Skip to content
Tidebreak Advisory

For RIAs, broker-dealers, and trust companies

An assessment your CCO can read.

Tidebreak performs a practitioner-grade assessment of your IT environment, mapped to the security framework your auditors and carriers already recognize and to the FTC Safeguards, SEC Reg S-P, and NYDFS 500 obligations your compliance program already carries.

CIS CONTROLS v8.1.2 × FTC SAFEGUARDS RULE

What the rule actually asks for

The FTC Safeguards Rule at 16 CFR Part 314 defines the core obligation for most RIAs and broker-dealers: a written information security program, a qualified individual, a written risk assessment, and eight specific safeguard categories. SEC Reg S-P's 2024 amendments overlay an incident-response program and a 30-day customer-notice requirement (with tiered compliance dates). For New York-licensed firms, NYDFS 23 NYCRR 500's second amendment adds governance and continuous monitoring requirements that go beyond what the federal rules require. Your CCO tracks all of this. What she needs from a practitioner is a readable, defensible map of the environment against each applicable obligation.

Where the Safeguards Rule asks for accountability

The Safeguards Rule is unusually specific about accountability, and that specificity is where firms tend to fall short. The rule names a qualified individual who is responsible for the information security program, and it asks that person to base the program on a written risk assessment that identifies reasonably foreseeable risks and the safeguards that address them. The eight categories (access controls, data inventory, encryption, secure development, multifactor authentication, disposal, change management, and monitoring) are not a checklist to be marked present; they are positions the qualified individual has to be able to defend. A program that recites "industry best practices" without mapping a specific control to each category is a program that has not done the work the rule contemplates. A practitioner reading against CIS Controls v8.1.2 turns each of those categories into a tested observation the qualified individual can sign with confidence rather than hope.

The overlays raise the stakes rather than complicate them. Reg S-P's 2024 amendments add an incident-response program and a customer-notification obligation, which means the firm now has to demonstrate not only that it protects customer information but that it can detect, respond to, and disclose a compromise on a defined clock. NYDFS 500's second amendment, for New York-connected firms, layers in governance expectations, senior-officer certification, and continuous monitoring that go past the federal baseline. Each overlay assumes the firm has an independent, current reading of its environment to build on. The CCO who walks into an examination with a framework-mapped assessment in hand is answering questions the examiner has not finished asking; the one without it is reconstructing the program under examination pressure.

What the CCO receives

What the CCO receives is a reading organized the way the rule is organized. Findings map to the Safeguards Rule's eight categories, carry the CIS Controls v8.1.2 safeguard each one implicates, and flag the Reg S-P or NYDFS 500 overlay where it applies, so the document reads as a compliance-program artifact rather than a technical report that needs interpretation. We sample the controls most likely to fail under examination pressure, document why we sampled there, and reconcile what the environment shows against what the IT vendor reports. The independence is the point: because the qualified individual signs the §314.4(b) risk assessment, that person needs work performed by someone who does not run the environment to sign on top of. We provide that independent input. We do not sign the assessment for the firm, and we do not stand in for the examiner or the compliance consultant.

Worked example

Representative finding

"Industry best practices" ISP language with no specific control map

CIS Safeguard 14.3 Security Awareness Program · FTC Safeguards §314.4(e) Employee Training

The RIA's written information security program referenced "industry best practices" and "reasonable safeguards" but mapped no specific controls to the Safeguards Rule's eight categories. The annual written risk assessment under §314.4(b) had been performed by the firm's IT vendor, not the qualified individual, and was not signed. No documented basis for encryption exceptions under §314.4(c)(3) existed.

This is the single most common FTC Safeguards finding and it is the one most likely to be cited in a first examination or a first incident. The remediation is procedural, not technical, and remediates quickly, if someone has mapped the specifics.

What Tidebreak does, and what it does not

A Tidebreak assessment delivers an Executive Report your CCO can forward to your examining authority and a Full Assessment Report your IT provider can remediate against. The methodology is documented procedurally and maps directly to the Safeguards Rule categories, with Reg S-P and NYDFS 500 overlays where applicable. See the methodology

Tidebreak is independent. Tidebreak does not perform the §314.4(b) written risk assessment that your qualified individual is obligated to sign, is not your compliance consultant or SEC examiner, and is not your IT provider. We perform a practitioner-grade assessment of your IT environment. Our findings inform your compliance program; they do not replace it.

Why this matters

For a financial-services firm, the security posture is a regulatory exposure, a coverage question, and a client-confidence question at once. An SEC examiner who finds a written risk assessment authored by the firm's own IT vendor, unsigned by the qualified individual, has found the kind of deficiency that drives a deficiency letter and shapes the tone of the rest of the examination. A cyber carrier underwriting an RIA prices the maturity of the information security program directly into the premium and the exclusions. Institutional clients and their consultants now run operational due diligence that asks for exactly this evidence before they allocate or stay allocated, and the firm that can produce an independent, framework-mapped reading clears that diligence instead of stalling in it. The qualified individual carries personal accountability for the program, and a partner-level or principal-level exposure that surfaces in an examination or after an incident does not stay contained to the IT line item. An independent assessment is how the firm gives its qualified individual something defensible to sign and its examiners something credible to read.

Who runs the assessment

We assess MSPs. I used to run one.

Jeff White has spent twenty-five years in the IT business. Enterprise infrastructure architecture. Eight years at Microsoft Consulting Services. Most recently, VP of Engineering Services at a mid-market MSP, where he built out the service delivery organization and a 24/7 security operations center from the ground up.

Now he works for you, not your provider. Tidebreak exists to give firms like yours a read most don't have a way to get: an independent look at whether the IT you pay for is actually the IT you're getting.

VP Engineering Services, MSP · 8 years Microsoft Consulting Services · Azure Solutions Architect Expert · Assessments mapped to CIS Controls v8.1.2 and NIST CSF 2.0

Schedule a scoping conversation