Regulatory and Legal Compliance
Financial Services Regulatory Assessment
Control assessments for GLBA and the FTC Safeguards Rule, NYDFS Part 500, FINRA, SEC cybersecurity rules, and SOX IT general controls.
Overview
Control assessment against the technical requirements of the financial services regime, including the Gramm-Leach-Bliley Act and the Federal Trade Commission Safeguards Rule, New York Department of Financial Services Part 500, Financial Industry Regulatory Authority guidance and examination priorities, Securities and Exchange Commission cybersecurity disclosure and risk management rules, and Sarbanes-Oxley information technology general controls.
Who it is for
Designed for established organizations measuring and maturing an existing security program, and law firms, corporate legal departments, and the clients they advise.
What you receive
Regulatory control assessment, deficiency findings, remediation plan, certification support.
How engagements work
Every engagement is scoped individually and conducted under a master services agreement and mutual confidentiality terms. Work begins with a scoping conversation to understand your objectives, constraints, and deadlines, followed by a written statement of work defining scope, deliverables, and timeline. Both parties retain the right to decline an engagement where the fit is not right.