| Generic MSP | PK Tech | |
|---|---|---|
| IT Fundamentals | ||
| Day-to-day IT support during business hours | ||
| Procurement and installation of business-class workstations, servers, network equipment, and cloud solutions | ||
| 24/7/365 IT support availability | ||
| Audited annually by a third party for security controls (SOC 2 Type II) | ||
| Properly insured for comprehensive coverage of breaches, extortion, and mistakes | ||
| 15+ years of Microsoft partnership and expertise | ||
| Generic IT Support vs. PK Tech | ||
| Experts in helping financial services firms comply with required regulations, such as SEC Regulation S-P and the SEC Marketing Rule | ||
| Familiarity and additional support offered during SEC exam season and quarter-end reporting deadlines | ||
| Successful track record of hosting and managing portfolio management and CRM platforms (e.g., Orion, Schwab Advisor Center, Redtail) in Microsoft Cloud | ||
| Works well with internal IT managers as their backup, escalation point, and security advisor | ||
| 15+ years of experience supporting financial services firms | ||
Why PK Tech for my Financial Services firm?
SOC 2 Type II, 24/7/365, SupportCompliance-Focused IT, Microsoft Security Experts, Secure Cloud Infrastructure
Secure, compliant, and proactive IT support built for financial organizations that depend on trust, uptime, and data protection.
A Message to Financial Services Firms
We know Financial Services firms.
Financial organizations operate in a high-trust environment where downtime, security gaps, and compliance issues can have serious consequences.
At PK Tech, we understand the pressure financial firms face when it comes to protecting sensitive information, maintaining reliable systems, and supporting both employees and clients without interruption.
Our approach combines proactive IT support, cybersecurity, cloud expertise, and compliance-focused guidance designed specifically for firms where security and reliability are critical.
Financial firms don’t just need IT that works. They need IT that protects trust.
Partner with PK Tech.
![]()
Jordan Hetrick
Founder & CEO
Why Financial Firms Choose PK Tech
Compliance-Aware IT
Support built around security, documentation, and operational accountability.
Secure Cloud & Microsoft 365
Protect sensitive financial data with modern Microsoft security controls.
24/7 Support
Because financial operations don’t stop at 5 PM.
Vendor & Platform Expertise
Support for financial applications, cloud platforms, and third-party systems.
Business Continuity
Reduce downtime and improve operational resilience.
Strategic IT Planning
Technology guidance aligned with long-term business growth.
| Rightworks (formally Right Networks) | Thomson Reuters | PK Tech | |
|---|---|---|---|
| IT Fundamentals | |||
| Day-to-day IT support during business hours | |||
| Procurement and installation of business-class workstations, servers, network equipment, and cloud solutions | ❓ |
||
| 24x7x365 IT support availability | ❓ |
||
| Audited annually by a third party for security controls (SOC 2 Type II) | ❓ |
||
| Properly insured for comprehensive coverage of breaches, extortion, and mistakes | ❓ |
||
| 15+ years of Microsoft partnership and expertise | ❓ |
||
| CPA Industry Specific | |||
| Experts in helping CPA firms comply required regulations, such as the FTC Safeguards Rule, IRS Publication 4557 | ❓ |
||
| Familiarity and additional support offered during tax season deadlines | ❓ |
||
| Successful track record of hosting and managing tax applications in Microsoft Cloud | ❓ |
||
| Works well with internal IT managers as their backup, escalation point, and security advisor | ❓ |
||
| 15+ years of experience supporting CPA firms | ❓ |
||
Ready to speak with an expert?
| On your own | Generic MSP | PK Tech | |
|---|---|---|---|
| FTC Safeguards Rule | |||
| Qualified Individual to implement and supervise your company’s information security program The Qualified Individual can be an employee of your company or can work for an affiliate or service provider. The person doesn’t need a particular degree or title. What matters is real-world know‑how suited to your circumstances. The Qualified Individual selected by a small business may have a background different from someone running a large corporation’s complex system. If your company brings in a service provider to implement and supervise your program, the buck still stops with you. It’s your company’s responsibility to designate a senior employee to supervise that person. If the Qualified Individual works for an affiliate or service provider, that affiliate or service provider also must maintain an information security program that protects your business. |
Unknown |
||
| Conduct a risk assessment You can’t formulate an effective information security program until you know what information you have and where it’s stored. After completing that inventory, conduct an assessment to determine foreseeable risks and threats – internal and external – to the security, confidentiality, and integrity of customer information. Among other things, your risk assessment must be written and must include criteria for evaluating those risks and threats. Think through how customer information could be disclosed without authorization, misused, altered, or destroyed. The risks to information constantly morph and mutate, so the Safeguards Rule requires you to conduct periodic reassessments in light of changes to your operations or the emergence of new threats. |
|||
| Required safeguards | |||
| Implement and periodically review access controls Determine who has access to customer information and reconsider on a regular basis whether they still have a legitimate business need for it. |
🤝 |
||
| Know what you have and where you have it. A fundamental step to effective security is understanding your company’s information ecosystem. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. Keep an accurate list of all systems, devices, platforms, and personnel. Design your safeguards to respond with resilience. |
|||
| Encrypt customer information on your system and when it’s in transit. If it’s not feasible to use encryption, secure it by using effective alternative controls approved by the Qualified Individual who supervises your information security program. |
|||
| Assess your apps. If your company develops its own apps to store, access, or transmit customer information – or if you use third-party apps for those purposes – implement procedures for evaluating their security. |
|||
| Implement multi-factor authentication for anyone accessing customer information on your system For multi-factor authentication, the Rule requires at least two of these authentication factors: a knowledge factor (for example, a password); a possession factor (for example, a token), and an inherence factor (for example, biometric characteristics). The only exception would be if your Qualified Individual has approved in writing the use of another equivalent form of secure access controls. |
|||
| Dispose of customer information securely. Securely dispose of customer information no later than two years after your most recent use of it to serve the customer. The only exceptions: if you have a legitimate business need or legal requirement to hold on to it or if targeted disposal isn’t feasible because of the way the information is maintained. |
|||
| Anticipate and evaluate changes to your information system or network. Changes to an information system or network can undermine existing security measures. For example, if your company adds a new server, has that created a new security risk? Because your systems and networks change to accommodate new business processes, your safeguards can’t be static. The Safeguards Rule requires financial institutions to build change management into their information security program. |
|||
| Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. Implement procedures and controls to monitor when authorized users are accessing customer information on your system and to detect unauthorized access. |
|||
| Regularly monitor and test the effectiveness of your safeguards. Test your procedures for detecting actual and attempted attacks. For information systems, testing can be accomplished through continuous monitoring of your system. If you don't implement that, you must conduct annual penetration testing, as well as vulnerability assessments, including system-wide scans every six months designed to test for publicly-known security vulnerabilities. In addition, test whenever there are material changes to your operations or business arrangements and whenever there are circumstances you know or have reason to know may have a material impact on your information security program. |
|||
| Train your staff. A financial institution’s information security program is only as effective as its least vigilant staff member. That said, employees trained to spot risks can multiply the program’s impact. Provide your people with security awareness training and schedule regular refreshers. Insist on specialized training for employees, affiliates, or service providers with hands-on responsibility for carrying out your information security program and verify that they’re keeping their ear to the ground for the latest word on emerging threats and countermeasures. |
|||
| Monitor your service providers. Select service providers with the skills and experience to maintain appropriate safeguards. Your contracts must spell out your security expectations, build in ways to monitor your service provider’s work, and provide for periodic reassessments of their suitability for the job. |
|||
| Keep your information security program current. The only constant in information security is change – changes to your operations, changes based on what you learn during risk assessments, changes due to emerging threats, changes in personnel, and changes necessitated by other circumstances you know or have reason to know may have a material impact on your information security program. The best programs are flexible enough to accommodate periodic modifications. |
|||
| Create a written incident response plan. Every business needs a “What if?” response and recovery plan in place in case it experiences what the Rule calls a security event – an episode resulting in unauthorized access to or misuse of information stored on your system or maintained in physical form. Section 314.4(h) of the Safeguards Rule specifies what your response plan must cover: The goals of your plan; The internal processes your company will activate in response to a security event; Clear roles, responsibilities, and levels of decision-making authority; Communications and information sharing both inside and outside your company; A process to fix any identified weaknesses in your systems and controls; Procedures for documenting and reporting security events and your company’s response; and A post mortem of what happened and a revision of your incident response plan and information security program based on what you learned. |
|||
| Require your Qualified Individual to report to your Board of Directors. Your Qualified Individual must report in writing regularly – and at least annually – to your Board of Directors or governing body. If your company doesn’t have a Board or its equivalent, the report must go to a senior officer responsible for your information security program. What should the report address? First, it must include an overall assessment of your company’s compliance with its information security program. In addition, it must cover specific topics related to the program – for example, risk assessment, risk management and control decisions, service provider arrangements, test results, security events and how management responded, and recommendations for changes in the information security program. |
|||
-1.png?width=1000&height=705&name=Untitled%20design%20(1)-1.png)
We know Financial Services Firms
-
What did the SEC change under Regulation S-P, and are financial services firms required to comply now?
Most financial services firms don't fully understand what changed here, and the compliance deadline has already passed. On May 15, 2024, the SEC adopted amendments to Regulation S-P. Larger entities were required to comply by December 3, 2025, with smaller entities following by June 3, 2026. If your firm is a registered investment adviser, broker-dealer, investment company, or transfer agent, this isn't a future requirement. It's one you should already be able to prove you're meeting today.
The core of it: covered firms must maintain a written Incident Response Program reasonably designed to detect, respond to, and recover from unauthorized access to customer information. That program has to be able to assess the scope of an incident and identify exactly which systems and data were affected, not a generic policy document sitting in a drawer.
The part most firms miss is notification. Firms are now required to notify affected customers as soon as practicable, and no later than 30 days, after becoming aware that unauthorized access to customer information has occurred or is reasonably likely to have occurred. Thirty days sounds like a long runway until you're the one trying to determine scope, draft notices, and get legal sign-off in week two of an actual incident.
We built our compliance work the same way we built it for CPA firms under the FTC Safeguards Rule: not a boilerplate policy that checks a box, but a real, tested Incident Response Program your firm can actually execute when it matters. If you can't answer, right now, who owns your incident response, how fast you could identify what data was touched, and how you'd hit that 30-day window, that's the gap we close.
To meet these requirements, firms need:
- A written Incident Response Program covering detection, response, and recovery
- A documented process for assessing the scope of any incident
- A designated notification process built to reliably meet the 30-day deadline
- Clear internal ownership of who executes the plan when an incident occurs
-
How do we know so much about financial services firms?
Because compliance-first IT is in our DNA, not something we bolted on to chase a new vertical. We were born inside a CPA firm in 2009. Our founder, Jordan Hetrick, started as an IT Manager for a leading public accounting firm in Arizona. After the partners saw what he could do, they partnered with Jordan to form PK Tech, with Jordan as an equal owner. The CPA partners mentored Jordan closely over the years, and PK Tech grew rapidly from there.
In 2016, Jordan acquired 100% of the business, and PK Tech remains completely independent today.
Here's why that matters for financial services firms specifically: we didn't have to relearn compliance-first IT for this vertical. We built our entire operating model around firms living under strict federal data security obligations, first the FTC Safeguards Rule for CPA firms, and that same discipline (written security programs, incident response, audit-ready documentation) is exactly what SEC Regulation S-P now demands of registered investment advisers, broker-dealers, and investment companies. Same rigor, different regulator.
We're also SOC 2 Type II certified, pursued voluntarily and audited annually by an independent third party, which is unusual for an MSP our size and gives financial services firms real, checkable proof rather than a sales claim.
Check out our story for more detail.
-
What IT regulations apply to financial services firms?
SEC Regulation S-P
The SEC's core rule governing how registered investment advisers, broker-dealers, investment companies, and transfer agents must protect customer information (see our FAQ above for the full breakdown of the 2024 amendments and deadlines).
- Requires a written Incident Response Program to detect, respond to, and recover from unauthorized access to customer information
- Requires customer notification within 30 days of discovering an incident
- Compliance deadline already passed: December 3, 2025 for larger entities, June 3, 2026 for smaller entities
Regulation S-ID (Identity Theft Red Flags Rule)
Requires broker-dealers and RIAs to implement a written identity theft prevention program tailored to the firm's size, complexity, and activities, covering any "covered account" such as retail brokerage accounts.
- Must identify relevant red flags for covered accounts
- Must detect those red flags when they occur
- Must respond appropriately to prevent and mitigate identity theft
- Regulators expect staff to be trained on the program, not just have it exist on paper
FINRA Cybersecurity Oversight
FINRA treats cybersecurity and technology governance as an ongoing examination priority for broker-dealers, not a one-time checklist. Firms are expected to maintain customer information protection practices and demonstrate active technology governance during exams.
Payment Card Industry Data Security Standard (PCI DSS) -
What official cybersecurity guidance has been issued to financial services firms?
-
Can I just use a compliance template and call it good?
It may seem like a quick way to comply with Regulation S-P is to find a written Incident Response Program template online, add your firm's name to the top, and call it good.
Additionally, there are compliance consultants advertising they can fill out your policies and procedures with only 15 minutes of your time.
These are not legitimate paths to compliance, nor will the SEC or FINRA be satisfied with a boilerplate policy full of empty promises.
NASAA offers a free Cybersecurity Checklist for Investment Advisers that can be a genuinely useful starting point. However, your Incident Response Program and cybersecurity policies must actually reflect your firm's specific systems, be tailored to your size and business model, and, most importantly, actually be followed. A regulator reviewing your program during an exam isn't checking whether a document exists. They're checking whether your team can execute it.
We recommend financial services firms avoid using a boilerplate template without genuinely implementing it, or any service that claims you can be compliant with only 15 minutes of your time.