Resources

Cybersecurity and compliance resources for financial services firms.

Start with the regulation, the evidence question, or the business decision your team is facing now.

Guides & Articles

Find the next useful answer

FCI writes for the moment when a compliance officer, executive, or IT leader has to prove that controls are not just documented, but actually enforced. If you are not sure where to start, take The 16 Questions Your Examiner Will Ask first.

Remote access & OS MFA

Can Your IT Provider Access Your Computer Without Asking?

Brian Edelman explains why user approval, technician authentication, and computer-login MFA are separate safeguards for devices holding client information.

5-minute assessment

The 16 Questions Your Examiner Will Ask

Score your firm against 16 examiner and cyber-insurance questions across regulatory readiness, breach preparedness, evidence production, and policy-versus-proof gaps.

Proof guide

Exam-Ready Cybersecurity Evidence

What strong evidence looks like for endpoint coverage, MFA enforcement, incident timelines, vendor oversight, Reg S-P, and cyber-insurance proof.

Case study

$700K Wire-Fraud Recovery

How FCI helped establish the facts, support the FBI, and recover client funds after a wire-fraud incident.

Understand a regulation

SEC & FINRA Cybersecurity Requirements

Reg S-P, Reg S-ID, FINRA Rules 3110 and 4370, and the evidence firms need when the examiner asks.

Reg S-P

Regulation S-P Requirements After the Deadline

What covered institutions need to produce now: incident response procedures, 30-day notification records, vendor oversight, and proof.

Understand a regulation

NYDFS 23 NYCRR 500

A practical guide to cybersecurity governance, incident response, access controls, and evidence under NYDFS requirements.

Prepare for audit

NYDFS Cybersecurity Audit Preparation

What DFS examiners request, what IT meetings cover, and how to organize Part 500 evidence before the audit starts.

Prepare for renewal

Cyber Insurance Readiness

How to back up application answers with timestamped evidence of the controls insurers increasingly require.

Insurance regulation

NAIC Model Law Cybersecurity Evidence

What carriers and agencies should be ready to evidence: risk assessment, vendor oversight, field controls, and incident response.

Choose a provider

Choosing a Cybersecurity Provider

Questions financial services firms should ask before trusting a provider with control enforcement and compliance evidence.

Scope the work

Deployment & Packaging

What changes the scope of an FCI deployment: users, endpoints, offices, BYOD, cloud apps, evidence requirements, and support model.

Clarify ownership

IT & Cyber Disciplines

A guide to how endpoint, network, user, data, cloud, and firm-level security responsibilities fit together.

AI governance

AI Regulatory Guidance

How regulators are approaching AI risk, vendor oversight, supervision, and governance in financial services.

AI governance

Governing AI in Your Firm

A practical starting point for firms that need AI policies, usage boundaries, and evidence of oversight.

Watch

Cyber Shorts

Short explanations of cybersecurity, compliance, and operational risk topics for financial services teams.

Exams

Cyber Exams Now Test Proof, Not Policy

Why financial services firms must move beyond written cybersecurity policies and be ready to produce evidence that controls actually operate.

Insurance

Cyber Insurance Now Requires Proof

Applications, renewals, and claims increasingly demand documented evidence of enforced controls — not attestations.

Need the practical next step?

Request a 30-Minute Gap Analysis

In 30 minutes, you will have a clearer picture of what controls must be in place, what evidence is missing, and what your next exam, audit, or cyber insurance renewal is likely to ask for.