Pittsburgh RIA Cybersecurity Case Study: SEC & FINRA Readiness

PGH Networks is a Pittsburgh-based managed IT and cybersecurity provider that helps financial services firms across the metro — registered investment advisors (RIAs), wealth managers, CPA-affiliated advisory practices, and small broker-dealers — meet SEC, FINRA, and GLBA Safeguards expectations. This Pittsburgh RIA cybersecurity case study walks through an anonymized engagement with a 35-seat wealth-management firm headquartered in the South Hills and preparing for an SEC examination.
The firm managed roughly $1.2B in AUM across three offices (Pittsburgh, Cranberry Township, and Wexford), ran on Microsoft 365 Business Premium, and had grown faster than its controls. Leadership had received an SEC exam notification and knew the examiner would ask pointed questions about incident response, vendor risk, identity, and the written information security program required under Regulation S-P amendments.
The scenario: a Pittsburgh RIA facing an SEC exam
The firm's chief compliance officer inherited a security posture that had been stitched together by a general-practice MSP. Endpoint protection was consumer-grade AV. Multi-factor authentication was enabled for email but not for the VPN or the portfolio management platform. Backups ran nightly to a NAS in the Pittsburgh office — no immutability, no offsite copy tested in the last 18 months. There was no documented incident response plan, no tabletop history, and no evidence of user security awareness training beyond a one-time onboarding video.
The examiner is not going to accept "we have antivirus" as an answer to a question about material cybersecurity risk.

The challenge
Under Regulation S-P (as amended), Reg S-ID, the SEC's 2023 cybersecurity risk management proposals now in force, FINRA guidance for dually-registered reps, and the GLBA Safeguards Rule as updated by the FTC, this firm needed defensible evidence across nine control domains: access control, encryption, MFA, monitoring, incident response, vendor oversight, training, disposal, and a written program owned by a qualified individual. The engagement window was 90 days to the exam.
Two constraints shaped the plan. First, the portfolio management and CRM platforms were SaaS and could not be replaced on that timeline — controls had to wrap around them. Second, advisors travel constantly, so anything that broke mobile productivity would be rejected.
How it was solved
PGH Networks ran a two-week AI readiness assessment and security gap analysis against NIST CSF 2.0 and the FTC Safeguards Rule, then executed a 10-week remediation. The layered plan combined cybersecurity controls with disciplined Microsoft 365 hardening:
Identity and M365 hardening. Every account was migrated to phishing-resistant MFA using Microsoft Authenticator number matching, with FIDO2 keys issued to the four principals and the CCO. Conditional Access policies enforced compliant-device and named-location rules; legacy authentication was blocked tenant-wide. The tenant was brought to CIS Microsoft 365 Benchmark Level 1, with selected Level 2 controls (Safe Links, Safe Attachments, and anti-phishing impersonation protection tuned to the firm's principals and top 25 client contacts). Microsoft Purview DLP policies were configured to flag SSNs and account numbers leaving via email or Teams.
Endpoint and monitoring. Consumer AV was replaced with a managed EDR platform backed by a 24x7 MDR SOC. Every endpoint — including advisor laptops used from hotels and client offices — reported to the same telemetry pipeline, with automated isolation on high-severity detections.
Backup and recovery. Local NAS backups were retained but supplemented with immutable cloud backups of Microsoft 365 (mail, OneDrive, SharePoint, Teams) and the on-prem file server, with a 30-day immutability window and quarterly restore tests documented.
People and process. A phishing simulation and training program launched in month one with monthly campaigns tuned to financial-services lures (wire-change requests, custodian impersonation, DocuSign spoofs). A written information security program was drafted, mapped clause-by-clause to Safeguards Rule §314.4, and adopted by the management committee. A tabletop exercise walked leadership through a simulated business email compromise ending in an attempted fraudulent wire — the same scenario the firm's E&O carrier had flagged.
Governance. A fractional vCIO engagement established a quarterly cadence for risk review, vendor attestations (custodian, portfolio system, e-signature, email archiver), and roadmap updates against the firm's compliance obligations.
Outcomes
TL;DR: In 90 days the firm moved from consumer-grade defenses to a documented, tested, examiner-defensible program aligned to SEC, FINRA, and GLBA expectations.
Measured results at the exam-readiness milestone:
- Mean time to detect (MTTD) on simulated endpoint threats dropped from "not measurable" to under 8 minutes, based on MDR SOC ticket timestamps.
- Phishing simulation click rate fell from 27% on the baseline campaign to 4% by month three, with report rate rising to 61%.
- 42 of 44 gap-analysis findings were closed; the remaining two (a legacy line-of-business tool and a vendor SOC 2 renewal) were documented with compensating controls and target dates.
- The SEC examination closed with no material cybersecurity deficiencies. The deficiency letter noted only a documentation refinement around vendor offboarding.
- The firm's cyber-liability renewal came back with a reduced premium and expanded social-engineering sublimit after the carrier reviewed the new controls package.

Why financial services firms in Pittsburgh choose this approach
Financial services is not a generic vertical. An RIA in Pittsburgh answers to the SEC (or PA Department of Banking for state-registered advisors), the FTC under GLBA, and — if dually registered — FINRA. The controls that satisfy a manufacturer's cyber-insurance questionnaire will not survive an SEC exam. That is the gap this Pittsburgh RIA cybersecurity engagement was built to close: vertical-specific control mapping, evidence collection built for examiners, and a local team that can be onsite in Downtown, the Strip District, Southpointe, or Cranberry the same day.
The same pattern applies to CPA-affiliated advisory practices navigating GLBA, family offices with concentrated wire-fraud exposure, and small broker-dealers under FINRA Rule 4370 business continuity expectations.
Takeaway for your firm
If your firm is 90 to 180 days from an SEC exam, a FINRA cycle exam, a GLBA Safeguards attestation, or a cyber-insurance renewal — and you cannot answer "what is our MTTD?" or "when did we last test a restore?" — the pattern above is repeatable. It starts with an honest gap analysis mapped to the frameworks that actually apply to you, not a generic checklist.
Talk to PGH Networks about a Pittsburgh RIA cybersecurity assessment or a broader financial-services readiness review. Call 724.888.7007 or reach us through the contact form.
Related reading

Cybersecurity Services in Greentree, PA
Cybersecurity services in Greentree, PA for small and mid-market businesses: local response, EDR/MDR, HIPAA and CMMC support from a Pittsburgh MSP.

Cybersecurity for Financial Advisors in Pittsburgh
Cybersecurity for financial advisors in the Pittsburgh metro: SEC and FINRA aligned controls, 24/7 monitoring, and incident response from a local MSP team.

Managed Security Services Provider in Pittsburgh
Looking for a managed security services provider in Pittsburgh? See our 5-step process for 24/7 monitoring, EDR, compliance, and incident response.