IT and cybersecurity for RIA / Wealth Management
You are held to SEC Reg S-P – active exam priority – and, like most firms your size, you are expected to meet it without anyone in-house whose job it is to own it. We run the IT and the security program so the obligation is actually covered, not just acknowledged.
Where we usually start: Reg S-P deadline (passed 6/3/26) + wire fraud.
If this sounds familiar
“The Reg S-P deadline just passed, and I honestly can’t tell you whether we’re compliant or just have a binder.”
The CCO knows a written incident-response program, 30-day client notification, and 72-hour vendor terms are now required – and suspects the firm’s version exists on paper without the workflows, contracts, and evidence behind it that an examiner will actually test.
“If a fraudulent wire goes out, that’s our client’s money, our liability, and our reputation – all at once.”
Advisers move money daily, business-email-compromise is rampant, and a single successful fraudulent wire request is a catastrophe the firm may not recover from.
“An SEC exam could walk in and expose every cyber gap we have, and I’d have no good answers.”
With Reg S-P a stated 2026 exam priority, the prospect of a deficiency letter – or worse – over cybersecurity is a live, personal fear for the CCO.
Who this is for
Typical size: 10–80 employees (sweet spot 15–50), revenue $1M–$15M. If that is roughly you, the rest of this page will land.
What working with us looks like
A named team that knows your stack, monitoring and patching that happens whether or not anyone chases it, and a written security program kept current – with the evidence to back it up when a client, an auditor or an insurer asks. We report to the Principal + CCO, not to a ticket queue.
Talk to us
Call 206-850-1496 or email mhasse@itwerx.net and we will set up a short call – no audit, no pitch deck, just a conversation about what you have and what is worrying you.

