Compliance

The requirement is already in effect. Can your IT setup produce the proof?

The questionnaire from a client, an insurer, or an examiner does not ask whether you meant to comply. It asks you to produce things. A written policy. A risk assessment. Proof that a control is really running. If those do not exist, “we take security seriously” is not an answer.

PCI supports firms that live with these rules: law firms, RIAs, family offices, healthcare practices. We do not sell certifications. We make sure the IT under you can produce what you will be asked for, before you are asked.

Performance Connectivity is a managed IT and technology advisory firm in Purchase, NY. We help Westchester and Fairfield County firms meet IT compliance demands: NYDFS Part 500, SEC Reg S-P, NY SHIELD, SOC 2, and cyber-insurance attestations. We do not sell certifications. We make sure the technology under you can produce the written policies, risk assessments, and control evidence an examiner, auditor, insurer, or client will ask for. Before they ask.

The frameworks that apply to you

Each one asks you to produce something specific.

Here is who each framework covers, where it stands today, and the plain question underneath it. Can you produce this now, or would you be scrambling? If a line makes you pause, that is the useful part.

NYDFS Part 500 Covers financial-services companies licensed by New York. Many RIAs, lenders, and insurance agencies fall inside it. The final rules have been in effect since November 1, 2025. And the first annual certification was due April 15, 2026. This is not coming. It is here. Can you produce this today? A written security policy that senior leaders signed off on. A current risk assessment. Proof that MFA is turned on for remote access and admin accounts.
SEC Reg S-P Applies to SEC-registered investment advisers and broker-dealers. The updated safeguards and breach-notice rules reached smaller firms on June 3, 2026. So a firm that used to be out of scope is now in it. Can you produce this today? A written incident-response program for break-ins to customer information. A step to notify affected customers within the required window. A record of which service providers touch client data.
NY SHIELD Act Applies to any business that holds the private information of New York residents. No size limit. No industry carve-out. If you have data on NY residents, it applies to you. Can you produce this today? A written data-security program that names its safeguards. Proof that staff have had security training. A list of where NY-resident data actually lives.
SOC 2 Client-driven, not government-mandated. Big clients of professional-services firms now want a SOC 2 report before they will sign. So it comes through your own sales pipeline, usually with a deadline attached. Can you produce this today? Written access controls and change management. Proof of ongoing monitoring and logging. A vendor-risk process your auditor can actually sample.
Cyber insurance — the de facto framework The application itself now works like a compliance framework. To bind or renew a policy, you attest to specific controls. And if a claim shows the attestation was not true, coverage can be denied when you need it most. Can you produce this today? MFA everywhere the application asks for it. EDR on every device. Tested, restorable backups. And a written incident-response plan you could hand the carrier after a claim.
Other frameworks we support Which frameworks apply depends on your clients and your contracts. We also support businesses working toward HIPAA, PCI-DSS, ISO 27001, and CMMC.
The Compliance Readiness Brief

What each framework expects your IT vendor to produce — in plain English.

One page per framework. The exact items you will be asked for, and one line on what “good” looks like. No jargon, no scare tactics. Tell us what is asking, and it opens right here on this page.

Where should we send it

Your copy opens below, and lands with Tim, who reads it himself.

No queue, no rep. The brief appears on this page the moment you submit. A copy goes to Tim, so he can point you to the lines that matter for you.

5.0 average across 15 Google reviews · Same three partners since 1997.

Straight answers

Straight answers to fair questions.

What is NYDFS Part 500, and who has to comply?

NYDFS Part 500 is New York's cybersecurity rule for companies licensed by the state's Department of Financial Services. Many RIAs, lenders, and insurance agencies fall inside it. The final rules have been in effect since November 1, 2025. And the first annual certification was due April 15, 2026. It calls for a written cybersecurity policy approved by senior leaders, a current risk assessment, and enforced multi-factor login, among other controls.

Does the NY SHIELD Act apply to a small business?

Yes. The SHIELD Act applies to any business that holds the private information of New York residents. There is no size limit and no industry carve-out. If you have data on New York residents, you need a written data-security program, proof of employee security training, and an inventory of where that data lives.

What does SOC 2 require, and why is a client asking us for it?

SOC 2 is client-driven, not government-mandated. Big clients now want a SOC 2 report before they will sign. So it usually arrives through your own sales pipeline, with a deadline attached. It expects written access controls and change management, proof of ongoing monitoring and logging, and a vendor-risk process an auditor can actually sample.

Can PCI make us compliant or issue a certification?

No. And any IT firm that says it can is overselling. Certifications like SOC 2 come from independent auditors. Compliance is something your firm holds, not something a vendor grants. What we do is make sure the IT under you can produce the policies, risk assessments, and control evidence each framework asks for. So the audit or questionnaire is not a scramble.

What happens if we cannot produce the documentation when an examiner or insurer asks?

That is the exposure. On a cyber-insurance claim, an attestation that turns out to be untrue can mean coverage is denied at the moment you need it most. With a regulator, missing records become findings. The point of getting ready now is simple. "We take security seriously" is not an answer. Producing the document is.

30 Years — coming in 2027