Buyer Guide
How FCI deployments are packaged.
FCI does not publish a one-size-fits-all price list because financial-services environments are not one-size-fits-all. Scope depends on users, endpoints, branch offices, BYOD exposure, cloud applications, evidence requirements, and the level of operational support the firm needs.
Use this guide before a gap analysis to understand what usually drives deployment scope.
The short version
FCI packages around the evidence your firm has to produce.
Most cybersecurity proposals are organized by tool. FCI scopes around the operating reality of the firm: which controls must be enforced, where those controls must operate, who needs visibility, and what documentation must be ready for examiners, insurers, executives, and incident responders.
Control scope
Users, devices, offices, and apps
The number of endpoints matters, but so does the complexity of branch offices, remote users, cloud applications, and BYOD.
Evidence scope
What compliance needs to prove
Reg S-P, FINRA, NYDFS, NAIC, cyber-insurance renewals, WISP obligations, and board reporting can change the package.
Operating scope
Who runs and documents the program
Some firms need control enforcement only. Others need CISO support, evidence-package production, incident response, and field-office rollout help.
Deployment models
Common starting points.
These are not public price tiers. They are the typical ways FCI scopes the work before finalizing a deployment plan.
Usually fits smaller RIAs or focused financial-services teams that need endpoint protection, user-security enforcement, documented control status, WISP alignment, and cyber-insurance evidence without a large field-office rollout.
Usually fits broker-dealers, hybrid RIAs, OSJs, and firms with advisors or representatives operating across many locations. The work is less about installing one tool and more about proving coverage across every office, endpoint, and user.
Usually fits insurance organizations that need to demonstrate oversight across carriers, agencies, appointed agents, vendors, and cyber-insurance requirements. The package emphasizes control evidence, incident readiness, and NAIC-aligned documentation.
What a deployment normally includes
The package is more than software.
FCI’s value is the combination of enforced controls, operational support, and evidence production. A typical deployment may include these components, depending on scope.
Control implementation
Endpoint, user, network, data, cloud-app, and firm-level controls configured for the firm’s real operating environment.
FCI Portal visibility
Centralized status, coverage, remediation, alerts, and evidence views for security, IT, compliance, and leadership stakeholders.
Policy-to-proof mapping
Documentation that connects written policies, WSPs, WISPs, cyber-insurance answers, and regulator expectations to enforced controls.
Evidence packages
Exam, renewal, incident, vendor, and board-ready artifacts that show what is deployed and whether it is working.
Incident response support
Containment, remediation, forensic documentation, and technical support for conversations with regulators, insurers, and law enforcement.
Ongoing operations
Monitoring, exception handling, reviews, support escalation, reporting cadence, and updates as regulations and firm structure change.
The most useful gap-analysis conversations start with operating facts: approximate users and endpoints, number of offices or advisor/agent locations, whether personal devices are in scope, what regulators or insurers are asking for, and which evidence is hardest to produce today.
Scope the deployment around your evidence gaps.
Start with the assessment, or schedule a gap analysis to map your users, endpoints, offices, regulations, and evidence requirements to the right deployment model.