The SFC now holds licensed corporations to clear cybersecurity expectations, and investors probe the same areas in operational due diligence. Our Compliance+ service maps to each one — so your technology stands up to scrutiny, and you have the evidence to prove it.
The SFC's thematic cybersecurity review found half of reviewed firms running end-of-life systems and widespread gaps in cloud security. Circular 25EC7, in effect since February 2025, advises licensed corporations to run a comprehensive technical review — including penetration testing — at least annually; a further June 2026 circular addresses AI-enabled threats. Between them they expect controls across patching, access, monitoring, third-party risk and incident response. For a small firm with no IT department, meeting this alone is not realistic. That's the gap we fill.
A plain-English view of what the regulator looks for and what our managed service delivers against it.
| SFC expectation area | What it means | How Komstadt covers it |
|---|---|---|
| Asset management | Know every device and system you run | Live, automated asset inventory via our management agents |
| End-of-life software | No unsupported operating systems in use | Lifecycle tracking + planned upgrades before support ends |
| Patch management | Timely, verified security updates | Managed patching to a 30-day SLA with monthly evidence |
| Access controls / 2FA | MFA enforced, least-privilege access | MFA across email, remote access and all admins; access reviews |
| Remote access | Secure VPN with controls | Company VPN, session timeouts and IP allow-listing |
| Email & phishing | Anti-spoofing and staff awareness | SPF/DKIM/enforcing DMARC + phishing simulations and training |
| Cloud security | Hardened Microsoft 365 configuration | Conditional access, least-privilege admin, DLP, regular review |
| Data protection & backup | Encrypted, tested backups; recoverable | Managed backup (incl. M365) with tested restores and a DR plan |
| Third-party / vendor risk | Due diligence and SLAs on IT providers | Vendor due-diligence pack and cybersecurity SLAs you can show the SFC |
| Incident response | A plan, and the ability to report | Documented incident-response runbook, contacts and annual drill |
| Governance & oversight | Policies and senior-management visibility | Core IT policies, documentation and quarterly compliance reviews |
Mapping reflects the areas addressed in the SFC's cybersecurity guidance for licensed corporations. It is general guidance, not legal or regulatory advice; your compliance team remains responsible for your obligations.
When an allocator runs operational due diligence, IT and cybersecurity are on the questionnaire. Firms that can answer with evidence — an asset inventory, a tested backup, a vendor due-diligence pack, an incident-response plan — clear ODD faster and look more institutional. We give you that evidence, and keep it current, so the next questionnaire is an attachment, not a scramble.
The same ones the SFC asks licensed firms. Answer honestly — most firms your size score 4–6.
Our complimentary review checks all ten areas in one visit and gives you a written findings report you can show your board, your investors or the SFC. No obligation, no sales deck.
Book your free assessment