Endure · Secure · Evolve(866) 4ELTENIClient portal ↗

Cybersecurity Regulatory Gap Analysis

An annual review of changing cybersecurity requirements and guidance that identifies gaps before an examiner, investor or client does.

When this helps

Know when to bring this work into the program.

Use this review to refresh the program against new or changing cybersecurity requirements without undertaking a full mock examination.

What we evaluate

A scope built around the risk.

An annual review of changing cybersecurity requirements and guidance that identifies gaps before an examiner, investor or client does.

  • Changes in applicable SEC, FINRA, NFA, NYDFS or other expectations
  • Policies, governance and required safeguards
  • Service provider oversight and incident obligations
  • Gaps between regulatory language and current practice
What you receive

Useful output for the people who must act.

  • Requirement-by-requirement gap analysis
  • Clear identification of new or changed obligations
  • Recommended policy, control and evidence updates
  • Leadership-ready summary of priority actions
Elteni explains the significance of the results, helps establish ownership and remains available as the response moves forward.
How Elteni approaches it

A process designed for cybersecurity regulatory gap analysis.

01

Identify obligations

Begin with changes in applicable SEC, FINRA, NFA, NYDFS or other expectations and confirm the systems, people and evidence needed to answer the client’s specific questions.

02

Map the current state

Review policies, governance and required safeguards. Then evaluate service provider oversight and incident obligations to determine whether the relevant controls operate as intended.

03

Confirm the gaps

Assess gaps between regulatory language and current practice and connect the result to credible security, operational and business impact.

04

Plan the updates

Provide requirement-by-requirement gap analysis and clear identification of new or changed obligations, then align responsible parties around the next actions.

Questions this service should answer

Move from activity to clarity.

What changed since the last review?

To answer this, Elteni analyzes changes in applicable SEC, FINRA, NFA, NYDFS or other expectations together with policies, governance and required safeguards. The client receives requirement-by-requirement gap analysis, with the evidence, context and next steps needed to act.

Which requirements apply to the firm and its services?

To answer this, Elteni analyzes policies, governance and required safeguards together with service provider oversight and incident obligations. The client receives clear identification of new or changed obligations, with the evidence, context and next steps needed to act.

What evidence would an examiner expect to see?

To answer this, Elteni analyzes service provider oversight and incident obligations together with gaps between regulatory language and current practice. The client receives recommended policy, control and evidence updates, with the evidence, context and next steps needed to act.

Connected program

The result does not have to live in another report.

Relevant findings, evidence, owners and remediation status can be centralized in the Elteni Platform as part of an ongoing relationship.

Explore the Elteni Platform →

Let’s scope cybersecurity regulatory gap analysis around the outcome you need.

Start a conversation →