The questionnaire from a client, an insurer, or an examiner does not ask whether you meant to comply. It asks you to produce things. A written policy. A risk assessment. Proof that a control is really running. If those do not exist, “we take security seriously” is not an answer.
PCI supports firms that live with these rules: law firms, RIAs, family offices, healthcare practices. We do not sell certifications. We make sure the IT under you can produce what you will be asked for, before you are asked.
Performance Connectivity is a managed IT and technology advisory firm in Purchase, NY. We help Westchester and Fairfield County firms meet IT compliance demands: NYDFS Part 500, SEC Reg S-P, NY SHIELD, SOC 2, and cyber-insurance attestations. We do not sell certifications. We make sure the technology under you can produce the written policies, risk assessments, and control evidence an examiner, auditor, insurer, or client will ask for. Before they ask.
Here is who each framework covers, where it stands today, and the plain question underneath it. Can you produce this now, or would you be scrambling? If a line makes you pause, that is the useful part.
One page per framework. The exact items you will be asked for, and one line on what “good” looks like. No jargon, no scare tactics. Tell us what is asking, and it opens right here on this page.
No queue, no rep. The brief appears on this page the moment you submit. A copy goes to Tim, so he can point you to the lines that matter for you.
A copy is on its way to Tim. He reads these himself and will point you to the lines that matter for you. Same business day.
Fifteen minutes with a partner, not a pitch from a rep. Bring the questionnaire, the application, or the examiner’s letter. We will tell you what is ready, what is not, and what is worth doing first.
NYDFS Part 500 is New York's cybersecurity rule for companies licensed by the state's Department of Financial Services. Many RIAs, lenders, and insurance agencies fall inside it. The final rules have been in effect since November 1, 2025. And the first annual certification was due April 15, 2026. It calls for a written cybersecurity policy approved by senior leaders, a current risk assessment, and enforced multi-factor login, among other controls.
Yes. The SHIELD Act applies to any business that holds the private information of New York residents. There is no size limit and no industry carve-out. If you have data on New York residents, you need a written data-security program, proof of employee security training, and an inventory of where that data lives.
SOC 2 is client-driven, not government-mandated. Big clients now want a SOC 2 report before they will sign. So it usually arrives through your own sales pipeline, with a deadline attached. It expects written access controls and change management, proof of ongoing monitoring and logging, and a vendor-risk process an auditor can actually sample.
No. And any IT firm that says it can is overselling. Certifications like SOC 2 come from independent auditors. Compliance is something your firm holds, not something a vendor grants. What we do is make sure the IT under you can produce the policies, risk assessments, and control evidence each framework asks for. So the audit or questionnaire is not a scramble.
That is the exposure. On a cyber-insurance claim, an attestation that turns out to be untrue can mean coverage is denied at the moment you need it most. With a regulator, missing records become findings. The point of getting ready now is simple. "We take security seriously" is not an answer. Producing the document is.