Cybersecurity Basics for Small Financial and Professional Firms in NYC
You hold client PII, you move money on instruction, and your clients' compliance teams are starting to ask you hard questions. Here's the control set that answers all three.
A six-person RIA, a boutique accounting practice, a consulting shop that advises funds, firms like these sit in an uncomfortable spot. You're small enough to have no security staff, but you handle exactly what attackers want: client identities, account details, and the authority to move money. And increasingly, your own clients' due-diligence questionnaires are asking what controls you run, with your answers determining whether you keep the engagement.
Quick framing note: we're an IT provider, not a law firm or compliance consultant. Nothing here is legal or regulatory advice. What we can tell you is which technical controls regulators-adjacent expectations, insurers, and client questionnaires keep converging on, because we implement them for firms like yours across New York City and North Jersey.
Why small financial firms specifically
Three reasons attackers rank you above the bodega and below the bank:
- Wire authority. If your firm can instruct custodians or process payments, one compromised mailbox can redirect six or seven figures. Business email compromise (BEC) losses dwarf ransomware losses year after year in FBI IC3 data, and professional firms are the preferred staging ground.
- Concentrated PII. A 200-client book means 200 sets of SSNs, account numbers, and dates of birth in your files, a better haul per breach than most retailers.
- Implied trust. An email from your domain gets opened. Attackers compromise small firms to phish their larger clients, which is exactly why those clients now audit you.
The expectations bearing down on you
Even firms with no direct regulator face a tightening web: SEC-registered advisers have explicit cybersecurity and incident-disclosure obligations and examiners who ask about them; FINRA publishes pointed small-firm cybersecurity guidance; New York's DFS rules (23 NYCRR 500) cover many financial entities operating in the state; the FTC Safeguards Rule reaches tax preparers and others. Whether each regime technically applies to your firm is a question for your compliance counsel. The practical reality we see: the control set they all gesture at is nearly identical, and it's the same list your cyber-insurance renewal and your clients' vendor questionnaires ask about. Build it once, answer everyone.
The control framework, in priority order
Control 1: Phishing-resistant MFA on identity and money paths
MFA on email and file storage is table stakes. For a financial firm, go further: authenticator-app or hardware-key MFA (not SMS) for any account that can initiate or approve a payment, change wire instructions, or access the custodian portal. Then add conditional access rules that block logins from anonymizing VPNs and unfamiliar geographies. Most of the BEC cases we've remediated began with a successful login that MFA done properly would have stopped.
Control 2: A wire-verification procedure that lives outside email
Not software, procedure, and arguably the highest-ROI control on this page. Any new or changed payment instruction gets verified by phone, to a number you already had on file, before execution. No exceptions for urgency; urgency is the tell. Attackers who own a mailbox will wait weeks for a real transaction, then swap the instructions mid-thread. We walk through the full anatomy of these attacks in our piece on email compromise attacks on NYC businesses.
Control 3: Email authentication, SPF, DKIM, and DMARC at enforcement
These DNS records stop criminals from sending mail as your domain. Most small firms have SPF, half have DKIM, and almost none have DMARC at an enforcement policy (quarantine or reject), which is the only setting that actually blocks spoofing. It costs nothing but configuration care, and it protects your clients from "you," which is precisely what their due-diligence questionnaire is probing. We deploy this as standard in our cybersecurity services.
Control 4: EDR with someone watching it
Endpoint detection and response on every machine that touches client data, with alerts routed to a human who responds, at 2 AM, because that's when it happens. Unmonitored EDR is a smoke detector with no one home. For a sub-20-person firm, monitored EDR runs a few hundred dollars a month, and it's the line item insurers ask about by name.
Control 5: Retained, searchable, backed-up records
Financial and professional firms carry record-keeping expectations most small businesses don't: email archiving with retention policies (books-and-records requirements for advisers; engagement-file retention for accountants), litigation-hold capability, and encrypted backup of mailboxes and files that's independent of Microsoft or Google. "It's probably in someone's Sent folder" is not an answer you want to give an examiner, or opposing counsel. Our cloud backup and disaster recovery setups for financial clients include archiving precisely because the two problems are solved with the same plumbing, and the underlying Microsoft 365 retention and compliance features get configured as part of Microsoft 365 support.
Control 6: Answers ready for the questionnaire
The vendor due-diligence questionnaire from your biggest client is now a recurring event, 40 to 200 questions about MFA, encryption, EDR, training, incident response, and vendor management. Treat it as a product requirement, not an interruption: maintain a living document with your current answers, evidence screenshots, and dates. Firms that answer in two days keep clients; firms that go quiet for three weeks get flagged. (Bonus: the same document answers 80% of your cyber-insurance application, see our breakdown of cyber insurance requirements.)
If you do nothing else this month
The order matters. This sequence front-loads the controls that stop money from moving to the wrong place:
- Week 1 Enforce app-based MFA tenant-wide; kill legacy authentication protocols that bypass it.
- Week 2 Write and circulate the call-back wire verification rule. One page. Everyone signs.
- Week 3 Publish SPF/DKIM, move DMARC toward enforcement; deploy monitored EDR to every endpoint.
- Week 4 Stand up independent email/file backup with retention; draft your questionnaire answer sheet.
What this costs a 10-person firm
Implemented and managed: typically $1,200-$2,000/month all-in with full IT support included, or a one-time hardening project in the $5K-$8K range if you keep IT in-house. For context, the median BEC wire-fraud loss reported to the FBI runs well into five figures, and the client relationship that walks after a breach is the loss nobody itemizes.
The standard we hold financial clients to
When we take on an RIA or accounting firm, the six controls above are non-negotiable, we've declined to quote "just antivirus and email" because it leaves the firm answering no on the questionnaires that decide its biggest relationships. The good news: at 5-20 employees, the full set is a 30-to-60-day project, not a transformation program, and it runs quietly afterward under a normal managed IT agreement.
If you want a frank read on where your firm stands, book a free IT assessment, bring the last due-diligence questionnaire you received and we'll score your current answers with you, question by question. More security guides for NYC and NJ firms are on the Setnom blog.
Answer your next due-diligence questionnaire with confidence.
Book your free IT assessment. We'll review your systems, flag your biggest risks, and show you exactly what reliable, secure IT support looks like, no pressure, no obligation.
- (646) 719-0490
- info@setnomconsulting.com
- Response within one business day