Home » Industries We Serve » Financial Services

Industries — Financial Services

Cybersecurity and managed IT for New York financial services firms

Independent RIAs, family offices, small funds, broker-dealers, and insurance agencies carry NYDFS and SEC obligations sized for institutions — without institutional headcount. We run the controls and produce the evidence.

Part 500 does not scale down. Your provider has to.

NYDFS 23 NYCRR 500 applies by license, not by size. If you hold a New York banking, insurance, or financial services license, you certify compliance every April 15 — and since November 2025, the MFA requirement applies without the old small-business exemption. Add the 72-hour incident notice, asset inventory duties, and the requirement to designate a CISO, and a fifteen-person firm is operating a program written for a bank.

The SEC and FINRA layer their own expectations on top: the amended Regulation S-P puts advisers and broker-dealers on a compliance clock through mid-2026 for incident response and customer notification, and examiners ask for the same artifacts insurers do — enforced MFA, EDR coverage, tested backups.

The finance-specialist providers in this market anchor on large funds. Stedholm is built for the firms below that line: same obligations, right-sized delivery. See how we approach NYDFS Part 500, how CPA firms face the parallel FTC Safeguards Rule, and the other industries we serve.

  • Built for

  • Independent RIAs

  • Family offices

  • Funds below institutional scale

  • Broker-dealers

  • Insurance agencies and brokerages

  • Fintech firms holding NY licenses

What we run for financial firms

Each control is operated to be evidenced — for the April 15 certification, an SEC exam, or your insurer’s renewal.

  • Identity and access control

    Entra ID hardening, enforced phishing-resistant MFA, and access reviews under Microsoft 365 management — the control NYDFS now requires without exemption.

  • Managed detection and response

    MDR across endpoints and identity, monitored around the clock by our tooling, with engineer escalation.

  • Vulnerability management and testing

    Continuous vulnerability management plus coordinated penetration testing to satisfy Part 500’s testing requirements.

  • vCISO and certification support

    A named security lead through strategic IT who maintains your risk assessment, policies, and the evidence file behind each annual certification.

  • Backup and recovery

    Immutable, tested backup and recovery — the artifact both DFS and your insurance carrier ask about first.

  • Day-to-day managed IT

    Help desk, endpoints, and vendor management from the same team that runs your security controls.

Common questions from financial firms

Does NYDFS Part 500 really apply to a firm our size?

If you hold a license under the New York Banking, Insurance, or Financial Services Law, yes — coverage follows the license, not headcount. Limited exemptions exist for the smallest firms, but they narrowed under the Second Amendment, and the MFA exemption ended in November 2025. We help you document which provisions apply, working alongside your counsel.

Can Stedholm act as our CISO?

Part 500 permits the CISO function to be fulfilled by a third party. Our vCISO service covers the designation, the annual report to your senior governing body, and the program work behind it. We are engineers, not lawyers — regulatory interpretation stays with your counsel.

We already have an IT provider we like. Can you add just the security layer?

Yes. Co-managed engagements where we run security operations next to an incumbent IT team or provider are a standard model for us, not an exception.

Get your Part 500 posture in writing.

An assessment maps your current controls against what you will certify to in April — you keep the findings either way.