Engagement Menu

Two Engagements.
One Path to Audit-Readiness.

Iron Bridge serves registered investment advisers through two complementary engagements: a one-time assessment that establishes an objective baseline before an SEC exam, and an ongoing governance retainer that maintains a permanent state of examination-readiness. Each is built to produce examiner-ready work product.

The Engagements

Deliverables &
Scope by Tier

Both tiers pair continuous technical scanning with formal governance reporting — translating technical findings into the business-risk language your board and your examiner expect.

Tier I
The SEC Readiness Assessment
One-Time Project
For
RIAs seeking an objective baseline before an SEC exam, or firms wanting to evaluate their current MSP's performance against an independent standard.
Outcome
Immediate visibility into your risk profile and a prioritized remediation roadmap — an exact punch list you can act on or hand to your IT provider.
Toolset
Vulnerability & M365 Scanning Gap Reporting & Framework Mapping
Engagement Fee
$2,500$5,000
One-time, fixed-scope project
Final fee is set after a brief scoping call and depends on firm size, environment complexity, and the systems in scope.
What You Receive
01

Technical Vulnerability Scan

Full external and internal network scanning to identify unpatched software, misconfigurations, and open ports across your environment.

02

M365 & Cloud Configuration Audit

Automated review of your cloud environment against CIS benchmarks — critical for RIAs, since nearly all run on cloud infrastructure.

03

Framework Gap Analysis

A formal governance review mapped directly against the NIST Cybersecurity Framework and SEC Regulation S-P requirements.

04

Executive Summary & Remediation Roadmap

A polished, client-ready report translating technical gaps into business risk — giving you an exact punch list to execute against.

Tier II
The Core Cyber Governance Retainer
Ongoing — Annual Contract
For
Small and emerging RIAs (under $250M AUM) that rely on an MSP for daily IT but lack internal security leadership, formal compliance policies, or documented proof of governance.
Role
Your permanent governance wrapper — we run the compliance program, handle policy orchestration, and hold your existing IT providers accountable.
Toolset
Continuous Monitoring GRC, Policy & Evidence Collection
Monthly Retainer
Starting at
$1,200/mo
Annual contract · billed monthly
Retainer engagements are structured to fit the operational budget of a small registered adviser — not a bulge-bracket compliance department.
What You Receive
01

Continuous Vulnerability Management

Regular technical scanning of infrastructure and cloud applications to confirm your MSP is actively patching and maintaining security posture.

02

Policy Generation & Upkeep

Custom-tailored Information Security Policies, Incident Response Plans, and Acceptable Use Policies, housed and version-controlled in our centralized GRC platform.

03

Vendor Due Diligence Management

Automated tracking and review of your third-party vendors — custodians, CRM platforms, and the MSP itself — to satisfy strict SEC due diligence mandates.

04

Quarterly SEC Posture Reports

Executive-level risk and compliance dashboards showing continuous improvement, ready to hand directly to an examiner during a sweep.

05

vCISO Advisory Hours

Monthly strategy calls with your Chief Compliance Officer, board presentation materials, and ad-hoc guidance for security questionnaires.

06

Examiner-Ready Evidence Library

A continuously maintained record of policies, assessments, and remediation activity — so the documentation an examiner requests already exists.

How They Work Together

From Assessment
to Ongoing Governance

The two tiers are designed to connect. The assessment surfaces what needs attention; the retainer executes the roadmap and keeps your firm in a permanent state of audit-readiness.

Step One

Establish the Baseline

The SEC Readiness Assessment gives you an objective, independent picture of your current risk profile — including gaps your firm may not have known existed.

Step Two

Receive the Roadmap

At the close of the assessment you receive a prioritized remediation roadmap — a clear, ordered punch list translating technical findings into business decisions.

Step Three

Maintain Readiness

The Core Cyber Governance Retainer executes that roadmap and sustains it — continuous monitoring, living policies, and examiner-ready reporting, quarter after quarter.

Begin

Start With a Clear Baseline

Whether you need an objective assessment before your next exam or a permanent governance program, the first step is a short conversation about your firm.

Schedule a Consultation