Delta Desk
Case studies
Project engagementFamily office

Independent security review uncovers two critical exposures at a $3B+ New York investment adviser

The firm had a capable IT provider, a clean-looking environment, and no history of outages or failed audits. What it didn't have was an independent read — anyone who hadn't built the environment looking at whether it would actually hold up. With a regulatory cycle approaching, leadership asked Delta Desk for exactly that.

Engagement results

2 critical
Exposures closed during the engagement
20
Findings documented with evidence
72-point
Microsoft 365 configuration review
$3B+
Assets under management
Overview

The firm manages more than $3 billion for individuals and families, with a small internal team and an external provider handling day-to-day technology. By every visible measure things were working. There had been no outage, no client complaint, no failed examination.

That is the position most advisers of this size are in, and it's a difficult one to assess from the inside. The provider who builds and runs an environment is not well placed to tell you where it's weak, and a scanning tool won't tell you how people actually work. Leadership wanted a genuinely independent assessment ahead of their next regulatory cycle — one with no incentive to report that everything was fine.

Delta Desk was engaged for a fixed-scope, fixed-fee review across the firm's entire technology footprint. We do not sell managed IT, and we had not built any part of the environment we examined.

The solution
  • Independent Security Assessment — fixed scope, fixed fee
  • Microsoft 365 Configuration Review (72-point)
  • Cloud Security Audit (AWS), mapped to CIS and NIST CSF 2.0
  • Endpoint and Email Security Review
  • Business Application Security Review
  • Regulatory Readiness Assessment (Reg S-P)
  • Prioritized Remediation Roadmap
Outcome

Impact on security posture

  • Two critical exposures identified and remediated during the engagement, before the report was delivered — an unattended administrator account holding full tenant privileges with no multi-factor authentication, and a long-lived cloud root access key.

  • Twenty findings documented with evidence, business impact and retest guidance for each.

  • Root cause isolated: a single missing identity license sat underneath roughly sixteen of the twenty findings — one purchase retired most of the list.

  • Internet-facing administrative access closed, including remote desktop reachable from any address on the internet, and a security group permitting all inbound traffic.

  • Endpoint and email security validated against the firm's existing tooling rather than replaced.

  • A custom accounting application the firm depends on daily brought into scope — something no automated scan would have covered.

Impact on regulatory readiness

  • Findings mapped to CIS, NIST CSF 2.0 and Reg S-P, so evidence is already in the form an examiner asks for.

  • Regulation S-P applicability determined precisely, including which compliance deadline applies based on assets under management — a distinction frequently gotten wrong, and one that moves the firm's deadline by six months.

  • Incident response and governance gaps named as a finding rather than left implicit.

  • A prioritized remediation plan, each item scoped and priced separately so the firm could sequence work against its own budget — explicitly including which items its existing IT provider could handle without us.

Services used
  • Independent Security Assessment
  • Microsoft 365 Security Review
  • Cloud Security Audit
  • Reg S-P Readiness
  • Remediation Roadmap
  • Named Security Advisor
Get in touch

Find out where your firm really stands.

Most advisers we meet have an IT provider they're happy with and no idea where their real exposure sits. A readiness call takes thirty minutes and tells you which of those two things is true.

Book a readiness call

Prefer to start on your own? Get the Reg S-P checklist

Confidential · 30 minutes · No pressure

Readiness call30 min
Exposure
Where client data actually sits
Controls
What's enforced, not assumed
Gaps
What an examiner would flag first

You leave with the findings either way.