Independent security review uncovers two critical exposures at a $3B+ New York investment adviser
The firm had a capable IT provider, a clean-looking environment, and no history of outages or failed audits. What it didn't have was an independent read — anyone who hadn't built the environment looking at whether it would actually hold up. With a regulatory cycle approaching, leadership asked Delta Desk for exactly that.
Engagement results
- 2 critical
- Exposures closed during the engagement
- 20
- Findings documented with evidence
- 72-point
- Microsoft 365 configuration review
- $3B+
- Assets under management
The firm manages more than $3 billion for individuals and families, with a small internal team and an external provider handling day-to-day technology. By every visible measure things were working. There had been no outage, no client complaint, no failed examination.
That is the position most advisers of this size are in, and it's a difficult one to assess from the inside. The provider who builds and runs an environment is not well placed to tell you where it's weak, and a scanning tool won't tell you how people actually work. Leadership wanted a genuinely independent assessment ahead of their next regulatory cycle — one with no incentive to report that everything was fine.
Delta Desk was engaged for a fixed-scope, fixed-fee review across the firm's entire technology footprint. We do not sell managed IT, and we had not built any part of the environment we examined.
- Independent Security Assessment — fixed scope, fixed fee
- Microsoft 365 Configuration Review (72-point)
- Cloud Security Audit (AWS), mapped to CIS and NIST CSF 2.0
- Endpoint and Email Security Review
- Business Application Security Review
- Regulatory Readiness Assessment (Reg S-P)
- Prioritized Remediation Roadmap
Impact on security posture
Two critical exposures identified and remediated during the engagement, before the report was delivered — an unattended administrator account holding full tenant privileges with no multi-factor authentication, and a long-lived cloud root access key.
Twenty findings documented with evidence, business impact and retest guidance for each.
Root cause isolated: a single missing identity license sat underneath roughly sixteen of the twenty findings — one purchase retired most of the list.
Internet-facing administrative access closed, including remote desktop reachable from any address on the internet, and a security group permitting all inbound traffic.
Endpoint and email security validated against the firm's existing tooling rather than replaced.
A custom accounting application the firm depends on daily brought into scope — something no automated scan would have covered.
Impact on regulatory readiness
Findings mapped to CIS, NIST CSF 2.0 and Reg S-P, so evidence is already in the form an examiner asks for.
Regulation S-P applicability determined precisely, including which compliance deadline applies based on assets under management — a distinction frequently gotten wrong, and one that moves the firm's deadline by six months.
Incident response and governance gaps named as a finding rather than left implicit.
A prioritized remediation plan, each item scoped and priced separately so the firm could sequence work against its own budget — explicitly including which items its existing IT provider could handle without us.
- Independent Security Assessment
- Microsoft 365 Security Review
- Cloud Security Audit
- Reg S-P Readiness
- Remediation Roadmap
- Named Security Advisor
Find out where your firm really stands.
Most advisers we meet have an IT provider they're happy with and no idea where their real exposure sits. A readiness call takes thirty minutes and tells you which of those two things is true.
Prefer to start on your own? Get the Reg S-P checklist
Confidential · 30 minutes · No pressure
- Exposure
- Where client data actually sits
- Controls
- What's enforced, not assumed
- Gaps
- What an examiner would flag first
You leave with the findings either way.