A program that survives the questionnaire.
A vCISO and GRC team that keeps your control environment aligned with SEC, FCA, and NFA requirements. Your organization remains prepared for audits, examinations, and due diligence requests year-round.
Posture you can evidence.
Most firms discover the gaps in their control environment during diligence, when there is no time left to close them. We run the program continuously instead: policies current, risks registered, vendors reviewed, and the evidence pack already assembled when the questionnaire lands.
What's included
- vCISO & virtual security leadership
- Policy creation & framework management
- Vendor due diligence & DDQ support
- Pen testing, tabletop & AI governance
Scored on the way in, scored again every year.
Every engagement opens with a gap analysis across six domains and closes the loop with an annual refresh. The dashed line is the posture the managed stack is built to reach.
Current posture
2.7/ 5
Defined
Target with RFA
4.6/ 5
Optimized
Where the program moves first
Illustrative of a typical opening assessment. Your own scores come out of the gap analysis in the first 30 days.
Thirteen deliverables, not a retainer.
Every line below is scoped, owned, and refreshed on a stated cadence. Nothing here is best-effort advisory time.
Governance
The documented program and who owns it.
04 deliverables
Policy Creation
BCP, IRP, and Infosec Framework, with an annual refresh on every document.
Framework Management
Initial gap analysis plus ongoing maintenance across DORA, GDPR, Cyber Essentials, and NIST CSF.
vCISO Services
Named security leadership accountable for the program, without a full-time hire.
Risk & Compliance Platform
One system of record facilitating vendor DDQ, the risk register, and the policy repository.
Assurance
Evidence that stands up to clients and examiners.
04 deliverables
Cyber Risk Register
Initial assessment plus an annual refresh as the risk picture moves.
Vendor Due Diligence
Third-party review and ongoing monitoring of the vendors holding your data.
DDQ Support
Ten hours of hands-on support answering investor and LP diligence questionnaires.
Due Diligence Readiness Assessment
Initial assessment plus an annual refresh, so you meet diligence already prepared.
Testing
Proof the controls actually hold.
03 deliverables
Vulnerability Management
Continuous scanning, prioritization, and remediation tracking across the estate.
Autonomous Pen Testing
Continuous automated penetration testing in place of a once-a-year point check.
Annual Tabletop Exercise
A facilitated incident simulation that proves the response plan works before it is needed.
AI
Governance for the models your firm is already using.
02 deliverables
AI Governance Framework
Initial policy draft plus an annual refresh, covering acceptable use and model oversight.
GenAI Security & Compliance Platform
Prompt Security monitoring and controlling AI usage: data leakage, prompt injection, and shadow AI.
One control set, every framework it answers to.
Controls are written once and mapped across regimes, so a new framework is a mapping exercise rather than a fresh program.
The outcomes that matter to the business.
Pass client and investor due diligence the first time
SEC / FCA examinations handled with confidence
vCISO leadership without a full-time hire
A living, auditable control environment
Related services
All services →Managed AI
NewHours back for your team, on AI you can govern, secure, and evidence.
Learn more →Managed Cybersecurity
Threats found and contained around the clock, by analysts who work for RFA.
Learn more →Managed IT Services
One team accountable for the network, the servers, and the desk — so your people stop losing days to IT.
Learn more →Let's talk about your
technology needs.
Speak with an RFA advisor about IT, cybersecurity,
AI, and compliance for financial services.