For years, a cybersecurity exam conversation could start with a familiar request: show us the policy. Today, that is only the beginning. The more important question is whether the firm can prove the policy is operating.

That shift matters for broker-dealers, RIAs, insurance organizations, and other financial services firms with distributed operations. Regulators and cyber insurers are no longer satisfied with a written statement that says controls are required. They want evidence that those controls are enforced, current, reviewed, and documented.

In practice, the new question is simple: Can you prove it?

A policy is not proof

A written safeguards policy, WSP, incident response plan, or cyber-insurance application is important. But each document creates a second obligation: the firm must be able to show that the controls named in the document are actually in place.

If a policy says every device must run endpoint protection, the firm should be able to produce an endpoint coverage record. If a procedure says MFA is required, the firm should be able to show MFA enforcement by user and application. If an incident response program describes escalation, investigation, containment, and notification, the firm should be able to show the timeline when an event occurs.

Without that evidence, a yes answer can become a risk. A firm may believe a control is in place, but belief is not the same as a timestamped record.

Reg S-P makes the evidence problem visible

The amended Regulation S-P requirements have made this operational reality harder to ignore. Covered institutions need written incident response procedures, customer-notification workflows, and service-provider oversight records. The issue is not only whether those documents exist. It is whether the firm can show how they operate when customer information, vendors, users, and systems are involved.

That means firms should be ready to answer questions such as:

Those are not theoretical questions. They are operational questions. They require records.

Distributed firms have a harder proof burden

For a centralized firm, evidence is still difficult. For a distributed financial services firm, it is much harder. The home office may write the program, but users, advisors, agents, devices, cloud applications, branches, and third-party providers often operate across a much wider environment.

That creates the gap examiners find: the policy is centralized, but the evidence is scattered. It may sit in security tools, spreadsheets, email threads, vendor portals, IT tickets, compliance folders, and manual reports. When an examiner, insurer, or executive asks for proof, the team has to rebuild the story from fragments.

That is why evidence cannot be a last-minute project. It has to be produced continuously as part of how the cybersecurity program operates.

What exam-ready evidence looks like

Exam-ready evidence is not a pile of screenshots. A useful record connects the requirement, the control, the environment, the owner, the date, and the current status.

A strong evidence record answers five questions:

That structure turns cybersecurity from a set of claims into an operating record.

The practical next step

Every financial services firm should pressure-test its own answers before an examiner or cyber insurer does. Start with the controls you already claim to have: endpoint protection, MFA, backups, incident response, vendor oversight, access reviews, and customer-information safeguards.

Then ask the harder question: if someone requested evidence today, could you produce it by the end of the day?

FCI built its managed cybersecurity model around that proof gap. The goal is not to add another document project before every exam. The goal is to enforce controls, document the work, and maintain a living evidence record that compliance, executives, examiners, and insurers can use when they need it.

To pressure-test your firm’s posture, start with FCI’s 16-question cybersecurity readiness assessment. To understand what the evidence should look like, review the guide to exam-ready cybersecurity evidence. For regulatory context, see FCI’s resources on Regulation S-P requirements and SEC and FINRA cybersecurity requirements.

By Brian Edelman, CEO, FCI Cyber