Small teams, serious obligations, no room for a technology department
Engineering, architecture, insurance, consulting, wealth and investment advisory, association management. Different work, same shape: a dozen or two people, deep client relationships, sensitive files, and no natural owner for technology.
What you are carrying
- Client contracts increasingly carry security and insurance requirements
- Files must remain retrievable years after a project closes
- Staff work from client sites, home and the road
- Growth arrives in steps, and the setup was built for the last step
- Cyber insurance renewals now come with a technical questionnaire
- Firms that are SEC-registered answer to a regulator as well as to their clients
What we do about it
- Controls mapped to whatever your largest client contract actually requires
- Archive and retrieval that works years later, not just this quarter
- Secure access from anywhere without a fragile VPN
- Capacity planning tied to your hiring plan
- Insurance questionnaire support, with evidence attached
- Verified procedures for any payment, distribution or account-detail change
- Retained access, change and log evidence, ready when someone asks for it
- A single roadmap so technology spend is predictable
If you are not sure which category you fall into, you are probably this one. It is also where wealth and investment advisory firms sit. If you are SEC-registered the obligations are heavier and more specific, and the small-firm compliance date for the amended Regulation S-P passed on 3 June 2026 — but the shape of the problem is the same one: a small team, sensitive records, and somebody who wants evidence rather than assurances.
How it usually works
What we find in professional offices
Professional offices get the least specific regulation and the most specific client demands, which is an awkward combination to plan around.
Cyber insurance renewals ask specific technical questions, and the answers you give become part of the policy. An answer given in good faith but wrong is a coverage problem rather than a paperwork one.
How it got that way
Underwriters moved from broad questions to named controls after several loss-heavy years. The form still arrives addressed to whoever signs it, who is rarely the person who knows the answer.
What we do
Before you sign it, ask us what your environment actually does. Knowing which answers are yes is worth more than a fast renewal.
Regulation S-P and S-ID probably do not apply to you. They cover SEC-registered advisers, broker-dealers, investment companies and certain other defined institutions — not professional offices generally.
SEC Regulation S-P (opens in a new tab)How it got that way
The rules are widely cited in security marketing without their scope attached, which is how firms end up budgeting for a requirement they do not have.
What we do
We tell you which rules actually reach you. Several of ours have found the answer is fewer than they were told.
Microsoft 365 is no longer wide open on day one. New tenants get MFA registration, administrator MFA, contextual user MFA and legacy authentication blocked, without anyone turning them on.
Microsoft security defaults (opens in a new tab)How it got that way
Security Defaults arrived quietly and apply to new tenants rather than retroactively, so a tenant created years ago may still be running the old posture while a new one is not. Most security advice has not caught up.
What we do
We work from a written baseline and report drift, because a tenant rarely gets less secure in one step.
Google states plainly that its disaster-recovery backups are not available to restore your data on request. The platform protects itself, not your deleted files.
Google Workspace data protection (opens in a new tab)How it got that way
“The cloud backs itself up” is true of the provider's own infrastructure and was never a statement about customer recovery. The distinction is in the documentation and almost never in the conversation.
What we do
Cloud data gets its own backup with its own restore path, separate from the platform.
Every rule above links to the rule itself rather than to our summary of it. If something here does not apply to your firm, that is worth knowing before you budget for it.
Compared honestly
What a generalist provider brings to professional offices
The firms in this category rarely have a technology owner, so the provider's job quietly includes the thinking as well as the doing.
A generalist
Secures the environment to a general standard.
CY6
Maps controls to whatever your largest client contract actually requires, because that is the standard you will be measured against.
A generalist
Answers the cyber insurance questionnaire on request.
CY6
Tells you what your environment actually does before you sign a form saying it — those answers become part of the policy, and a wrong one is a coverage problem rather than a paperwork one.
A generalist
Sizes the setup for the firm as it is today.
CY6
Sizes it against your hiring plan, because growth in this category arrives in steps and the setup is always built for the last one.
Plenty of generalist providers are good at their job. The distinction here is context, not competence.
Rules in play
What you are likely to be measured against
We are not your compliance counsel, and we will say so. What we do is make sure the technical controls and the evidence behind them stand up when someone asks.
- Client contractual security requirements
- NIST Cybersecurity Framework
- Cyber insurance underwriting requirements
- SEC Regulation S-P, for SEC-registered advisers and other covered institutions
- PCI DSS, where card payments are taken
- State breach-notification law
Not sure where you stand?
Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.
Or call 1-855-966-2967