Networking
We design, run, and monitor the whole path: circuits and SD-WAN across every office, firewalls and segmentation, wireless, always-on remote access, and the dedicated links into brokers, prime brokers, and market-data providers. On a trading path, latency is treated as an incident rather than a ticket.
- Circuits, SD-WAN & carrier management across every office
- Next-generation firewall, segmentation & zero-trust access
- Wireless, VPN & always-on remote connectivity
- Dedicated broker, prime-broker & market-data links
- Latency, jitter & packet-loss baselining on trading paths
- Office build-outs, moves & new-location standups
Agents baseline every link continuously and raise the carrier ticket with the trace already attached the moment a path degrades, typically before the desk notices.
Server & compute
Windows and Linux estates, virtualization, Azure and AWS, and the application servers behind the OMS, PMS, research, and accounting stack. Capacity and performance are reviewed as a program rather than chased when something slows down.
- Windows & Linux server estate, on-premise and cloud
- Virtualization, Azure & AWS workloads
- OMS, PMS, research & accounting application hosting
- Capacity, performance & rightsizing reviews
- Build standards, hardening & configuration baselines
- Lifecycle, refresh & decommissioning
Capacity and performance drift are caught and right-sized before they surface to a user as a slow application.
NOC & monitoring
Every managed system is watched from our own operations centers, not a monitoring vendor's. Coverage is reconciled against the asset record, so a system that is not being watched shows up as a gap rather than staying invisible until it fails.
- 24/7 monitoring across every managed system
- Follow-the-sun operations centers, staffed in-house
- Coverage reconciled against the CMDB
- Threshold and anomaly alerting per system class
- Escalation paths agreed per firm, not per vendor default
Agents triage the alert, correlate it against the rest of the estate, and clear the noise before a human is paged.
New York · 12:00 – 24:00 UTCLondon · 06:00 – 18:00 UTCSingapore · 22:00 – 10:00 UTC
Under watch
8 domains · every managed system
Latency, jitter, loss, failover
per link
Tunnel state, throughput, sessions
per device
CPU, memory, disk, services
per host
Job state, RPO drift, restore tests
per job
Service health, sign-in failures
per tenant
Market data & trading apps
Feed health, session state
per session
AP health, client density, RF
per site
Disk, patch state, agent health
per device
1.9M
Checks executed
per day
3,400↓
Threshold events
deduped
2,780↓
Auto-remediated
by agents
589↓
Engineer-actioned
in-house NOC
31↓
Raised to the firm
with context
Illustrative daily volumes across the RFA client base, shown to convey scale and ratio rather than as a reported metric.
CMDB & asset intelligence
Every device, host, circuit, license and cloud resource we manage is a record with an owner, a lifecycle stage, and its dependencies. It is not filing: patch rings, monitoring coverage, and diligence evidence are all derived from it, so a gap in the record is a gap in the service.
- Endpoints, servers, network devices & circuits
- Cloud resources tagged to application and cost owner
- Software estate, entitlements & renewal dates
- Dependencies, so the blast radius of a change is known
- A named business owner per system
- Exports straight into a DDQ or examination response
Discovery reconciles the record continuously, so the inventory reflects the estate today rather than at the last audit.
Patch management
Patching runs on rings, scheduled around your busiest hours rather than a vendor's maintenance window. Each ring has to report clean before the next one starts, and the whole run is evidenced for the examiner who asks how you know you are patched.
- Ring-based rollout, scheduled around operating windows
- Automatic hold when a ring reports failures
- Third-party application patching, not just OS
- Exception tracking with a documented owner and date
- Compliance reporting per ring and per system
Rings advance automatically on clean telemetry and hold themselves back the moment failures appear, without waiting for someone to notice.
RFA's own estate
Every patch lands on us before it lands on a client.
Day 0IT, operations & volunteer users
A representative slice of the firm, deliberately chosen.
Day 2General user population
Deployed after two clean days in pilot, outside market hours.
Day 5Trading, OMS & market-data hosts
Never inside a trading session. Change-controlled, with a rollback rehearsed first.
Scheduled weekend< 24 hrs
Critical CVE to canary ring
98.6%
Estate compliance, rolling 30 days
0
Trading-hours patch windows
100%
Exceptions with a compensating control
Compliance and timing figures are illustrative of the standard the program is run to; per-client targets are set in the service agreement.
Service desk & end-user
A service desk staffed by named RFA engineers who know your firm, reachable in the channel your people already use. Joiners, movers, and leavers run as managed workflows, and a vCIO owns the roadmap rather than reacting to it.
- Named engineers assigned to your firm
- Teams and Slack, not only a ticket portal
- Onboarding, offboarding & access changes
- Hardware procurement, imaging & lifecycle
- vCIO roadmapping and budget planning
Most issues are resolved before a ticket exists; the ones that reach an engineer arrive already diagnosed.