custodians and prime brokers

Every major custodian runs an annual cybersecurity attestation. Prime brokers and fund administrators ask the same questions in a different format. None of them accept "we use a good MSP" as an answer.

Driver 03

Institutional DDQs

Pension consultants, endowment investment offices, and fund-of-funds now ask about CISO designation, third-party penetration testing, and tabletop exercise cadence in their standard due diligence questionnaires. A weak answer here costs allocations.

Driver 04

SEC Division of Examinations

Examiners ask for the firm's cybersecurity policies, the most recent annual review under Rule 206(4)-7, and the evidence file showing the policies were actually implemented and tested. Firms without documentation written by a knowledgeable party fail this test.

Driver 05 — The One That Matters Most

The firm's own clients

The firm's clients assume the firm they hired is operating like Fort Knox. When a client picks up the phone and asks how their data is protected, what the firm did when a breach was reported in the news, or what happens to their account if the firm's email is compromised — the answer has to be specific, accurate, and unrehearsed. Vague reassurances cost trust on the first call and assets under management on the second. A documented program is the only way to answer those questions consistently across every person at the firm who might take them.

The BrainTrust — Self-Serve Resource Library

Templates, policies, and frameworks for firms doing the work themselves.

Not every firm is ready for a full engagement. The BrainTrust gives CCOs and IT managers access to MTradecraft's cybersecurity policy library, incident response templates, vendor due diligence questionnaire, annual review template, and the AI compliance framework — the same materials we use in our consulting engagements.

Free tier includes the Securing Compliance report and starter templates. Premium tier at $2,500 a year unlocks the full library, FieldCraft Security Awareness Training for up to 50 users, and email support from MTradecraft on cybersecurity compliance questions.

Premium Membership
$2,500 per year
  • AI Compliance Framework — full document
  • Cybersecurity Policies and Procedures Manual
  • Incident Response Plan template
  • 206(4)-7 Annual Review Template
  • Vendor Due Diligence Questionnaire
  • Mock SEC Cyber Audit tool
  • FieldCraft training — up to 50 users
  • Email support on compliance questions
Book a Call

Twenty minutes is enough to know whether we're the right firm for what you need — before any commitment.

Most calls start with a specific trigger — an upcoming examination, an insurance renewal, a DDQ response, or a custodian attestation. Tell us what's driving the timing and we'll tell you honestly whether we can help.

Click here to start a conversation →