Proof Asset

Exam-ready evidence is the difference between having controls and proving them.

Policies describe what should happen. Exam-ready evidence shows what is actually enforced, where it is enforced, when it was checked, who reviewed it, and what happened when something needed remediation.

Last updated: August 2026

The short version

Examiners and cyber insurers ask for evidence, not intention.

A strong cybersecurity program needs a written policy, enforced controls, and a record that connects the two. The hardest part for distributed financial services firms is usually not buying tools. It is producing a complete, current, defensible evidence trail across users, devices, offices, cloud applications, vendors, and incidents.

For Brian Edelman’s perspective on the regulatory shift behind this page, read The New Cyber Exam Question Is: Can You Prove It?

Policy

What the firm says must happen

Written safeguards, WSPs, incident response procedures, access-control standards, vendor requirements, and cyber-insurance attestations.

Control

What is technically enforced

Endpoint protection, MFA, patching, backups, DLP, monitoring, response actions, vendor oversight, and exception handling.

Evidence

What the firm can prove

Timestamped records showing coverage, status, ownership, remediation, approvals, incident decisions, and production-ready exam artifacts.

What good looks like

Six evidence records every financial services firm should be able to produce.

The exact request varies by examiner, insurer, regulator, and incident facts. These are the recurring proof categories that separate a documented program from a defensible one.

Endpoint coverage and remediation record

Devices, branches, advisors, agents, BYOD where applicable

A coverage report should show which devices are protected, which are missing controls, which exceptions exist, and how remediation was handled.

  • Device inventory and owner
  • Protection status and last check-in
  • Patch, EDR, encryption, and backup state
  • Exceptions, stale devices, and remediation timestamps

MFA and user-access enforcement record

Users, admins, contractors, remote access, critical applications

Cyber insurers and examiners increasingly ask whether MFA is enforced, not merely available. The proof must cover users, applications, and exceptions.

  • User population in scope
  • MFA enforcement status by application
  • Privileged-access restrictions
  • Joiner, mover, leaver and exception records

Incident response timeline

Detection, containment, investigation, notification, recovery

When a security event happens, the record should show who knew what, when they knew it, what action was taken, and why notification decisions were made.

  • Awareness timestamp and source
  • Containment and remediation actions
  • Customer-information impact analysis
  • Notification decision memo and final disposition

Vendor and service-provider oversight record

Reg S-P, third-party risk, customer-information systems

For vendors that touch customer information, the firm needs contracts, contacts, due diligence, and evidence that notification expectations are operational.

  • Vendor inventory and system mapping
  • Due diligence and review history
  • 72-hour breach-notification language where required
  • Escalation contacts and owner accountability

Regulatory mapping record

Reg S-P, Reg S-ID, FINRA 3110/4370, NYDFS where applicable

A control record becomes exam-ready when it maps to the policy and regulatory requirement it supports.

  • Requirement or policy reference
  • Control owner and operating evidence
  • Review cadence and approval history
  • Current status and exception rationale

Cyber-insurance control proof

Application answers, renewal evidence, claim support

Insurance applications create risk when answers are not backed by current records. Strong evidence supports both renewal and claim defensibility.

  • MFA, backup, EDR, encryption, and training evidence
  • Timestamped status at application or claim date
  • Exception records and remediation notes
  • Single source of truth for attestation support

Evidence standard

A useful evidence record answers five questions.

QuestionWhat the record should show
What control is required?The policy, supervisory procedure, insurance control, or regulatory requirement the evidence supports.
Where is it enforced?The users, devices, offices, applications, vendors, or data systems in scope.
What is the current status?Whether the control is active, missing, degraded, excepted, or remediated.
When was it verified?Timestamped checks, review dates, incident timeline entries, or approval records.
Who owns the gap?The accountable owner, escalation path, remediation note, and closure evidence.

FCI approach

FCI turns managed cybersecurity work into a living evidence record.

The point is not to create another spreadsheet before every exam. The point is to make evidence a byproduct of operating the cybersecurity program.

Deploy and enforce

Controls are implemented across endpoints, users, networks, cloud applications, data, and firm-level workflows.

Monitor and respond

Alerts, incidents, remediation work, and exceptions are handled with ownership and documentation.

Map to obligations

Evidence is tied back to regulatory requirements, written policies, insurance controls, and operational risk categories.

Produce proof

Compliance, executives, examiners, and insurers can see the record without rebuilding it from scattered systems.

Find out where your evidence trail is strongest — and where it breaks.

Start with the 16-question readiness assessment, then use a gap analysis to validate which records your firm can produce today.