
- Home
- Who we serve
- Financial Services
Who we serve
For Financial Services & Commercial Organizations
Built by people who have been on the other side of the table.
Our cybersecurity practice was not built by consultants who read about attacks. It was built by a former Chief Cybercrimes Prosecutor — someone who investigated intrusions, handled the electronic evidence, and took the cases forward.
That background changes the advice. It means we design programs with the examination in mind, and we handle incidents knowing that the evidence may eventually have to survive scrutiny by a regulator, an insurer, or a court.
01What we help with
Financial-services cybersecurity regulation
Program design and annual certification for examined institutions: written policies, CISO reporting to the board, testing and vulnerability-scanning cadence, audit trails, access-privilege review, authentication and encryption standards, retention and disposal, incident response, and the notification obligations that run on a clock.
The certification is an attestation, made annually, that the program is what you say it is. We build the program and we prepare the certification. We do not treat a policy binder as a program.
Framework alignment and control mapping
Recognized control frameworks, mapped across overlapping regimes so one control set answers several regulators instead of three programs answering one each. When a federal directive or an executive order shifts expectations, we say what it does — and does not — require of a non-federal entity.
Cyber risk assessment and security strategy
Where the actual exposure is, what it would cost, and what to do first — in a document an executive committee can act on. Architecture follows the risk register, not the other way around.
Third-party and vendor risk
Assessment programs, contractual security requirements, and ongoing monitoring for the vendors that hold your data. You remain responsible for what your vendors do with your data. A questionnaire that no one scores is not a program.
Incident response and electronic evidence
Response planning before an incident; during one, handling that preserves the evidence. This is the capability most firms cannot offer, and it comes directly from prosecutorial experience — chain of custody, imaging decisions, and what will still be usable if the matter becomes an examination or a case.
Privacy and data protection
Program design, data mapping, retention and disposal, and breach-notification obligations across jurisdictions. Privacy work that cannot produce an inventory, a retention schedule, and a notice decision tree is not ready for examination.
Corporate transparency and beneficial ownership
Corporate Transparency Act and FinCEN reporting posture — including what the August 2026 final rule eliminated for U.S. companies and U.S. persons, what still applies to foreign reporting companies, and what state transparency regimes and bank KYC/AML requirements continue to demand regardless. Do not assume prior BOI records have been deleted until FinCEN says the deletion is complete.
Business continuity and disaster recovery
Plans that are tested, not filed. Recovery-time and recovery-point objectives, alternate processing, and evidence that someone has run the plan since it was approved.
Internal control design and testing
Controls built to be examined, with the testing evidence produced as you go. A control that exists only in a narrative will not survive a request for the sample.
Before the examination
A fixed-scope review against the regime you actually answer to, delivered as a gap analysis with a prioritized remediation plan.
02How we work
Most engagements start with a regulatory readiness assessment — a fixed-scope review against the specific regime you answer to, delivered as a gap analysis with a prioritized remediation plan and realistic effort estimates. You will know what is required, what you have, and what it takes to close the distance.
We are a small firm. That means the people who scope your engagement are the people who do it.
Sosa & Arvelo, LLCNext step
Tell us what you’re facing.
A 30-minute conversation, no charge, no obligation. We will tell you whether an assessment is the right next step, whether we are the right firm — and if we are not, who is more likely to be.
