Resources
Cybersecurity and compliance resources for financial services firms.
Start with the regulation, the evidence question, or the business decision your team is facing now.
Guides & Articles
Find the next useful answer
FCI writes for the moment when a compliance officer, executive, or IT leader has to prove that controls are not just documented, but actually enforced. If you are not sure where to start, take The 16 Questions Your Examiner Will Ask first.
Remote access & OS MFA
Can Your IT Provider Access Your Computer Without Asking?
Brian Edelman explains why user approval, technician authentication, and computer-login MFA are separate safeguards for devices holding client information.
5-minute assessment
The 16 Questions Your Examiner Will Ask
Score your firm against 16 examiner and cyber-insurance questions across regulatory readiness, breach preparedness, evidence production, and policy-versus-proof gaps.
Proof guide
Exam-Ready Cybersecurity Evidence
What strong evidence looks like for endpoint coverage, MFA enforcement, incident timelines, vendor oversight, Reg S-P, and cyber-insurance proof.
Case study
$700K Wire-Fraud Recovery
How FCI helped establish the facts, support the FBI, and recover client funds after a wire-fraud incident.
Understand a regulation
SEC & FINRA Cybersecurity Requirements
Reg S-P, Reg S-ID, FINRA Rules 3110 and 4370, and the evidence firms need when the examiner asks.
Reg S-P
Regulation S-P Requirements After the Deadline
What covered institutions need to produce now: incident response procedures, 30-day notification records, vendor oversight, and proof.
Understand a regulation
NYDFS 23 NYCRR 500
A practical guide to cybersecurity governance, incident response, access controls, and evidence under NYDFS requirements.
Prepare for audit
NYDFS Cybersecurity Audit Preparation
What DFS examiners request, what IT meetings cover, and how to organize Part 500 evidence before the audit starts.
Prepare for renewal
Cyber Insurance Readiness
How to back up application answers with timestamped evidence of the controls insurers increasingly require.
Insurance regulation
NAIC Model Law Cybersecurity Evidence
What carriers and agencies should be ready to evidence: risk assessment, vendor oversight, field controls, and incident response.
Choose a provider
Choosing a Cybersecurity Provider
Questions financial services firms should ask before trusting a provider with control enforcement and compliance evidence.
Scope the work
Deployment & Packaging
What changes the scope of an FCI deployment: users, endpoints, offices, BYOD, cloud apps, evidence requirements, and support model.
Clarify ownership
IT & Cyber Disciplines
A guide to how endpoint, network, user, data, cloud, and firm-level security responsibilities fit together.
AI governance
AI Regulatory Guidance
How regulators are approaching AI risk, vendor oversight, supervision, and governance in financial services.
AI governance
Governing AI in Your Firm
A practical starting point for firms that need AI policies, usage boundaries, and evidence of oversight.
Watch
Cyber Shorts
Short explanations of cybersecurity, compliance, and operational risk topics for financial services teams.
Exams
Cyber Exams Now Test Proof, Not Policy
Why financial services firms must move beyond written cybersecurity policies and be ready to produce evidence that controls actually operate.
Insurance
Cyber Insurance Now Requires Proof
Applications, renewals, and claims increasingly demand documented evidence of enforced controls — not attestations.
Case Studies
Client stories, told with proof
Named clients, real outcomes, and the FCI model behind each. More are on the way.
RIA · Full Zero Trust
A Growing RIA, Fully Zero Trust
How Portland Private Wealth adopted FCI’s complete managed stack — every control enforced, evidence on demand, advisors unchanged.
Home Office & Enterprise
WestPac Wealth Partners — Two Sets of Requirements, One Answer
A national Guardian Life agency meets both cybersecurity regulation and its home office’s policy document — reviewed, configured, enforced, and evidenced by FCI.
Need the practical next step?
Request a 30-Minute Gap Analysis
In 30 minutes, you will have a clearer picture of what controls must be in place, what evidence is missing, and what your next exam, audit, or cyber insurance renewal is likely to ask for.