Industries — Financial Services
Cybersecurity and managed IT for New York financial services firms
Independent RIAs, family offices, small funds, broker-dealers, and insurance agencies carry NYDFS and SEC obligations sized for institutions — without institutional headcount. We run the controls and produce the evidence.
Part 500 does not scale down. Your provider has to.
NYDFS 23 NYCRR 500 applies by license, not by size. If you hold a New York banking, insurance, or financial services license, you certify compliance every April 15 — and since November 2025, the MFA requirement applies without the old small-business exemption. Add the 72-hour incident notice, asset inventory duties, and the requirement to designate a CISO, and a fifteen-person firm is operating a program written for a bank.
The SEC and FINRA layer their own expectations on top: the amended Regulation S-P puts advisers and broker-dealers on a compliance clock through mid-2026 for incident response and customer notification, and examiners ask for the same artifacts insurers do — enforced MFA, EDR coverage, tested backups.
The finance-specialist providers in this market anchor on large funds. Stedholm is built for the firms below that line: same obligations, right-sized delivery. See how we approach NYDFS Part 500, how CPA firms face the parallel FTC Safeguards Rule, and the other industries we serve.
Built for
Independent RIAs
Family offices
Funds below institutional scale
Broker-dealers
Insurance agencies and brokerages
Fintech firms holding NY licenses
What we run for financial firms
Each control is operated to be evidenced — for the April 15 certification, an SEC exam, or your insurer’s renewal.
Identity and access control
Entra ID hardening, enforced phishing-resistant MFA, and access reviews under Microsoft 365 management — the control NYDFS now requires without exemption.
Managed detection and response
MDR across endpoints and identity, monitored around the clock by our tooling, with engineer escalation.
Vulnerability management and testing
Continuous vulnerability management plus coordinated penetration testing to satisfy Part 500’s testing requirements.
vCISO and certification support
A named security lead through strategic IT who maintains your risk assessment, policies, and the evidence file behind each annual certification.
Backup and recovery
Immutable, tested backup and recovery — the artifact both DFS and your insurance carrier ask about first.
Day-to-day managed IT
Help desk, endpoints, and vendor management from the same team that runs your security controls.
Common questions from financial firms
Does NYDFS Part 500 really apply to a firm our size?
If you hold a license under the New York Banking, Insurance, or Financial Services Law, yes — coverage follows the license, not headcount. Limited exemptions exist for the smallest firms, but they narrowed under the Second Amendment, and the MFA exemption ended in November 2025. We help you document which provisions apply, working alongside your counsel.
Can Stedholm act as our CISO?
Part 500 permits the CISO function to be fulfilled by a third party. Our vCISO service covers the designation, the annual report to your senior governing body, and the program work behind it. We are engineers, not lawyers — regulatory interpretation stays with your counsel.
We already have an IT provider we like. Can you add just the security layer?
Yes. Co-managed engagements where we run security operations next to an incumbent IT team or provider are a standard model for us, not an exception.
Get your Part 500 posture in writing.
An assessment maps your current controls against what you will certify to in April — you keep the findings either way.