Compliance — New York / Tri-State
IT compliance services for New York businesses
If a regulator, a client, or an insurer can ask you to prove how your systems are secured, compliance is part of your IT — not a binder on a shelf. Stedholm builds and operates controls so the proof exists before anyone asks for it.
Controls that produce evidence
The regimes that govern New York businesses ask overlapping questions: who can access what, how do you know, what happens when something breaks, and can you show your work. Most compliance failures are not exotic — they are ordinary controls that were enabled once and never operated, so when the examiner, the auditor, or the claims adjuster asks for the record, there is no record.
We build controls to be evidenced, not just switched on. MFA enforcement reports, access-review logs, backup restore tests, training completion, incident-response rehearsals — filed as they happen, mapped to the requirement they satisfy. When a filing deadline or a questionnaire arrives, the answer is retrieval, not archaeology.
One boundary, stated plainly: we prepare and operate controls; we are not a law firm or an auditor. We do not issue legal opinions or attestation reports — we build the program those professionals examine, and we sit with you while they examine it. The judgment layer above the daily work is our vCISO and strategic IT practice.
01 — Regimes we operate in
Five regimes, one operating discipline
The control set overlaps far more than the paperwork suggests. Operate it once, well, and evidence it for each regime that binds you.
Financial services
NYDFS 23 NYCRR 500
Universal MFA, asset inventory, 72-hour incident reporting, and the April 15 certification — operated and evidenced for licensed New York financial firms.
Healthcare
HIPAA + NY SHIELD
Risk analysis, safeguards, and BAAs — plus the New York layers that hospital systems now push down to every affiliated practice.
CPAs & advisors
FTC Safeguards Rule
Nine required program elements for firms that rarely realize they are covered: CPAs, tax preparers, advisors, insurance agencies, dealerships.
Defense suppliers
CMMC 2.0
NIST 800-171 remediation and assessment preparation for Tri-State manufacturers and subcontractors — the deadline is contractual now.
B2B firms
SOC 2 readiness
When enterprise clients make SOC 2 a condition of the deal: scoping, controls mapping, evidence collection, and preparation for a CPA-firm audit.
Cyber insurance: the one regime everyone is in
Not every business answers to DFS or the FTC. Nearly every business renews a cyber-insurance policy — and underwriters have stopped taking answers on faith. Applications now ask whether MFA is enforced, whether every endpoint runs detection and response, and whether backups have actually been restored. Carriers verify at renewal, and more painfully, at claim time.
We treat the renewal application as a compliance checklist with a hard deadline. The controls carriers require are the same ones the named regimes require — managed detection and response, hardened identity, tested recovery — so operating them once serves the policy, the regulator, and the business itself.
What carriers commonly require
MFA enforced on email, VPN, remote access, and admin accounts
EDR on every endpoint
Tested, isolated backups
A written, rehearsed incident response plan
Monitoring around the clock, with escalation to an engineer
How we run compliance work
The same sequence for every regime — only the mapping changes.
Map the obligations
Which regimes, client contracts, and insurance terms actually bind you, and what each one demands in controls. Many firms sit under two or three and have only heard of one.
Assess the gap
Current state against those obligations, in a findings document you keep whether or not you hire us.
Remediate in priority order
Deadline-driven and risk-driven, with pricing in writing. The items an examiner or underwriter checks first come first.
Operate and evidence
Controls run as a daily discipline, and the evidence files itself continuously — not in a scramble the week before the deadline.
Certify and renew
We assemble the record behind your filings, audits, and renewal applications: the April 15 certification, audit fieldwork, the insurance questionnaire. You sign with the evidence in front of you.
Common questions
Which compliance regime applies to us?
Usually more than you think. A New York insurance agency can sit under NYDFS Part 500 and the FTC Safeguards Rule at once; a medical practice carries HIPAA, the SHIELD Act, and its hospital system’s requirements. Start from your industry, and we will map the rest in an assessment.
We are covered by more than one regime. Does that double the cost?
No. The underlying controls — identity, MFA, monitoring, backup, training, incident response — overlap heavily across regimes. We operate one control set and maintain separate evidence mappings, which is much cheaper than running parallel programs.
Can you work with our existing IT provider or internal team?
Yes. Compliance and security operations layer cleanly onto a co-managed arrangement: your team or incumbent provider keeps running daily IT, and we add the control operation, evidence, and reporting.
How fast can we get compliant?
It depends entirely on the gap, and anyone quoting a timeline before an assessment is guessing. Typical remediation runs weeks for insurance-readiness items and months for full regime programs — CMMC honestly takes six to twelve. The assessment gives you a real number.
Will you talk to our regulator, auditor, or insurer?
We prepare the technical record and join the conversations where an engineer is useful — exam responses, audit fieldwork, claims documentation. Legal positions stay with your counsel; attestation stays with your auditor. We stay in our lane, which is the part they examine.
Know where you stand before someone asks.
A scoped assessment maps your obligations to your actual controls. You keep the findings either way.