Skip to main content
CY6Check Your Six

Small teams, serious obligations, no room for a technology department

Engineering, architecture, insurance, consulting, wealth and investment advisory, association management. Different work, same shape: a dozen or two people, deep client relationships, sensitive files, and no natural owner for technology.

What you are carrying

  • Client contracts increasingly carry security and insurance requirements
  • Files must remain retrievable years after a project closes
  • Staff work from client sites, home and the road
  • Growth arrives in steps, and the setup was built for the last step
  • Cyber insurance renewals now come with a technical questionnaire
  • Firms that are SEC-registered answer to a regulator as well as to their clients

What we do about it

  • Controls mapped to whatever your largest client contract actually requires
  • Archive and retrieval that works years later, not just this quarter
  • Secure access from anywhere without a fragile VPN
  • Capacity planning tied to your hiring plan
  • Insurance questionnaire support, with evidence attached
  • Verified procedures for any payment, distribution or account-detail change
  • Retained access, change and log evidence, ready when someone asks for it
  • A single roadmap so technology spend is predictable
Straight answer

If you are not sure which category you fall into, you are probably this one. It is also where wealth and investment advisory firms sit. If you are SEC-registered the obligations are heavier and more specific, and the small-firm compliance date for the amended Regulation S-P passed on 3 June 2026 — but the shape of the problem is the same one: a small team, sensitive records, and somebody who wants evidence rather than assurances.

How it usually works

What we find in professional offices

Professional offices get the least specific regulation and the most specific client demands, which is an awkward combination to plan around.

  1. Cyber insurance renewals ask specific technical questions, and the answers you give become part of the policy. An answer given in good faith but wrong is a coverage problem rather than a paperwork one.

    How it got that way

    Underwriters moved from broad questions to named controls after several loss-heavy years. The form still arrives addressed to whoever signs it, who is rarely the person who knows the answer.

    What we do

    Before you sign it, ask us what your environment actually does. Knowing which answers are yes is worth more than a fast renewal.

  2. Regulation S-P and S-ID probably do not apply to you. They cover SEC-registered advisers, broker-dealers, investment companies and certain other defined institutions — not professional offices generally.

    How it got that way

    The rules are widely cited in security marketing without their scope attached, which is how firms end up budgeting for a requirement they do not have.

    What we do

    We tell you which rules actually reach you. Several of ours have found the answer is fewer than they were told.

    SEC Regulation S-P (opens in a new tab)
  3. Microsoft 365 is no longer wide open on day one. New tenants get MFA registration, administrator MFA, contextual user MFA and legacy authentication blocked, without anyone turning them on.

    How it got that way

    Security Defaults arrived quietly and apply to new tenants rather than retroactively, so a tenant created years ago may still be running the old posture while a new one is not. Most security advice has not caught up.

    What we do

    We work from a written baseline and report drift, because a tenant rarely gets less secure in one step.

    Microsoft security defaults (opens in a new tab)
  4. Google states plainly that its disaster-recovery backups are not available to restore your data on request. The platform protects itself, not your deleted files.

    How it got that way

    “The cloud backs itself up” is true of the provider's own infrastructure and was never a statement about customer recovery. The distinction is in the documentation and almost never in the conversation.

    What we do

    Cloud data gets its own backup with its own restore path, separate from the platform.

    Google Workspace data protection (opens in a new tab)

Every rule above links to the rule itself rather than to our summary of it. If something here does not apply to your firm, that is worth knowing before you budget for it.

Compared honestly

What a generalist provider brings to professional offices

The firms in this category rarely have a technology owner, so the provider's job quietly includes the thinking as well as the doing.

  • A generalist

    Secures the environment to a general standard.

    CY6

    Maps controls to whatever your largest client contract actually requires, because that is the standard you will be measured against.

  • A generalist

    Answers the cyber insurance questionnaire on request.

    CY6

    Tells you what your environment actually does before you sign a form saying it — those answers become part of the policy, and a wrong one is a coverage problem rather than a paperwork one.

  • A generalist

    Sizes the setup for the firm as it is today.

    CY6

    Sizes it against your hiring plan, because growth in this category arrives in steps and the setup is always built for the last one.

Plenty of generalist providers are good at their job. The distinction here is context, not competence.

Rules in play

What you are likely to be measured against

We are not your compliance counsel, and we will say so. What we do is make sure the technical controls and the evidence behind them stand up when someone asks.

  • Client contractual security requirements
  • NIST Cybersecurity Framework
  • Cyber insurance underwriting requirements
  • SEC Regulation S-P, for SEC-registered advisers and other covered institutions
  • PCI DSS, where card payments are taken
  • State breach-notification law

Not sure where you stand?

Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.

Or call 1-855-966-2967