
For Financial Services & Commercial Organizations
Built by people who have been on the other side of the table

Our cybersecurity practice was not built by consultants who read about attacks. It was built by a former Chief Cybercrimes Prosecutor — someone who investigated intrusions, handled the electronic evidence, and took the cases forward.
That background changes the advice. It means we design programs with the examination in mind, and we handle incidents knowing that the evidence may eventually have to survive scrutiny by a regulator, an insurer, or a court.
That is partner background. It is not a claim about a named client.
What we help with
Financial-services cybersecurity regulation
23 NYCRR 500 program design and annual certification: written policies, CISO reporting to the board, penetration-testing and vulnerability-scanning cadence, five-year audit trails, access-privilege review, multi-factor authentication, encryption in transit and at rest, data retention and disposal, incident response, and the 72-hour Superintendent notification under 500.17(a).
The annual certification under 500.17(b) is due April 15. We build the program and we prepare the certification. We do not treat a policy binder as a program.
Framework alignment and control mapping
NIST Cybersecurity Framework and NIST 800-53/171, mapped across overlapping regimes so one control set answers several regulators instead of three programs answering one each. Where CISA directives or an executive order (including EO 14409) change federal expectations, we say what that does — and does not — require of a non-federal entity.
Cyber risk assessment and security strategy
Where the actual exposure is, what it would cost, and what to do first — in a document an executive committee can act on. Architecture follows the risk register, not the other way around.
Third-party and vendor risk
Assessment programs, contractual security requirements, and ongoing monitoring for the vendors that hold your data. 23 NYCRR 500.11 is explicit: you remain responsible. A questionnaire that no one scores is not a program.
Incident response and electronic evidence
Response planning before an incident; during one, handling that preserves the evidence. This is the capability most firms cannot offer, and it comes directly from prosecutorial experience — chain of custody, imaging decisions, and what will still be usable if the matter becomes an examination or a case.
Privacy and data protection
Program design, data mapping, retention and disposal, and breach-notification obligations across jurisdictions. Privacy work that cannot produce an inventory, a retention schedule, and a notice decision tree is not ready for examination.
Corporate transparency and beneficial ownership
Corporate Transparency Act and FinCEN reporting posture — including what the August 2026 final rule eliminated for U.S. companies and U.S. persons, what still applies to foreign reporting companies, and what state transparency regimes and bank KYC/AML requirements continue to demand regardless. Do not assume prior BOI records have been deleted until FinCEN says the deletion is complete.
Business continuity and disaster recovery
Plans that are tested, not filed. Recovery-time and recovery-point objectives, alternate processing, and evidence that someone has run the plan since it was approved.
Internal control design and testing
Controls built to be examined, with the testing evidence produced as you go. A control that exists only in a narrative will not survive a request for the sample.
How we work
Most engagements start with a regulatory readiness assessment — a fixed-scope review against the specific regime you answer to, delivered as a gap analysis with a prioritized remediation plan and realistic effort estimates. You will know what is required, what you have, and what it takes to close the distance.
We are a small firm. That means the people who scope your engagement are the people who do it.
