Mid-market NYC hedge fund, ~$2B AUM, 60 employees including a growing quant team
Hedge fund stands up full DFS Part 500 program on compressed timeline
- Challenge
- The fund had outgrown its original IT footprint, an investor due-diligence questionnaire had flagged material Part 500 gaps, and the CISO certification deadline was under 120 days away. Existing tooling lacked the vulnerability management, access governance, and third-party oversight depth Part 500 requires.
- Outcome
- We stood up the complete Part 500 program in under 90 days: risk assessment, written policies, MFA everywhere, EDR with 24/7 response, quarterly access reviews, vendor oversight program, tabletop-exercised incident response plan, and a board-ready CISO report. The fund filed its CISO certification on time and cleared the investor DDQ without follow-up.
