Florida  ·  Puerto Rico  ·  New York  ·  Washington, DC [email protected] +1 917 410 3335
Sosa & Arvelo, LLC Request a consultation
Sosa & Arvelo, LLC
ServicesCyber & InnovationFinancial AdvisoryRisk & ComplianceStrategy & OperationsSectorsAll sectorsFinancial Services & CommercialNonprofits & Faith-BasedInsightsFirmAboutTeamHow we workCareersContact Request a consultation

Who we serve

For Financial Services & Commercial Organizations

Built by people who have been on the other side of the table.

Our cybersecurity practice was not built by consultants who read about attacks. It was built by a former Chief Cybercrimes Prosecutor — someone who investigated intrusions, handled the electronic evidence, and took the cases forward.

That background changes the advice. It means we design programs with the examination in mind, and we handle incidents knowing that the evidence may eventually have to survive scrutiny by a regulator, an insurer, or a court.

01What we help with

01

Financial-services cybersecurity regulation

Program design and annual certification for examined institutions: written policies, CISO reporting to the board, testing and vulnerability-scanning cadence, audit trails, access-privilege review, authentication and encryption standards, retention and disposal, incident response, and the notification obligations that run on a clock.

The certification is an attestation, made annually, that the program is what you say it is. We build the program and we prepare the certification. We do not treat a policy binder as a program.

02

Framework alignment and control mapping

Recognized control frameworks, mapped across overlapping regimes so one control set answers several regulators instead of three programs answering one each. When a federal directive or an executive order shifts expectations, we say what it does — and does not — require of a non-federal entity.

03

Cyber risk assessment and security strategy

Where the actual exposure is, what it would cost, and what to do first — in a document an executive committee can act on. Architecture follows the risk register, not the other way around.

04

Third-party and vendor risk

Assessment programs, contractual security requirements, and ongoing monitoring for the vendors that hold your data. You remain responsible for what your vendors do with your data. A questionnaire that no one scores is not a program.

05

Incident response and electronic evidence

Response planning before an incident; during one, handling that preserves the evidence. This is the capability most firms cannot offer, and it comes directly from prosecutorial experience — chain of custody, imaging decisions, and what will still be usable if the matter becomes an examination or a case.

06

Privacy and data protection

Program design, data mapping, retention and disposal, and breach-notification obligations across jurisdictions. Privacy work that cannot produce an inventory, a retention schedule, and a notice decision tree is not ready for examination.

07

Corporate transparency and beneficial ownership

Corporate Transparency Act and FinCEN reporting posture — including what the August 2026 final rule eliminated for U.S. companies and U.S. persons, what still applies to foreign reporting companies, and what state transparency regimes and bank KYC/AML requirements continue to demand regardless. Do not assume prior BOI records have been deleted until FinCEN says the deletion is complete.

08

Business continuity and disaster recovery

Plans that are tested, not filed. Recovery-time and recovery-point objectives, alternate processing, and evidence that someone has run the plan since it was approved.

09

Internal control design and testing

Controls built to be examined, with the testing evidence produced as you go. A control that exists only in a narrative will not survive a request for the sample.

Before the examination

A fixed-scope review against the regime you actually answer to, delivered as a gap analysis with a prioritized remediation plan.

Request an assessment

02How we work

Most engagements start with a regulatory readiness assessment — a fixed-scope review against the specific regime you answer to, delivered as a gap analysis with a prioritized remediation plan and realistic effort estimates. You will know what is required, what you have, and what it takes to close the distance.

We are a small firm. That means the people who scope your engagement are the people who do it.

Sosa & Arvelo, LLC

Next step

Tell us what you’re facing.

A 30-minute conversation, no charge, no obligation. We will tell you whether an assessment is the right next step, whether we are the right firm — and if we are not, who is more likely to be.