01Assess & Test
Independent security audits, penetration testing, and cloud security reviews. CISSP and OSCP led, with a prioritized remediation roadmap your team or MSP can execute.
Specialized security and compliance support for firms that manage billions and can't afford disruption.
Already have an MSP? Good. We complement them, we don't replace them.
The SEC's compliance deadline for smaller advisers has passed. Examiners are now asking for evidence, not plans.
Coordinated AI-driven vishing hit hedge funds this August, sophisticated enough that FINRA activated its Fusion Center.
Firms trusted specialist security providers and watched them get absorbed into generalist platforms. Your risk profile didn't generalize with them.
Keeps the lights on
Does the work outside their lane
Your MSP keeps the lights on: helpdesk, devices, email, uptime. We do the work that sits outside their lane. We hand your MSP a prioritized remediation roadmap; they execute it. No turf war, no rip-and-replace.
Independent security audits, penetration testing, and cloud security reviews. CISSP and OSCP led, with a prioritized remediation roadmap your team or MSP can execute.
The SEC's amended Regulation S-P requires a documented incident response program, 30-day customer breach notification, vendor oversight, and five years of records. We build it and keep it exam-ready.
Written policies and an incident response program, mapped to what examiners ask for first.
Tracking for every service provider that touches customer information.
A breach-notification workflow rehearsed before you ever need it.
Policies, vendor records, notification timelines, and annual reviews. Exportable on demand for exams and allocator due diligence.
Continuous watch over the places risk actually enters a firm.
Business-hours or 24/7 coverage, depending on tier.
Credentials tied to your employees, your clients, or your firm.
Priority alerts on high-risk vulnerabilities.
Monitoring across NuGet, Node.js, and pip for firms running custom tools.
Your firm is adopting AI whether you've decided to or not. Your staff, your vendors, and your attackers already have. This August's coordinated AI-vishing campaign against hedge funds made that plain. We cover the full path.
An acceptable-use policy, data-handling rules, and staff training that covers AI-driven social engineering: voice cloning, deepfakes, and vishing.
Due diligence on the AI products entering your stack, and what firm or customer data they can see, before your compliance exam asks.
For firms building with AI: prompt injection, agent privilege abuse, data exfiltration through AI tooling, and red-team exercises against your actual stack.
A named security officer without the full-time cost, from fractional advisory for emerging managers to quarterly board and investor-facing reporting for established firms. DDQ preparation and allocator evidence packages included at every level.
Solo and small RIAs, emerging managers, first formal program.
Growing managers and multi-family offices with vendors and exam scrutiny.
Everything in Essentials, plusEstablished managers, quant funds, larger family offices.
Everything in Professional, plus| Essentials | Professional | Enterprise | |
|---|---|---|---|
| One-time setup | $8,500 | $18,000 | $35,000 |
| Monthly retainer | $1,500 | $4,000 | $8,500 |
| Minimum term | 12 months | 12 months | 12 months |
Penetration tests, breach forensics, and specialized add-ons scoped separately. Multi-year and multi-entity discounts available.
Vendor oversight, the 30-day notification workflow, and a maintained evidence pack, without the full security program.
Your website and your cloud tenant are the two parts of your firm that an attacker can study without ever touching your staff. Each service below answers a different question. Take one. Take all three.
Every service is a one-time fee, fixed as soon as we scope it. No retainer. No minimum term. Each report is written so that you can hand it to an examiner or to an allocator.
We fix critical findings during the engagement. You do not wait for a roadmap.
What can an attacker find without touching us?
We work from outside only. No credentials, and no contact with your staff. We collect with automation, then a person reviews every result.
From $3,500. One week.
Are our own settings holding?
We work from inside, with read only access. We compare your live settings against the benchmark and against how your firm actually operates. We do not exploit anything.
From $6,500. Two weeks.
What happens when someone actually tries?
Manual, adversarial testing, led by a CISSP and OSCP practitioner. We show you the full attack path, not a list of weaknesses.
From $11,500. Three weeks.
Fees depend on the number of sites, client portals, and cloud tenants in scope. We give you a fixed number before you sign.
All three together: from $18,500. We remove the duplicate discovery work and pass on the saving.
Need hands on the fix? Remediation support is $2,500 per 10 hour block, or we brief your MSP at no charge.
Want this run every quarter instead of once? That is the Packages section.
We work in scoped engagements with defined deliverables: an audit, a program buildout, a monitored retainer. You always know exactly what you're getting and what it costs. No open-ended consulting. And we work alongside your existing MSP or IT team, not against them: they get a clear roadmap, you get one accountable security partner.
Where we operate your environment, independent third-party testing is built into the engagement at cost. Your allocators are told to demand independent evidence over self-assessment. We agree with them.
Since smoothly transitioning to Delta Desk from another Third-Party system, we've gained a seamless, scalable cloud-based solution and a real improvement in our cybersecurity posture. But the biggest differentiator has been the personal service and total commitment to our success. Moving to Delta Desk has been a big win for our firm.
James Tufts
Partner, Chief Operating Officer · Passaic Partners

Former hedge-fund CTO, Series 7, 63, 4, 3

CISSP, OSCP
Delta Desk pairs two people who usually sit on opposite sides of the table: a former hedge-fund CTO who spent years building the trading and operations infrastructure asset managers run on, and an offensive-security practitioner (CISSP, OSCP) who tests it the way an attacker would.
That pairing is the firm. We understand your systems, your regulators, and your allocators' due-diligence questionnaires because we've been on the receiving end of all three. And while most of the industry's security providers have consolidated into private-equity platforms, we're founder-controlled. The people you meet are the people who do the work.
A 30-minute readiness call covers your posture against Reg S-P and the SEC's examination priorities. You'll leave with a clear view of your gaps, whether or not you become a client.
Confidential. No spam, no pressure.