Industries

Three people can audit you, and they do not coordinate.

An advisory firm answers to its regulator, its custodian and its cyber insurer, and each arrives with a different questionnaire on a different schedule. The controls behind the answers are largely the same set. Iconium runs that set, and keeps the evidence in a form you can hand over.

30 days
Reg S-P customer notice
24/7
Threat monitoring
Under 2 hrs
First response, business hours
$0
Trip charges

What actually goes wrong in a financial services firm

The money-moving failures

  • Business email compromise on a distribution or transfer request, where the attacker only needs to change one line
  • A spoofed client email asking for a wire, arriving on a Friday afternoon
  • Credentials for a custodian portal reused elsewhere and already for sale

The examination failures

  • A written incident response plan that exists as a document nobody has tested
  • Access to client data that was never reviewed after someone changed roles or left
  • No way to show what was reachable during an incident, because nothing was logged

What Regulation S-P now requires

The SEC’s 2024 amendments to Regulation S-P apply to broker-dealers, registered investment advisers, investment companies and transfer agents. The compliance dates for both larger and smaller entities have now passed, so this is a live obligation rather than something on the horizon.

An incident response programme

Written policies and procedures to detect, respond to and recover from unauthorised access to or use of customer information. Written, and capable of being followed by the people who would actually have to follow it.

Customer notification

Notice to affected individuals as soon as practicable, and no later than 30 days after becoming aware of the incident, describing what happened, what data was involved and what the customer can do about it.

Thirty days is the part firms underestimate. The clock does not pause while you work out what was accessed, and that determination is a technical exercise. Firms that have logging and access controls in place answer it in days; firms that do not spend the month on it.

Firms outside SEC registration — lenders, finance companies, and advisers not registered with the Commission — generally fall under the FTC Safeguards Rule instead, which carries its own written-programme requirement and a 30-day notification duty to the FTC. The obligations differ; the controls underneath them barely do. Our accounting and tax page covers the Safeguards Rule in detail.

The controls we run

All part of the standard monthly rate. This list is also, in practice, most of a custodian or insurer questionnaire.

Detect

  • Managed detection and response, 24/7, independent of our support hours
  • Audit logging and activity monitoring
  • Dark web credential monitoring
  • Patch and vulnerability management

Prevent

  • Multi-factor authentication and identity hardening
  • Encryption in transit and at rest
  • Reviewed access controls, so a role change updates access
  • Email security and quarantine, DNS and web content filtering, application allow-listing

Respond and recover

  • Containment and recovery with backup verification and restore testing behind it
  • A technical account of what was reachable, which is what the 30-day clock actually turns on

Evidence

  • Audit evidence collection, assembled rather than reconstructed
  • Security awareness training and simulated phishing, with results you can produce
  • Vendor management and quarterly technology planning

Where our responsibility stops

  • We are not your compliance consultant and we do not act as your chief compliance officer. We operate the controls those roles depend on and give them evidence to work from.
  • The incident response programme is adopted by the firm. We supply its technical substance and we will sit in the tabletop exercise, but a plan the firm has not read is not a plan.
  • Regulatory filings, client notifications and the judgment about what is reportable belong to the firm, normally with counsel.
  • We do not sell attestations or certifications. No regulator issues one, and a vendor offering a compliance seal is offering you an image file.

What it costs

The same published rates: $163 per user, $19 per computer, $100 per server, $17 per mailbox and $179 per additional location, per month. A fully equipped seat is $199 all in. No minimum, no setup fee, no automatic annual escalator. See the pricing page.

We support firms across Northeast Ohio and the Greater Houston area, including co-managed arrangements alongside an internal IT or compliance team.

Questions advisers ask us

If you are a registered investment adviser, yes. The 2024 amendments cover broker-dealers, registered investment advisers, investment companies and transfer agents, and the compliance dates for both larger and smaller entities have now passed. Smaller firms were given longer to prepare, not an exemption. If your firm is not SEC-registered, the FTC Safeguards Rule is usually the one that applies instead, and it carries a similar written-programme requirement.

It depends on whether it describes what actually happens. The common gap is not the absence of a document but the distance between the document and reality: a plan naming a person who left, a recovery step nobody has tested, a system listed that was decommissioned. We will read yours against what is actually deployed and tell you where the two have drifted apart.

Yes, and this is one of the most useful things we do. We tell you exactly what is deployed and show the evidence behind each answer. The answers go in over the firm’s signature because the custodian or insurer is contracting with you, not with us. These questionnaires are also where gaps surface, and that is a far better place to find them than a claim or an examination.

Containment first, which does not wait for business hours. Then the question the clock turns on: what customer information was actually reachable. That is a technical determination, and how long it takes depends almost entirely on whether logging and access controls were in place beforehand. We produce that account; the notification decision and the notification itself are the firm’s, normally with counsel.

Layered, and none of it exotic: email security and quarantine to catch the spoof, multi-factor authentication so a stolen password is not enough, dark web credential monitoring so you know when a password is circulating, and simulated phishing so the person on the receiving end has seen the pattern before. The control that matters most is not technical at all — a callback procedure on a known number, which we will help you write but you have to actually follow.

Not unless you want us to. Co-managed arrangements are normal here: your person keeps the relationships and the institutional knowledge, and we take the parts that need 24/7 coverage, specialist tooling or an audit trail. It also solves the single-point-of-failure problem, which is a question examiners and insurers both ask.

We plan for a clean handover and never withhold data or client intellectual property. We work with your incoming provider to make it orderly. Onboarding in the other direction typically takes about a week, with terms of twelve, twenty-four or thirty-six months and no setup fee.

The published rates apply here as everywhere: $163 per user, $19 per computer, $100 per server, $17 per mailbox and $179 per additional location, per month, or $199 for a fully equipped seat. No minimum and no setup fee. The full list and a calculator are on the pricing page, with no form in front of them.

Got a custodian or insurer questionnaire sitting unanswered?

Call (440) 991-9980 or book a thirty minute call. Bring the questionnaire. We will go through it and tell you which answers you can already give and which ones need work first.

See also: every industry we serve and our written answers.