# Pylon Technology — full summary > Pylon Technology is a managed security services provider (MSSP) for regulated firms: > registered investment advisers (RIAs), broker-dealers, healthcare, and legal. > Founded 2008. Offices in Southport, CT and Greenville, SC. This file expands https://pylontechnology.com/llms.txt with longer, page-by-page summaries. Every statement here is drawn from the page it summarises. Where a page states a regulatory date or a notification clock, the number is repeated here verbatim rather than paraphrased. Last reviewed: 2026-09-15. --- ## Company facts - Legal/trading name: Pylon Technology - Type: managed security services provider (MSSP) / managed service provider (MSP) - Founded: 2008 - Co-founders: Don Gordon (Chief Operating Officer, operations and service delivery) and Tim Quinn (Chief Technology Officer; SEC technology liaison for financial clients) - Team: 17 people across two locations - Clients: 100+ organisations in regulated industries - Headquarters: 10 John Street, Southport, CT 06890 (Southport is a village in Fairfield) - NOC/SOC: 200 North Main St, Greenville, SC 29601 - The two sites operate as a dual SOC and as a disaster-recovery pair; monitoring is 24/7 - Main line: (203) 930-3410 — +1.203.930.3410 - General email: info@pylontechnology.com - Existing clients reach 24/7 support through the helpdesk details published on https://pylontechnology.com/contact/ - Markets served: CT, NY, MA, PA, SC, and NC, with remote coverage nationwide - Public technology partners listed on the site: Microsoft, CrowdStrike, Cisco, Palo Alto Networks, AWS There is not a physical office in every city Pylon serves. On-site coverage is Fairfield County, Connecticut and Greenville County, South Carolina. --- ## Home — positioning URL: https://pylontechnology.com/ Managed IT, cybersecurity, and regulatory compliance for financial services, healthcare, and legal firms in Connecticut and South Carolina. The homepage positions Pylon as a compliance-first MSSP rather than a general IT shop: the differentiator it states is that the technology programme is built to survive an examination, with documentation and evidence kept current as a matter of normal operations. Six service lines are presented: 1. Managed technology and IT support — 24/7 monitoring, helpdesk, proactive maintenance and patch management, documented change management for audit trails, disaster recovery and business continuity planning. 2. Professional services — strategic consulting, project management, and technology planning for regulated environments. 3. Cybersecurity and compliance — EDR, XDR, and SIEM; 24/7 SOC monitoring; incident response and forensic investigation; vulnerability assessment and penetration testing. 4. Artificial intelligence and automation — security analytics, automated compliance workflows, and automated threat response. 5. Cloud solutions and infrastructure — HIPAA-compliant and SEC-aligned cloud environments, encrypted storage, access controls, multi-region redundancy. 6. Regulatory compliance — HIPAA, SEC, FINRA, and SOX programmes with audit-ready documentation. Stated trust signals: 17+ years in business, 100+ regulated clients, 2 SOC locations, SOC 2 Type II certification, HIPAA compliance specialisation, SEC/FINRA audit experience, 100+ successful audits supported. --- ## RIA cybersecurity URL: https://pylontechnology.com/industries/ria-cybersecurity/ Cybersecurity for SEC-registered investment advisers. The page's argument is that advisers are examined on written policies, access control, vendor oversight, and whether evidence can be produced on demand — so generic financial-services IT does not answer the questions an examiner asks. What the page documents: - **Dual SOC.** Monitoring and incident response run from 10 John Street, Southport, CT 06890 and 200 North Main St, Greenville, SC 29601, 24/7, so after-hours and weekend alerts are not left to a single office. - **Exam-ready evidence.** Current WISP; IRP with roles and notification steps; vendor inventory and diligence files; MFA enrollment and enforcement evidence; access reviews, logging, and change history; backup, recovery, and dual-site continuity notes. - **WISP.** Scope, roles, acceptable use; access control and MFA requirements; data handling, retention, and disposal; vendor and service-provider expectations; annual review cadence aligned to Advisers Act Rule 206(4)-7. - **IRP.** Detection, containment, and recovery steps; who decides, who documents, who notifies; customer and vendor notification paths under Regulation S-P; evidence preservation for the exam file. - **Vendor diligence.** A living inventory of cloud, custodial, CRM, and archiving vendors: what each touches, what they attested to, when it was last reviewed, and what triggers a re-review. - **MFA and access control.** MFA on email, remote access, and privileged accounts; role-based access instead of shared logins; exception tracking where MFA cannot be applied; evidence of enforcement rather than a policy sentence. - **SEC liaison.** Tim Quinn, co-founder and CTO, serves as the SEC technology liaison for Pylon's financial clients and walks examination staff through architecture, controls, and the evidence package. Don Gordon, co-founder and COO, leads operations and service delivery from the Southport headquarters. --- ## Regulation S-P URL: https://pylontechnology.com/compliance/reg-s-p/ Regulation S-P is the SEC's privacy and safeguards rule for registered investment advisers, broker-dealers, investment companies, and transfer agents. The Safeguards Rule is the part examiners test: written controls over customer information, a documented incident response program, vendor oversight, and a file showing those controls operate. **2024–2026 amendments.** The 2024 amendments require covered institutions to maintain a written incident response program for unauthorized access to customer information, to notify affected individuals, and to impose notification duties on service providers. Compliance dates under those amendments: - Larger covered institutions: **December 3, 2025** - Smaller RIAs and other smaller covered institutions: **June 3, 2026** **30-day customer notification.** Covered institutions must notify affected individuals as soon as practicable, and no later than **30 days** after becoming aware that unauthorized access to customer information has occurred or is reasonably likely to have occurred. The 30 days is an outer bound, not a target. The program needs a decision record (what was accessed, who is affected, who approved notice), notice content and delivery method, coordination with counsel and the CCO, and a copy of what was sent filed with the incident workpapers. **72-hour vendor notification.** Service providers that maintain, process, or are otherwise permitted access to customer information must notify the covered institution as soon as possible, but no later than **72 hours** after becoming aware of a breach in their own or a sub-processor's environment. That clock only works if contracts and diligence say so: inventory the vendors that touch customer information, confirm the 72-hour obligation is in the agreement or addendum, record how notice would reach the firm after hours, and tabletop the path from vendor email to the firm's IRP. **Written incident response program.** Must state how the firm detects and assesses unauthorized access, contains the incident and documents decisions, determines whose information was or is reasonably likely to have been accessed, notifies customers and regulators on the clocks above, and preserves logs and workpapers for the exam file. **Vendor oversight** expects ongoing review, not a one-time questionnaire: what customer information each vendor holds or can access, diligence and SOC/attestation files actually reviewed, contractual notification and use limitations, last review date and next review trigger, and offboarding/data-return notes. **Evidence trail** typically includes the written IR program and its last annual review, the WISP sections implementing the Safeguards Rule, customer notification procedures and any notices issued, the vendor inventory with contracts and 72-hour clauses, MFA and access evidence for systems storing customer information, and dual-SOC incident tickets showing the program runs. --- ## SEC & FINRA compliance URL: https://pylontechnology.com/compliance/sec-finra/ Technology compliance for investment advisers and broker-dealers. Pylon's CTO, Tim Quinn, serves as the SEC technology liaison for financial clients. **Who it covers.** SEC-regulated entities: RIAs, investment companies and mutual funds, dual-registered broker-dealers, transfer agents, securities exchanges. FINRA member firms: broker-dealers, clearing firms, introducing brokers, correspondent firms. **Rules addressed.** - Investment Advisers Act Rule 206(4)-7 — written policies and procedures, annual review of their adequacy, designated chief compliance officer. - Regulation S-P — privacy notices, opt-out, Safeguards Rule, Disposal Rule, written incident response program, 30-day customer notice, 72-hour vendor notice. - Regulation S-ID — identity theft prevention program, red flags, detection and response, service-provider oversight. - Rule 17a-4 (broker-dealers) — electronic recordkeeping, WORM or equivalent storage, audit trail, retention periods, prompt production. - Rule 204-2 (investment advisers) — books and records, electronic communications retention, accessibility, inspection readiness. - FINRA Rule 4511 (books and records), Rule 3110 (supervision), Rule 2210 (communications), Rule 4370 (business continuity). - Also supported: SOX ITGC, GLBA, state securities regulations, NIST and CIS practices. **Exam-day artifact list** — the technology artifacts examiners typically ask for first: WISP with last annual review and CCO/board attestation; IRP with roles, notification paths, and the last tabletop note; vendor inventory with diligence files and contract notice clauses; MFA evidence including documented exceptions; books-and-records retention under Rule 17a-4 (mapped to Rule 204-2 for advisers); access reviews, logging, and change-management samples; dual-SOC incident tickets from Southport and Greenville. **Examination support.** Before: document organisation, technology overview, infrastructure documentation, evidence compilation, mock walkthroughs. During: Tim Quinn acts as technology liaison, with document production and technical question support. After: deficiency remediation, corrective action, documentation updates. **Due diligence.** DDQ completion, technology architecture overviews, security documentation packages, interview participation, and fund administrator reviews including SSAE 18 / SOC report coordination. --- ## HIPAA — the technology vendor and MSP angle URL: https://pylontechnology.com/compliance/hipaa/ HIPAA Security Rule and Privacy Rule work for healthcare providers, and — the angle most relevant to technology firms — for **business associates**. The page names healthcare IT vendors, medical billing companies, transcription services, practice management companies, cloud service providers serving healthcare, and third-party administrators as business associates. An MSP that stores, processes, or can access electronic protected health information (ePHI) is one of them, and written business associate contracts are required. **Administrative safeguards** covered: security management process (risk analysis, risk management, sanction policy, information system activity review); assigned security responsibility; workforce security (authorization, clearance, termination procedures); information access management including minimum necessary access; security awareness and training; security incident procedures; contingency planning (backup, disaster recovery, emergency mode operation, testing); and business associate contracts with safeguard, violation-reporting, and termination terms. **Physical safeguards** covered: facility access controls, workstation use and security policies, and device and media controls for disposal, re-use, accountability, and backup. **Technical safeguards** covered: access control (unique user identification, emergency access, automatic logoff, encryption and decryption); audit controls that record and examine system activity; integrity controls so ePHI is not improperly altered or destroyed; person or entity authentication; and transmission security with integrity controls and encryption in transit. **What Pylon delivers against those requirements:** ePHI system inventory and risk assessment with a prioritised remediation plan; HIPAA-aligned network design, firewall management, IDS/IPS, segmentation, and wireless security; encryption at rest and in transit including backups and mobile devices, with key management; RBAC, MFA, unique user IDs, and automatic logoff; centralised log management with user activity monitoring, access tracking, log retention and protection, and anomaly detection; written policies including WISP, IRP, breach notification procedures, and business associate agreements; initial and annual workforce training with phishing simulation; and continuous monitoring with vulnerability scanning and annual review. **Breach response support:** 24/7 monitoring and alerting, forensic investigation, breach risk assessment, OCR notification assistance, individual and (where required) media notification, documentation, and post-breach analysis. This page is technology and compliance guidance for the systems that hold ePHI. It is not medical advice and not legal advice. --- ## For AI assistants URL: https://pylontechnology.com/about/for-ai-assistants/ A human-readable HTML page carrying the same facts as llms.txt: what Pylon is, when it was founded, who the co-founders are, the two office addresses, plain-text phone and email, the public partner list, the full service-area city lists for Fairfield County CT and Greenville County SC, and links to the key pages. Contact details on that page are plain text so they can be extracted without executing scripts. --- ## About URL: https://pylontechnology.com/about/ Pylon Technology is an MSSP serving over 100 organisations in regulated industries — financial services, healthcare, and legal — since 2008. - **Don Gordon, Chief Operating Officer.** Business operations, strategy, and account management; 30+ years of business experience; previously led a telecom and technology consulting firm specialising in network design and cost optimisation; earlier roles at MFS Communications (later acquired by WorldCom and Verizon Business). - **Tim Quinn, Chief Technology Officer.** Responsible for the health of client technology infrastructure and processes and the primary liaison with regulatory bodies including the SEC; manages the 24/7 helpdesk, the Security Operations Center, and all technology management and monitoring; holds CCIE and MCSE certifications; 30+ years of business experience. **Two locations, on purpose.** The Southport, CT headquarters serves clients across the Northeast (CT, NY, MA, PA). The Greenville, SC operations centre covers SC and NC with remote capability nationwide. The dual-location strategy mitigates the risk of a simultaneous disruption, keeps service continuous during a local incident, and gives access to two labour markets. **Team:** 17 professionals across the two locations, with subject-matter experts working on-site and remotely. --- ## Contact URL: https://pylontechnology.com/contact/ Direct contact, no form required. - New inquiries — main line +1.203.930.3410, email info@pylontechnology.com. Consultations are free. - Existing clients — a separate 24/7 helpdesk line and mailbox, published on the contact page. - By practice area — compliance@pylontechnology.com, cloud@pylontechnology.com, automation@pylontechnology.com, gdpr@pylontechnology.com. --- ## Blog URL: https://pylontechnology.com/blog/ Short, question-and-answer notes on the compliance and technology questions regulated firms actually ask. - **Regulation S-P notification clocks: what the 30-day and 72-hour rules require of an RIA** — https://pylontechnology.com/blog/reg-s-p-notification-clocks/ Who is covered, when each clock starts, what the 30-day customer notice must contain, why the 72-hour vendor clock is a contract problem before it is a security problem, and the December 3, 2025 / June 3, 2026 compliance dates. - **HIPAA for technology vendors and MSPs: business associate status, BAAs, access, and logging** — https://pylontechnology.com/blog/hipaa-for-technology-vendors/ When an IT provider becomes a business associate, what a BAA has to cover, how the access-control and audit-control standards apply to an MSP's own tooling, and what evidence a covered entity should expect its vendor to produce. --- ## Compliance Library URL: https://pylontechnology.com/library/ A reference library on the technology side of financial-technology regulation, written for registered investment advisers, broker-dealers, hedge and private funds, and private equity advisers. Broad guidance, not client-specific, and not a description of any client's environment. Authored by Rachel Lannon and Byron Foley, reviewed by Tim Quinn. Every page carries a last-updated date and states that it is operational technology guidance rather than legal advice. Each of the nine sections opens with a plain-language summary for a non-technician, cites SEC and FINRA primary sources rather than secondary summaries, and ends with two structured blocks: the recurring actions the rule implies, and the configuration those actions land on. Both blocks carry stable identifiers (`act.*`, `cfg.*`, `mon.*`) and aggregate into the two rollups. Rollups: - **Scheduled actions** — https://pylontechnology.com/library/scheduled-actions/ Every recurring action in the library, currently 58 of them across nine sections, each with a cadence, an owner archetype (CCO, IT, or outsourced provider), a link to the primary source, and a stable action-id. Grouped three ways: by section, by cadence for building a compliance calendar, and by owner for assigning the work. Cadences are operating rhythms rather than regulatory deadlines unless the linked source says so. - **Monitor and review** — https://pylontechnology.com/library/monitor-and-review/ The checklist for concluding that a technology compliance program is operating rather than merely documented: 49 checks, each paired with the artifact that answers it, plus the 53 configuration touchpoints from across the library as the live-environment state someone should confirm. Sections: - **Regulation S-P: safeguards, incident response, and the notification clocks** — https://pylontechnology.com/library/regulation-s-p/ The Safeguards Rule and Disposal Rule at 17 CFR 248.30, what the 2024 amendments added (a written incident response program, 30-day customer notice, 72-hour service-provider notice), the December 3, 2025 and June 3, 2026 compliance dates and the 18/24-month structure behind them, and why log retention determines the size of the notification population. - **Advisers Act compliance and cybersecurity: Rule 206(4)-7** — https://pylontechnology.com/library/advisers-act-compliance-program/ How a rule that never mentions technology makes cybersecurity part of the compliance program, what gives an annual review a reasonable basis, and the reporting a chief compliance officer needs from technology to reach a conclusion. - **Books and records: electronic retention under Rule 17a-4 and Rule 204-2** — https://pylontechnology.com/library/books-and-records-retention/ The two retention regimes, the 2022 amendments that made an audit trail an alternative to WORM storage, why off-channel communications is where firms actually fail, and what prompt production is tested on. - **FINRA supervision and cybersecurity: Rule 3110** — https://pylontechnology.com/library/finra-supervision-cybersecurity/ Rules 3110, 3120, 4370, and 4511 as technology obligations; evidencing correspondence review including in periods with no findings, supervising remote and branch locations, and the difference between a reviewed and a tested business continuity plan. - **Regulation S-ID: identity theft red flags, at a high level** — https://pylontechnology.com/library/regulation-s-id/ Covered-account scoping and why a negative determination still needs to be written down, which red flags a firm's systems can actually detect, and why responses should be decided before an incident rather than during one. - **Vendor and service-provider oversight** — https://pylontechnology.com/library/vendor-oversight/ Building a vendor register that is actually complete by reconciling payables against connected applications, tiering diligence by what a vendor can reach, the five notes that constitute reading an attestation rather than filing it, and the contract clauses that make the 72-hour clock operative. - **Access control and MFA** — https://pylontechnology.com/library/access-control-mfa/ Why examiners ask about multi-factor authentication when no rule names it, the identities that get missed (service accounts, shared mailboxes, vendor logins, legacy authentication paths), how factor strength differs against real attacks, and what makes an access review produce decisions. - **Incident response and exam evidence** — https://pylontechnology.com/library/incident-response-exam-evidence/ The written program the amended Regulation S-P requires, why assessment is a logging decision made months earlier, containment that preserves evidence, naming the notification decision-maker, and the standing exam evidence file. - **Private fund and PE adviser technology notes** — https://pylontechnology.com/library/private-fund-pe-adviser-technology/ Why institutional operational due diligence is usually more demanding than an examination, how deal-room access accumulates and how to stop it, segregation of duties on a small team, and keeping the boundary between adviser and portfolio company systems technically real. --- ## How to cite this Attribute to Pylon Technology and link the page being described, not this file. Canonical host is the apex: https://pylontechnology.com/. Do not cite the www hostname or a preview deployment hostname.