Buyer Guide

How FCI deployments are packaged.

FCI does not publish a one-size-fits-all price list because financial-services environments are not one-size-fits-all. Scope depends on users, endpoints, branch offices, BYOD exposure, cloud applications, evidence requirements, and the level of operational support the firm needs.

Use this guide before a gap analysis to understand what usually drives deployment scope.

The short version

FCI packages around the evidence your firm has to produce.

Most cybersecurity proposals are organized by tool. FCI scopes around the operating reality of the firm: which controls must be enforced, where those controls must operate, who needs visibility, and what documentation must be ready for examiners, insurers, executives, and incident responders.

Control scope

Users, devices, offices, and apps

The number of endpoints matters, but so does the complexity of branch offices, remote users, cloud applications, and BYOD.

Evidence scope

What compliance needs to prove

Reg S-P, FINRA, NYDFS, NAIC, cyber-insurance renewals, WISP obligations, and board reporting can change the package.

Operating scope

Who runs and documents the program

Some firms need control enforcement only. Others need CISO support, evidence-package production, incident response, and field-office rollout help.

Deployment models

Common starting points.

These are not public price tiers. They are the typical ways FCI scopes the work before finalizing a deployment plan.

Model 1
Core control and evidence package.

Usually fits smaller RIAs or focused financial-services teams that need endpoint protection, user-security enforcement, documented control status, WISP alignment, and cyber-insurance evidence without a large field-office rollout.

Common scope drivers: number of users/endpoints, current MFA state, device ownership model, cloud application footprint, cyber-insurance renewal timing, and whether policies already exist.
Model 2
Distributed branch and advisor network package.

Usually fits broker-dealers, hybrid RIAs, OSJs, and firms with advisors or representatives operating across many locations. The work is less about installing one tool and more about proving coverage across every office, endpoint, and user.

Common scope drivers: branch count, advisor/representative count, onboarding waves, BYOD policy, field-office exception handling, compliance reporting needs, and portal access for home-office stakeholders.
Model 3
Insurance carrier, agency, and oversight package.

Usually fits insurance organizations that need to demonstrate oversight across carriers, agencies, appointed agents, vendors, and cyber-insurance requirements. The package emphasizes control evidence, incident readiness, and NAIC-aligned documentation.

Common scope drivers: agency/agent population, data access model, vendor relationships, NAIC Model Law applicability, security-assessment cadence, incident notification workflow, and insurer evidence requirements.

What a deployment normally includes

The package is more than software.

FCI’s value is the combination of enforced controls, operational support, and evidence production. A typical deployment may include these components, depending on scope.

Control implementation

Endpoint, user, network, data, cloud-app, and firm-level controls configured for the firm’s real operating environment.

FCI Portal visibility

Centralized status, coverage, remediation, alerts, and evidence views for security, IT, compliance, and leadership stakeholders.

Policy-to-proof mapping

Documentation that connects written policies, WSPs, WISPs, cyber-insurance answers, and regulator expectations to enforced controls.

Evidence packages

Exam, renewal, incident, vendor, and board-ready artifacts that show what is deployed and whether it is working.

Incident response support

Containment, remediation, forensic documentation, and technical support for conversations with regulators, insurers, and law enforcement.

Ongoing operations

Monitoring, exception handling, reviews, support escalation, reporting cadence, and updates as regulations and firm structure change.

How to use this before a call
Bring the scope questions, not a shopping list.

The most useful gap-analysis conversations start with operating facts: approximate users and endpoints, number of offices or advisor/agent locations, whether personal devices are in scope, what regulators or insurers are asking for, and which evidence is hardest to produce today.

Fastest next step: complete The 16 Questions Your Examiner Will Ask, then bring the result to a 30-minute gap analysis. It gives both sides a clearer view of where scope is likely to concentrate.

Scope the deployment around your evidence gaps.

Start with the assessment, or schedule a gap analysis to map your users, endpoints, offices, regulations, and evidence requirements to the right deployment model.