RIA Cybersecurity

Cybersecurity Built for Registered Investment Advisers

Registered investment advisers are examined on written policies, access control, vendor oversight, and whether they can produce evidence on demand. Generic financial-services IT does not answer those questions. Pylon Technology provides RIA cybersecurity for SEC-registered advisers — dual SOC operations between Southport, CT and Greenville, SC, and documentation examiners can actually use.

Pylon has served regulated firms since 2008. CTO Tim Quinn acts as the SEC technology liaison for our financial clients.

24/7 Dual SOC: Southport, CT and Greenville, SC

Monitoring and incident response run across two sites:

  • Headquarters: 10 John Street, Southport, CT 06890
  • NOC/SOC: 200 North Main St, Greenville, SC 29601

The two locations operate as a dual SOC and disaster-recovery pair. Coverage is 24/7 so after-hours alerts, weekend incidents, and exam-week questions are not left to a single office.

Public partner stack we deploy from: Microsoft, CrowdStrike, Cisco, Palo Alto, and AWS.

Exam-Ready Evidence

SEC staff ask for artifacts, not slide decks. We keep the RIA cybersecurity program in a form you can produce:

  • Current Written Information Security Policy (WISP)
  • Incident Response Plan (IRP) with roles and notification steps
  • Vendor inventory and diligence files
  • MFA enrollment and enforcement evidence
  • Access reviews, logging, and change history
  • Backup, recovery, and dual-site continuity notes

See SEC & FINRA compliance for RIAs and broker-dealers for the broader examination framework, and Regulation S-P for Safeguards Rule notification clocks.

WISP and IRP

Advisers need a written information security program and a tested incident response plan — not a template that sits in a drawer.

Written Information Security Policy

  • Scope, roles, and acceptable use
  • Access control and MFA requirements
  • Data handling, retention, and disposal
  • Vendor and service-provider expectations
  • Annual review cadence aligned to Rule 206(4)-7

Incident Response Plan

  • Detection, containment, and recovery steps
  • Who decides, who documents, who notifies
  • Customer and vendor notification paths under Regulation S-P
  • Evidence preservation for the exam file

Vendor Diligence

Cloud, custodial, CRM, and archiving vendors sit inside the adviser’s risk profile. We help you keep a living vendor inventory and diligence file: what the vendor touches, what they attested to, when it was last reviewed, and what would trigger a re-review.

That file is the same inventory examiners request and the same list Regulation S-P expects you to oversee.

MFA and Access Control

Multi-factor authentication is a standard exam question. We implement and document:

  • MFA on email, remote access, and privileged accounts
  • Role-based access instead of shared logins
  • Exception tracking when MFA cannot be applied
  • Evidence of enforcement — not just a policy sentence

Tim Quinn, SEC Technology Liaison

Tim Quinn, co-founder and CTO, serves as the SEC technology liaison for Pylon’s financial clients. During examinations he can walk staff through architecture, controls, and the evidence package — the same role described on our SEC & FINRA page.

Don Gordon, co-founder and COO, leads operations and service delivery from the Southport headquarters.


Schedule an RIA Cybersecurity Consult

Schedule a consultation to review your WISP, IRP, vendor file, and MFA evidence.

Call: (203) 930-3410 Email: info@pylontechnology.com

Frequently Asked Questions

What cybersecurity evidence do SEC examiners ask a registered investment adviser to produce?

SEC staff ask for artifacts rather than slide decks: the current Written Information Security Policy, an Incident Response Plan with roles and notification steps, the vendor inventory and diligence files, MFA enrollment and enforcement evidence, access reviews with logging and change history, and backup, recovery, and continuity notes.

What is the difference between a WISP and an IRP?

The Written Information Security Policy sets scope, roles, acceptable use, access control and MFA requirements, data handling and disposal, vendor expectations, and an annual review cadence aligned to Rule 206(4)-7. The Incident Response Plan covers what happens during an incident: detection, containment and recovery steps, who decides and who documents, customer and vendor notification paths under Regulation S-P, and evidence preservation for the exam file.

Do SEC examiners ask registered investment advisers about multi-factor authentication?

Multi-factor authentication is a standard examination question. Pylon implements and documents MFA on email, remote access, and privileged accounts, role-based access instead of shared logins, exception tracking where MFA cannot be applied, and evidence of enforcement rather than a policy sentence.

What does a dual SOC mean for an adviser, and where are Pylon's operations centers?

Monitoring and incident response run from two sites: the Southport, CT headquarters at 10 John Street and the Greenville, SC NOC/SOC at 200 North Main St. The two locations operate as a dual SOC and disaster-recovery pair with 24/7 coverage, so after-hours alerts, weekend incidents, and exam-week questions are not left to a single office.

Which vendors belong in an adviser's vendor diligence file?

Cloud, custodial, CRM, and archiving vendors sit inside the adviser's risk profile. The living inventory should record what each vendor touches, what they attested to, when the diligence was last reviewed, and what would trigger a re-review. It is the same inventory examiners request and the same list Regulation S-P expects the firm to oversee.

Who handles technology questions during an SEC examination?

Tim Quinn, co-founder and Chief Technology Officer, serves as the SEC technology liaison for Pylon's financial clients. During examinations he walks staff through architecture, controls, and the evidence package. Don Gordon, co-founder and Chief Operating Officer, leads operations and service delivery from the Southport headquarters.