ECI Pulse
At ECI, it is our mission to be the most transformative business partner you will ever engage. We thrive in a state of constant progress and pushing the boundaries of what’s possible. Over the past two decades, ECI has emerged as the premier provider of managed services and technology solutions, across cloud, digital, and cybersecurity, to the investment management industry. To date, we have helped more than 1000 global clients, from financial hedge funds and private equity entities to asset management companies, to activate their full potential through technology, a consultative approach, and a relentlessly innovative spirit.
Join us as we explore the latest trends, innovations, and strategies that are shaping the industry. Each episode features insightful conversations with industry leaders and experts who share their experiences, challenges, and visions for the future. Tune in and stay ahead of the curve with ECI.
ECI Pulse
Reg S-P Compliance: The Four Pillars You Need to Know
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Reg S-P has been on the books for decades, but a major SEC update reshaped how alternative investment firms are expected to protect client data. In this episode, Chad Fullerton, VP of Information Security, breaks down the four pillars of Reg S-P compliance, from incident response to service provider oversight, and share practical first steps for firms working to close the gap.
Welcome to ECI Pulse, where we bring together our thought leaders to discuss the technology trends that are taking place in the workplace. Today I am joined by one of my friends, Chad Fullerton, who leads information security here at ECI. Chad, welcome. Thanks for taking the time today. Thank you, Jen. Happy to be here. We are hearing a lot of questions from clients about Reg SP, and I'm sure you are hearing the most. But thought it was a good opportunity for us to take a few minutes, chat through, kind of make a very practical guide for our clients and those in the area who are wondering what to do. So can you give us kind of a a one one? Give us a primer on what Reg SP actually is and why is it suddenly getting so much attention? Yeah, I I think the starter of kind of what it is and and the kind of precursor to that is a lot of people are looking at it like it's new. it's it's this new thing, right? It it's actually been around since about two thousand. it's it's not new. It's a kind of expansion of the the Gram Leech Billy Act. it's not anything that kind of sets a new standard. What it is is it it originally set a standard for how financial institutions, we're gonna call covered entities, should be protecting investor data.~ it's been been around for a very long time. But it was largely unchanged. It kind of sat there ~ and just kind of collected dust, right? And you know, it's what the SEC would use when they're conducting audits to enforce certain requirements, but it didn't adapt with the times. As we know, technology has exploded over the last 20 years, 26 years or so since it came out, and it was mostly unchanged and didn't really account for new technologies. We're in the AI revolution now, right? It didn't account for anything to do with AI, and it's it's gonna continue to expand. So Back in 2024, ~ around May, the SEC finally kind of modernized what Reg SP who it was going to affect, who was going to apply to, and what the new changes were going to be. Kind of stepping back a step right before that, the SEC for the last few years had had this cyber rule that they had proposed, and it kind of sat in this draft will they, won't they, sort of state for a long time.~ overall a a pretty solid rule, but it it still was, you know, there's There's these frameworks and foundations that experts across the world, people much smarter than me, kind of come together and create things like NIST CSF, ISO 27001, right? You see these standards. The SEC kind of creating their own is again just it's gonna get stale in another 20 years when nobody updates it, right? ~ so one of the big changes that came through with Reg SP was the kind of destruction. They they killed that cyber act. And then a few months we all kind of sat in this limbo state of like, well, what does that really mean? Few months later we have the changes to Reg SP,~ which aligned a lot more standards, which we'll talk about in minute, for what registered investment advisors and kind of covered entities have to align to. What does that actually mean?~ so overall, Reg SP is a set of foundations that are relatively broad. They're not as prescriptive as something like a~ but they're prescriptive enough to tell kind of covered entities exactly how they are supposed to treat and protect. Sensitive data. So that's investor data, financial data, accounts, right?~ social security numbers, like things like that that kind of to do with your clients. So ~ excited to talk a little bit more about what kind of all of that comes together. But I think the last kind of key point on like what is it and why does it matter, the key deadlines have actually already happened at the time of this podcast.~ so larger entities and there's there's certain asset under management kind of thresholds that constitute that. was December of last year. ~ and then the smaller entities, which a lot of, you know, the clients that ECI supports fall into that smaller entity range, was actually last month. So we're sitting here kind of almost almost exactly one month to the date of recording this post when every entity is supposed to be in full compliance with with the reg SP changes. So we're here. Absolutely, absolutely. So this isn't coming soon. This is right now. Let's talk about who it applies to. You just alluded that the ECI clients are investment managers, their head funds, their PE, and they fall into that smaller entities that you just highlighted. Are they all covered under Reg SP? Yeah, so anything that would they would call covered institutions, right? So that specifically ties to registered investment advisors, right? If you're registered with the SEC as an R as a RIA,~ we used to call these RIA requirements, right? They they've kind of been there for a while. This falls into those RIA requirements. if you manage a registered fund, right? If you're a fund manager that supports a registered fund,~ if you are a broker dealer. Right. If you're a hedge fund, private equity managers, credit managers, right, all of these kind of fall into this reg SP as as ~ covered entities or covered institutions, right? Kind of a lot of people use different words, but that's what reg SP would tie to. Excellent. So help us understand that last part ~ is critical, right? When we talk about the managed service provider, the cloud provider, anyone who touches your client data has to meet those So we fall into there. So what are the actual requirements that folks need to meet when it comes to the third party vendors that have their hands in your Yeah, so I think that there is like you talked about, does this apply to to ECI, right? As as as a kind of third party. We are not a covered institution, but we support covered institutions. So as we talk about there's kind of four pillars that surround ~ Reg SP, I'll talk about those in a little bit more detail in just a second, but that's where it's it's important to understand, and you bring up a a key point there, Jen, right? Is that just because you don't fall in as a covered institution, if you support covered institutions, They are going to have requirements of you. So I think the SEC, when they released this, they actually said kind of some keywords, tricky phrases. You can't outsource risk, right? Like it all falls on the covered institution. So the prescriptions that the reg SP kind of covers are those RIAs, those broker dealers, those hedge funds, private equity, right? Those types of folks.~ but you guys, as covered institutions, then have to force requirements onto people like us ~ You know, you're supporting your critical vendors, people who have access to that sensitive data that we talked about a little So that is a key point. That is a key call out. And I think, you know, I'll touch a little bit on like what the four pillars really are. ~ and in order to go into kind of the service provider oversight, which is one of those key pillars, right? ~ but it be it goes beyond just the service provider, Absolutely. right? So there's there's a lot more to it. But yeah, like so so kind of looking at like pillar number one is is incident response program. It's a it's a key call out that the SEC did when they made this ruling is that they didn't necessarily specifically align to NIST CSF as the standard for this, but they did call out things like detect, protect, respond, recover, govern, right, for data. Those should sound familiar to people that have heard of NIST The core pillars of NIST CSF are those kind of five control families, right?~ so when we look at what is an incident response program, the precursor to that is what is your information security program. And so Reg SP really does require organizations similar to what this the proposed cyber rule that was scrapped did, to have a core information security program and have that in place to then talk about how you're protecting client data, how are you managing the client data,~ and then having incident response practices around what are you going to do in the event of Right. We've seen these types of regulations come globally from things like~ NIS two, right? The EU is obviously first to trigger on a lot of ~ regulations kind of coming out the door. But Reg SP does something similar where it says it's not really a matter of if, it's a matter of when. So how are you going to respond in the event of right? And that's where kind of pillar one, that incident response program, are you addressing things like how are you going to detect ~ events in the first place? How are you gonna detect whether it's Material breaches or not, how are you going to detect them? How are you going to respond to them? How are you going to operate during? And then how are you going to recover? Right. How are you going protect client data?~ pillar two is customer notification gets called out. And I'm going to cover this in kind of two pieces. One actually falls into service provider oversight, which is the third pillar, but customer notification within 30 days. So that's a hard call out. It's a hard date. It used to be that you didn't necessarily have. specific call outs, right? It was kind of a you get to determine what's a material breach, you get to determine how it affects you, you get to determine how you know you're going to do certain things. Now we have a specific call out that if you have any evidence whatsoever that data or client sensitive data specifically has been accessed, and this falls into those things that we talked about, right? Socials, account numbers, financial data, et cetera, you are required to notify the affected You don't have to notify every client that you have, but only those that were affected by this cyber incident.~ that didn't exist. There wasn't that federal minimum standard, right? It didn't exist before. Now it's there. So what does that mean? Like what do firms need to look at, right? We talked about incident response. Documentation's huge there. If you don't have an incident response policy, you don't have an incident response program. If it's not written down, you didn't do it, right? You can't just kind of best effort it. Customer notification. How are you going to notify customers? Are you going to take that? well, we're in within 30 days, I'll shoot them a text or an email, right? Like, no, you probably need to have a formal tracking and process established there, a notification process with tracking that you can then retain, because we're going to talk about record keeping in a second, which is pillar number four. But are you going to be in the middle of an incident and go, let me bring in my public relations manager and see if we can come up with some jargon to throw at him, right? No, these are things you should plan for in advance.~ and then kind of Part three, pillar pillar number three, which is service provider oversight, but also kind of ties back to that notification of we had we had in pillar number two, governing your third parties. Like who is ECI? What are we here for? We are the governed third party, right? We are the service provider that should have oversight, that you should have oversight of. And so, like, that's all of your critical third parties. Anybody who touches client data, basically at all, or can touch client data, whether you're housing it, whether you're accessing it. Processing it, right? Anything.~ so you have core standards that you should require against those. But also one of the biggest kind of pieces to that is a 72 hour breach notification that you should have with your third parties. One of the big things that ECI does that I have not seen other providers do, we make that contractual, right? So we add that as an addendum to the MSA. If you're reaching out, if you're an ECI client and you're reaching out saying, hey, you need to have 72 hour reporting. It's not just an email where somebody named Bob goes like, Yeah, yeah, yeah, we'll we'll let you know. Right. Cause that how do you govern that? How do you hold people to that? It's Bob doesn't work here anymore. Nobody else agreed to this. We're not gonna do it, right? ECI takes that a step further and actually does that at addendums to the which is huge. And I've seen a lot of covered entities go, Wow, like you guys are one of three people. We've reached out to fifty. You guys are one of three that have actually taken it to a contractual level. And I think it ties back to who we are, right? Like who is in our DNA. ~ and then the fourth is record keeping, right? You have to retain everything that we've talked about has to be retained. I think it's five years off the top of my head is what they're looking for. But it's everything to do with your information security program, your incident response program, your service provider oversight, who are all of your third parties? Have you done a business impact analysis to even capture who your critical third parties are? ~ and then have you assessed them? Have you done due diligence? Have you looked at things like contractual obligations for semi-two hour reporting? Have you assessed that they have the minimum cybersecurity standards that, you know, you require? ~ and then are you retaining proof that you did that? Cause when you get audited, right, it's not just gonna be take my word for it, bro. Right. It's gonna be you need to have proof that you did it and not that you did it last week when you heard the auditor was coming, right? That you've been doing it over the last few years. Absolutely. So now I'm just gonna give you the softball to tell us all how hard you work because this really does feel like a lot, Ha ha. right? When you look at that and you listen to this, you know, you just made the point we, you know, Bob will call you when you're you've it's within seventy-two hours, or yeah, we have a an email template that marketing uses when we need to send something out. But this is a lot to actually document and have in a plan a twenty person firm, right? When you look at Reg SP, you even said that the larger firms were earlier and now the small firms are catching up. ~ where do they fall short? What's the hardest part for these smaller funds to get aligned and and to be in line and and compliant? Yeah, that's a great question. I I think it it kind of falls into a few key areas, right? The first is they don't either don't have documentation at all. It's kind of that if you conquer Rome in a day but don't tell anybody about it, did you even do it? ~ it and it falls into that, Right. right? Even even ECI clients who have great cybersecurity hygiene, they're they have kind of all the bells and whistles, they've got a sim, they've got a sock, they've got XDR, they've got all these things that are above and beyond like just the the basic requirement, but none of it's written down anywhere. So An auditor comes in, you know, even we could even go beyond just like Reg SP and and the SEC auditing you. Investors come in or potential investors. So you go through due diligence or you go through kind of that ODD process and they go, Let me see your this. I don't have one of those, right? I could tell you about it. Like nobody trusts you. Nobody wants to hear words. They want to see it written down. So either A, it's not written down at all. They don't have policies and procedures or plans,~ things like an incident response plan, or B, they have one. But they use Copilot to make it. And nobody's actually reviewed if it's real, right? Nobody's actually said, hey, can we actually hold ourselves to this? Or we haven't called out who the key players are. It has a bunch of like the information security response team. Well, well, who is that team? What is that team comprised of? I don't know. We'll see who we feel like that day.~ those are the types of things that don't hold up, right? And the typical audit, the typical due diligence, the typical anything you're looking for is somebody who's conducted More audits than I have years old, is, you know, you look at things and you say, hey, if I look at this at a high level and this looks like it was AI generated, or this looks like it's it's just totally broad general strokes, nonspecific. If this looks like it says nothing of of substance, I'm gonna dig deeper. I'm gonna say, What are you actually doing? I wanna get into the weeds now because I don't trust you and I don't believe that you know what you're doing. So having these like strong documentation, that's the That's the gate, right? That's the first piece that an auditor or investor is going to look at. If that's descriptive, if that's prescriptive, if it says all the things it needs to say, that usually is the end of conversation, right? So, you know, those are kind of the first two things I see. The second thing is, or the third thing is really nothing being tested, right? They haven't actually gone through like a tabletop exercise to say, hey, in the event of how are we going to respond to this? Do we have templates in place? Do we have These kind of are we prepared to hold up our obligation of actually being able to speak to you know clients within 30 days?~ do are we gonna even know? How are we even gonna know if there was a breach, right? Or how are we gonna know if data was compromised? Do you have things like a sim? Do you have a sock team behind that?~ and sometimes that answers no, and sometimes that answers yes, and sometimes it answers like, well, yeah, but they send alerts to an email and nobody reads that email, and and maybe we do something, maybe we don't, right? Are you bought into your security program? And, you know, we'll talk a little bit more about how ECI helps to address this stuff, but like you mentioned, how is a twenty person operational team, you know, gonna do all of this stuff, right? And that's where people like ECI, that's why I have a job, right? That's where people like us really come into play. Absolutely. So you lead compliance here at ECI, but our full product suite has to support this, right? You you align with so many. So can we go like pillar by pillar? If someone is looking at this right now saying, Do I have the four things? Am I aligned?~ where can ECI jump in and assist with? Yeah, great question. So when it comes to, you know, the ECI products, we like you said, this is our bread and butter, this is in our DNA, like, you know, all of the things that that our CEO Jeff likes to post on right? All the the keywords, tricky phrases, like it all is actually true. All of our products are are really designed to meet these requirements, which is why when something like Reg SP changes come out, we're like, cool, you know, whatever. We were already doing all of that. So it's like Cool. Like like now there's something that says, hey, look, ECI is great. Like it's not we're not scrambling going, how do we figure this out? Like it's all it's all already baked in. If you're an ECI client, it's conversation over, right? You know, maybe there's some conversations we need to have, but it's not this big like, I need to go buy a bunch of things, right? So going pillar by pillar, right, looking at like incident response, well, that's our like Ella Protect and our XDR process and our XDR program. Like that team is doing that. That's where The sim, the SOAR, like the the EDR platforms, all of those layering in together to say, would you even know if data was compromised at all? How would it, how would you know? Right? Who would be alerted? ~ looking at things like you know, are you gonna know what was compromised? Right. There's a big difference in your requirement of like, hey, we had a breach. Okay. So are you gonna alert every client you've ever had that you have any information on whatsoever? Like, talk about reputational risk. That's that's brutal. Or are you going to say, hey, we had data compromise of this client from like from this SharePoint site, this SharePoint site has, you know, this client and that's that client has this data and that's what was exfiltrated. And by the way, we can see the total amount of data that was exfiltrated and we can see what was accessed, right? Those types of conversations then drastically reduce your scope as a covered entity to say, hey, I now have to notify this client or these four clients instead of those, you know. hundred clients that I was working with last week in a different SharePoint site, right? ~ so those sorts of things fall into like our are baked into what our XDR program really kind of covers.~ you know, customer notification, incident response playbooks, having the documentation, having the written documentation, being able to advise you on what you should do and how you should approach things, you know, incident response support, right? Coming in from the SOC team, but also like what is my bread and butter is GRC, you know, what we call GRC. VC so kind of services, right? These types of baked in compliance and security support teams that really fall our GRC. We're writing playbooks for clients. We're writing response plans. We're validating those against your environment. We're making sure that they they stop questions at the door, right? But even a step further, it's not just responding to Reg SP, it's also operational due diligence and going into the kind of helping you generate revenue. How do you secure fund investments? We're there for that too, right? Which is huge. ~ You know, service provider oversight, like we talked about how ECI has this baked into its DNA. We're building that into your MSA, addendum to your MSA. We have it, we're ready to go. It's done. It's it's an easy conversation. Let's just get it signed off. We move on. It's a the contracts team. We have a contracts team, which is already a big step from some MSPs, right? That they're ready to put this into your MSAs. These are addendums. They're ready to go now. The service teams, the the account managers, CRMs, CTMs, like they're they live this stuff too. This isn't just a like side hobby for everybody. It's not like they're like, hold on, let me go ask Chad, right? They know this stuff as well. They deal with this every day. So it's built into like our service delivery motion.~ you know, and and then record keeping, right? Between our LA platform, L IQ, our compliance documentation, we're uploading documentation to our client portal where that documentation is retained. Right. So it's not just like, hey, we sent you an email last week with a list of who clicked on what emails. Right. Or, hey, here's a, you know, you did training last month. Hope you got the report. We're saving that report. Right. That's also saved to our client portal. We're retaining that information as well. Obviously, we still recommend clients retain that within their own, you know, ecosystem, right? You know, but for clients that don't, or for clients that forget to or clients that need to look back, we're retaining that. Within our platforms, but also in our client portal that you have access to. Those sorts of things, that ease of access information is just baked into like who is ECI. Absolutely. ~ AI is the buzzword. You and I always joke about this over and over again. But we have a relationship with anthropic. We're a cloud partner. How does that factor into it from a compliance for clients who are looking at these AI tools? It's a great qu great question. mostly in that AI, like I said, we're in the AI revolution. You know, we talk about the industrial revolution, the technology revolution. You know, we used to go hundreds of years between revolutions, right? These like textbook revolutions. Now it's like every three minutes there's a new one.~ but like 10 years from now, Exactly. Exactly. we're gonna be looking at, you know, 2024, give or take, as the AI revolution, and that's gonna span from like let's say, you know, 2020 to 2030, whatever it's gonna be. And the partnership with Anthropic, obviously everybody knows Anthropic Claude~ is, I would say, leading the charge with AI. Like obviously, Microsoft's doing a lot with AI, OpenAI, you know, ChatGPT is doing a lot with AI tools. But obviously, ECI is a you know expert tier, top-tier Microsoft partner. We do all the things with Microsoft. We could support all the things with Microsoft. But some clients and some people like I,~ like myself, right? I I'm a big Claude fanboy. We look at AI and we say, look, there's some things that every tool does a little bit differently or does a little better. It's baked in a little bit different, right? Yes, you can code with Copilot, but I want to use Cloud Code because it's a little bit better. It's a little more ingrained into my workflow. Or I brought on this top tier developer and they know cloud code and they don't to touch Microsoft. So I'm going to do it because they're going to be so much more efficient, right? So our partnership with Anthropic, to me, what it signals and what it says is ECI recognizes changes in the industry. ECI recognizes changes in technology. ECI recognizes that you can't be all in one stack only ever, only do that and say forget everything else, right? And we're willing to support and kind of put our money where our mouth is with the other tools that are leading in the space, because we're leading in the space, right? We're leading in supporting financial services, obviously, is the goal of this, but just companies in general. We're leading the charge in utilizing AI internally. Right. We talk about LA IQ. We talk about these platforms. We're building AI functionality off of the back of, you know, Anthropic and Cloud. We're building it off the back of you know, our Ella platform that we've built in-house that allow this AI functionality.~ and then regulated industries, right? There is a lot of concern around things like clo cloud co work,~ that you know, through our partnership with anthropic, one, we have it ourselves, right? We have the tools. We are the testing ground, right? We are able to take these things to a dev environment and really see what the real impact is. We're not speaking off of just slides and stuff we Googled, right? We didn't go, hey, co-pilot, what should I do about Claude?~ we're actually testing it. We're living it, we're breathing it. So as there's changes in the again, the industry's evolving every three minutes, as these things evolve, as these things change, we can make real world, real life recommendations to clients. And we're experienced with it and we know how to do it. And that's kind of like the biggest things that it means to me. Absolutely. I mean, comparable answer, Jeff always calls it the and conversation, right? There's no more one tool or the other. It's you have to be well versed in all of these feats and we have to know what's going on. so I have to be cheeky and be the marketing person. I I hear in the marketplace that some of our competitors are actually using Reg SP as a line item. They're they're charging to fall into play as that third party vendor. ~ Is this something you're seeing in compliance? Is this something that you have on our framework? Is that something that our clients would expect to see from us?~ how does that work and how do why are folks doing that? I mean, anybody wants to make money any way they can, right? Is is kind of the answer to that question. Yeah. at ECI, like it it's ingrained in who we are. So no, is the answer for us, right? We we are seeing it. We are seeing it with not just other MSPs but technology platforms altogether.~ I think it ties back to this idea of, you know, hey, I want to have Microsoft. Okay, that costs X. Well, I want Microsoft, but all my data stays in the continental US. Okay, well, that's gonna cost Y, because data centers are more expensive here, right? you know, you see the same thing with technology platforms that are like, the tool cost X, but you want SSO? Hold on now, we're gonna talk about why. It's like you're just you're arbitrarily gating things behind paywalls just to try to upcharge. Like you already have to have the c the core components baked in. You can do it if you're doing it for one client or doing it for a thousand. If you've truly built in the core competencies, it operates at scale and that there's really no difference. If we've built in how we respond to client contract requests, if we've built in due diligence packets and that we're we're ready and prepared to answer due diligence questions, right? It's not ~ a hamster spinning, you know, spinning around with his head cut off trying to figure out what to do. It's no, we have a due diligence packet. It's on the client portal. You can go download it tomorrow. It's ready to go. It's already there. It covers these core elements. It's got SOC2 reports, it's got all the things it needs, then Why do we need to charge for that? Right. Like that's baked into who we are. That's a core competency. It's part of our DNA. So that's the things I look at and say, you know, are we really looking to nickel and dime or are we looking to just be best of breed? And I think that's where like ECI differentiates is, you know, yeah, obviously different technologies cost more, obviously different things cost different amounts. But if you're looking at us aligning to Reg SP as a third party vendor, that's there's absolutely no reason we shouldn't be. Considering that's our client base. Like it just should be baked in. And so for us, y you know, it absolutely is. So I'm sure someone's listening to this right now thinking, I get this, except that one thing. So ~ if folks are realizing their gaps right now, what do they do first? Like how do you handle it if someone were to call you tomorrow and say, Heard the podcast, Chad, kinda worried, are we okay? What's step one for folks to start thinking about? So I think it depends where they're at in their journey ~ and what they've already done or haven't done. But for me, it's kind of three simple steps, and that's where you start. The first is always a gap assessment. I just said it depends where you are in your journey. Well, I don't know. So that's step one, a gap assessment. Where are you in your journey? How much of this have you done or haven't you done? Right. Honestly, not just not propaganda, not smoke and mirrors, not not to pick on gen, not the marketing slang, right? Not the What am I going to tell investors of where I am? Right. What am I going to tell clients? What am I going to tell third parties? It's where are you? Have a have that kind of like sit down in the mirror conversation and say, on this list of things Chad talked about today, what have I done and what have I not done? Right. Do I have written policies that are good or not? Have I read those? You know, do I even know what those say? Or did I just kind of export them off Copilot, throw it in SharePoint and say, if I get audited, here they are? Do they match my environment? Have I had major technical changes in the last few years that I'm not really fully caught up on? Have I audited my third parties? Do I even know who my critical third parties are? Right. Step one is that honest conversation, a gap assessment. Do you have the things or do you not have the things? Right. ~ obviously, as as is a trend in every podcast we're gonna do, ECI does these things too. ~ shocker, Yeah. right? But like as part of our GRC, that is what we do. Step one is doing a security and risk assessment against the standards like NIST CSF to say, hey, these are the things that are missing from your security program. These are the things that are missing from your compliance program. These are the things that are missing from your governance program. Let's go do them. Right. And step two, don't wait to get audited, right? We've already seen it's probably the most common thing I'm seeing across the world right now is regulations come out, but do they have teeth or not? Let's wait till the first person gets taken down or fined or sanctioned or And then we'll comply. A lot of these things take time, right? You can't go tomorrow. And go list out every single vendor that's critical and has access to client data and then go send them an audit and then go get your contracts and then go get all your policies up. That's not gonna take 10 minutes, right? That's not something you do in a day. So those things take time. I mean, vendors are getting these things left and right. Not all vendors are as prepared as we are, right? So they're they might be months behind in a backlog of getting these due diligence questionnaires out the door. So you've got wait time and lead time with some of these third parties. So Don't wait for the examiners to come in. Don't wait for it to prove that it has teeth. We know the SEC has teeth, right? Like it's it's the whole reason we're here. If none of us believe the SEC had teeth, we wouldn't be here. So we don't need to wait for them to prove it, right? ~ and then obviously, third and and last, like you're gonna have to lean on your managed service providers. A lot of the information that you need is going to come from people like us. If you know you look at things like obviously we have a lot of competitors in this space, but If they don't do all the things, if they don't offer the GRC, if they don't offer these kind of compliance programs that are built in, they're not as prepared to be able to jump into all of these things. So like leaning on your MSP to say, hey, I need someone who's prepared, who can jump in, who can take these things. If you're a 20 person company, you don't have the resources to go dedicate towards writing correct policies and reaching out to vendors and answering questionnaires. Let us do it. Right. We'll we'll do it for you.~ and then will bring you actionable information and checkpoints as opposed to, hey, go do this, have a nice day. Bye. Right. Absolutely. So we covered off on it, but I would normally ask, you know, if they're not an ECI client, what would they do? So you've rattled down the list.~ that assessment, that gap assessment, we offer that for free. Is that correct? We do we do kind of a free phone call for folks to get them a a current state. Is that correct? Yeah, I it's something that especially if you're not an ECI client, it's something that's built into our sales process, right? It's something to say, hey, you know, we're not gonna sell you some stuff that you already have, and we're not going to tell you to go buy something if you have something that's comparable. It's all about kind of how does it align? So we're gonna do that gap. We're gonna understand where you are today in order to make the impact where it matters, not just say, Hey, we're gonna replace everything. Well, my firewall is six months old. Nope, it's getting replaced because I said so, right. Like we have to assess it first, so. Chad, this has been awesome. I appreciate it. I know we chatted a little longer than I originally promised, but ~ I think there's a ton of information for folks who are worried about this and and have this top of mind.~ any final thoughts, anything that that folks need to think of? I think, you know, I talked about it a little bit. Like the SEC has teeth. We don't need to wait. So this isn't compliance theater, right? This isn't a let's just say we did some stuff. So we can say we did some stuff. This is something that I will expect to see be audited. I will expect to see financial repercussions. I will expect to see, you know, all of these sorts of things that we're kind of used to seeing within the SEC. But on top of that, I do a lot of due diligence. I do a lot of ODD for our clients. I get on the phone and I speak with potential investors for our clients. And this is what they want to see. So our clients that are covered institutions, like they want it, they don't want to get into bed with somebody that is not doing the bare minimum to protect their data. And that's what they're asking for. Right. Every ODD starts with, I want to see your policies and procedures. Period. And I'm going to ask questions. I'm going to read them and I'm going to ask questions, right? And then then kind of like the final remark on that is AI makes access to information so easy, right? Any contract I get goes into Claude, goes into you know, ~ ChatGPT, goes into Copilot, goes into whatever and says, tell me what I need to know. That's the first step of anything. So you're gonna send a policy or a procedure that you AI generated and doesn't match your actual environment. They're gonna throw that into an AI tool and they're gonna say, is this real or is this crap? And they're gonna know in three seconds, you can't hide things in plain sight anymore. Right. You can't just kinda hide things in obscurity like, I made it a 16 page document that doesn't say anything. They're gonna know, they're gonna know in three minutes everybody's using the tools you have. So that's that's kind of the thing. You can't hide anymore. So you have to do it right the first time. Absolutely. We say that all the time, that we can we can use AI to get us halfway there, but we can't use lazy AI to get us to ~ the cheap food. Yeah. Garbage in, garbage out. Absolutely, I love it. Thanks, Chad. I appreciate the time today. I will ~ let you get back to our clients. Thanks for taking a break and having a chat with us and thanks everyone for listening. Thanks, Jen. Appreciate it.