Institutional-grade security for a nine-person firm answering to two regulators
A nine-person firm carries the same regulatory weight as a nine-hundred-person one. This adviser is registered with the SEC and operates as a commodity pool operator and trading advisor, putting it under NFA and CFTC oversight at the same time. Delta Desk runs its entire security program — and re-tests that program against federal baselines rather than assuming it still works.
Engagement results
- 18
- Endpoints under continuous management
- 2
- Regulators, one security program
- $1.4B
- Assets under management
- Since 2023
- Full stack operated by Delta Desk
Most technology providers treat a nine-person firm as a small business. This one isn't. Dual registration means two regulators, two sets of recordkeeping expectations, and two examination regimes — Regulation S-P on the SEC side, NFA information-systems security requirements on the other. The obligations don't scale down with headcount.
The firm needed a security program built to that standard without hiring a security team to run it. Delta Desk has operated the full stack since 2023: email security, endpoint detection and response, device and patch management, identity and access controls, data loss prevention, security awareness training, and helpdesk.
The part that matters most isn't the deployment. It's what happens afterward.
- Managed Email Security and Threat Protection
- Security Awareness Training and Phishing Simulation
- Managed Endpoint Detection and Response
- Device Management and Patch Management
- Identity and Conditional Access Controls
- Data Loss Prevention
- Continuous Baseline Conformance Testing (CISA benchmarks)
- Managed Helpdesk
Impact on security operations
18 endpoints under continuous management, with patch policy verified device by device rather than reported in aggregate.
A full CISA Microsoft 365 baseline conformance assessment run against the live tenant, testing the environment against the same benchmarks the US government applies to federal agencies — producing a prioritized remediation list now being worked.
Patch-compliance anomalies investigated to root cause instead of escalated on face value. Three devices reporting low compliance turned out not to be a patching failure at all: every outstanding update was already approved with installation scheduled, and the recurring "missing" item across the fleet was the Windows Malicious Software Removal Tool — a monthly cleanup utility, not a security patch. The real issue was operational: laptops kept powered off never picked up the cycle.
End-of-life hardware identified and separated from the active fleet as a distinct replacement track, so it stops distorting the compliance picture.
Identity and licensing reconciled across the tenant, resolving discrepancies between contracted and actual seat counts and surfacing stale duplicate and guest accounts for cleanup.
Impact on regulatory readiness
A security program mapped to both regulatory regimes — SEC Regulation S-P and NFA information systems security requirements — rather than to one and hoping it covers the other.
Configuration evidence captured against a named public standard, so the answer to "how do you know your tenant is configured correctly" is a benchmark result rather than an assurance.
Phishing simulation and security awareness training delivered on a recurring basis, with completion evidence retained.
Documented coverage across the stack, so examination and due-diligence questions are answered from records rather than reconstructed under deadline.
- Managed Email Security
- Managed Endpoint Detection & Response
- Patch Management
- Security Awareness Training
- Identity & Access Management
- Baseline Conformance Testing
Find out where your firm really stands.
Most advisers we meet have an IT provider they're happy with and no idea where their real exposure sits. A readiness call takes thirty minutes and tells you which of those two things is true.
Prefer to start on your own? Get the Reg S-P checklist
Confidential · 30 minutes · No pressure
- Exposure
- Where client data actually sits
- Controls
- What's enforced, not assumed
- Gaps
- What an examiner would flag first
You leave with the findings either way.