---
title: Should IT Companies In San Francisco Support FINRA Cybersecurity Compliance?
description: Even though FINRA has made an effort to support organizations’ cybersecurity practices with detailed resources, these resources are not always as easy to understand and implement as they should be. Ar
---

[Skip to the main content.](https://ontimetech.valeonetworks.com/blog/it-companies-in-san-francisco#main-content)

[![OTT powerd by VN big](https://ontimetech.valeonetworks.com/hs-fs/hubfs/OTT%20powerd%20by%20VN%20big.png?width=500&height=175&name=OTT%20powerd%20by%20VN%20big.png "OTT powerd by VN big")](https://ontimetech.valeonetworks.com)

[![OTT powerd by VN big](https://ontimetech.valeonetworks.com/hs-fs/hubfs/OTT%20powerd%20by%20VN%20big.png?width=500&height=175&name=OTT%20powerd%20by%20VN%20big.png "OTT powerd by VN big")](https://ontimetech.valeonetworks.com)

- [Services](https://ontimetech.valeonetworks.com/our-services/) 
    - [Managed It Services](https://ontimetech.valeonetworks.com/our-services/managed-it/)
    - [Cybersecurity](https://ontimetech.valeonetworks.com/our-services/cybersecurity/)
    - [Cloud Solutions](https://ontimetech.valeonetworks.com/our-services/cloud-solutions/)
    - [Compliance](https://ontimetech.valeonetworks.com/our-services/compliance/)
- [Industries](https://ontimetech.valeonetworks.com/industries/)
- [Resources](https://ontimetech.valeonetworks.com/resources/) 
    - [Blog](https://ontimetech.valeonetworks.com/blog)
- [About](https://ontimetech.valeonetworks.com/about/) 
    - [Client Testimonials](https://ontimetech.valeonetworks.com/testimonials/)

[415-294-5250](tel:4152945250) [Client Portal](https://portal.Valeonetworks.com)

Toggle Menu

Toggle Menu

[415-294-5250](tel:4152945250) [Client Portal](https://portal.Valeonetworks.com)

- [Services *Toggle Menu*](https://ontimetech.valeonetworks.com/our-services/) 
    - [Managed It Services](https://ontimetech.valeonetworks.com/our-services/managed-it/)
    - [Cybersecurity](https://ontimetech.valeonetworks.com/our-services/cybersecurity/)
    - [Cloud Solutions](https://ontimetech.valeonetworks.com/our-services/cloud-solutions/)
    - [Compliance](https://ontimetech.valeonetworks.com/our-services/compliance/)
- [Industries](https://ontimetech.valeonetworks.com/industries/)
- [Resources *Toggle Menu*](https://ontimetech.valeonetworks.com/resources/) 
    - [Blog](https://ontimetech.valeonetworks.com/blog)
- [About *Toggle Menu*](https://ontimetech.valeonetworks.com/about/) 
    - [Client Testimonials](https://ontimetech.valeonetworks.com/testimonials/)

- Example Link
- Example Link
- Example Link

[*Facebook*](https://ontimetech.valeonetworks.com/blog/it-companies-in-san-francisco#0) [*Instagram*](https://ontimetech.valeonetworks.com/blog/it-companies-in-san-francisco#0) [*LinkedIn*](https://ontimetech.valeonetworks.com/blog/it-companies-in-san-francisco#0) [*Twitter*](https://ontimetech.valeonetworks.com/blog/it-companies-in-san-francisco#0) [*Youtube*](https://ontimetech.valeonetworks.com/blog/it-companies-in-san-francisco#0) [*Medium*](https://ontimetech.valeonetworks.com/blog/it-companies-in-san-francisco#0)

 4 min read

# Should IT Companies In San Francisco Support FINRA Cybersecurity Compliance?

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/ulisticadmin) :  Feb 4, 2020, 9:52:08 AM

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services)

## IT Companies In San Francisco Can Help With FINRA Cybersecurity Compliance

Being secure and being FINRA compliant are almost the same thing. FINRA’s all about protecting the customer’s information (and what happens when you can’t), which is really a matter of your cybersecurity. Whichever of the local [**IT companies in San Francisco**](https://www.ontimetech.com/) you work with should be helping you stay compliant and secure - are they?

Whether you have expert support or not, the good news is that you don’t have to start from scratch on your own. FINRA has some resources available to help you develop effective and compliant [cybersecurity](https://www.ontimetech.com/blog/cybersecurity-services/), such as their [**Report On Selected Cybersecurity Practices**](https://www.finra.org/sites/default/files/Cybersecurity_Report_2018.pdf).

Have you read and understood this resource?

### A FINRA Cybersecurity Primer

Before we get to the recommended best practices, let’s examine the foundation of FINRA [compliance](https://www.ontimetech.com/compliance/). The bottom line is that compliance is determined by your firm’s ability to protect the confidentiality, integrity, and availability of sensitive customer information, then it means following these three regulations:

- **Written Policy**  
   Regulation S-P ([17 CFR §248.30](http://www.ecfr.gov/cgi-bin/text-idx?SID=226b4b62d8bf25d29cc88df5039cddde&mc=true&node=se17.4.248_130&rgn=div8)), which requires firms to adopt written policies and procedures to protect customer information against cyber-attacks and other forms of unauthorized access
- **Identity Theft Prevention**  
   Regulation S-ID ([17 CFR §248.201-202](http://www.ecfr.gov/cgi-bin/text-idx?SID=5621786ec1a831400e4b64f3e92198bd&mc=true&node=pt17.4.248&rgn=div5#sp17.4.248.c)), which outlines a firm's duties regarding the detection, prevention, and mitigation of identity theft
- **Data Storage**  
   The Securities Exchange Act of 1934 ([17 CFR §240.17a-4(f)](http://www.ecfr.gov/cgi-bin/text-idx?SID=b6b7a79d18d000a733725e88d333ddb5&mc=true&node=pt17.4.240&rgn=div5#se17.4.240_117a_64)), which requires firms to preserve electronically stored records in a non-rewriteable, non-erasable format

From there, we can examine the best practices that FINRA recommends…

### 5 Key Cybersecurity Best Practices Recommend By FINRA

**1. Keep Data Safe Where Branches Are Concerned**  
 Your onsite cybersecurity measures will not extend to the branch level. That’s why Written Supervisory Procedures (WSPs) are so important. They dictate exactly how branches are expected to protect data. Requirements could include:

- Mandatory security controls
- Notifications concerning issues and breaches
- Accepted security settings and vendors
- Assignment of duties and responsibilities pertaining to cybersecurity controls
- Training curriculum and testing protocols

**2. Understand And Prevent Phishing Attacks**  
 Phishing emails are typically crafted to deliver a sense of urgency and importance, tricking the user into doing what the cybercriminal wants them to. The message within these emails often appears to be from the government, a bank or a major corporation and can include realistic-looking logos and branding.

Phishing succeeds when a cybercriminal uses fraudulent emails or texts, and counterfeit websites to get the user to share their personal or business information like their login passwords, Social Security Number or account numbers. They do this to rob a user or organization of their identity and/or steal their money.

The key phishing’s effectivity is how unsuspecting the target is. The fact is that businesses aren't learning to protect themselves, which is why the number of reported phishing attacks has gone up [**by 65%**](https://cofense.com/wp-content/uploads/2017/11/Enterprise-Phishing-Resiliency-and-Defense-Report-2017.pdf) in the past few years.

Unfortunately, many users aren’t skeptical enough to spot a scam. In fact, [**more than half of all Americans**](https://retruster.com/blog/2019-phishing-and-email-fraud-statistics.html) say they’ve been the victim of a scam. That’s why comprehensive security awareness training is so important - it teaches your staff members to identify phishing emails and learn how to contribute to your cybersecurity.

Cybersecurity awareness training is becoming a more and more common part of modern IT services. The fact is that users are a key target for cybercriminals; the more they know about cybercrime tactics, the better defended your organization will be.

**3. Make Your Users A Cybersecurity Asset**  
 More often than anything else, security isn’t a matter of antivirus software, or unhackable blockchains, or anything else like that. The truth is that security facets like that are surface-level – what's at the core of security?

The user. Think about it – how many times have you used a password that’s easy to remember, but not really secure enough for the information it’s supposed to protect? How often have you stayed logged in to an app out of convenience, even when it posed a theoretical security risk to the data accessible therein? When was the last time you misplaced a smartphone, or a tablet, or a laptop? If it belongs to the business you work for, have you considered what’s at risk?

This is why you need to have a carefully implemented process to track the lifecycle of accounts on your network.

- Follow a careful system for how accounts are created for new members, how their security is maintained and verified through their life, and how they are removed when no longer needed.
- Implement secure configuration settings (complex passwords, multi-factor authentication, etc.) for all accounts.
- Implement controls for login and use, such as lockouts for too many unsuccessful logins, unsuccessful login alerts, and automatic log-off after a period of inactivity

**4. Confirm Your Cybersecurity Effectiveness**  
 You can’t just assume your cybersecurity is effective - you need to test and find out for sure. Penetration testing is a valuable exercise in which you let one of the local [**IT companies in San Francisco**](https://www.ontimetech.com/) attempt to break through your organization’s cybersecurity defenses, determining precisely where your vulnerabilities may be.

FINRA recommends running penetration tests both on a regular basis, as well as after key events – anything really that makes significant changes to your firm’s infrastructure, staffing, access controls, or other cybersecurity-based considerations.

**5. Keep Data Protected On Mobile Platforms**  
 It's no surprise that mobile devices are continuing to become a central and necessary part of the business world. What might be surprising is how unprepared some businesses are for that reality.

No matter what kind of cybersecurity you have in place at the office, it won’t extend to the mobile devices that have access to your data. This is a critical limitation of your cybersecurity software, and it’s obvious when you think about it – if your firewall is only installed on your work devices, but you let employees use personal devices and home workstations to access business data, then obviously you won’t be totally secure.

That’s why mobile security is so important. Maintaining mobile security isn’t just about having the right apps – it means following the right protocols, to eliminate unknown variables and maintain security redundancies:

- Review installed apps and remove any unused ones on a regular basis.
- Review app permissions when installing, and when updates are made.
- Enable Auto Update, so that identified security risks are eliminated as quickly as possible.
- Keep data backed up to the cloud or a secondary device (or both).

If you really want to, technically, you can ignore FINRA’s [**Report On Selected Cybersecurity Practices**](https://www.finra.org/sites/default/files/Cybersecurity_Report_2018.pdf)**.** But it wouldn’t be smart. This resource exists to help make FINA compliance simpler. Combined with expert support from one of your local [**IT companies in San Francisco**](https://www.ontimetech.com/)**,** you achieve a cybersecurity and compliance posture robust enough that you don’t have to worry about it.

On Time Tech can help. Our team has experience successfully completing FINRA assessments, IT Security Audits, and delivering cybersecurity best practices consulting in both private and public sector environments of all sizes. Our streamlined assessment process can guide you through becoming compliant in as little as one day - all you have to do is reach out to our team.

Like this article? Check out the following blogs to learn more:

[**2020 Outlook: Why Are Countries Such as China Sponsoring Cyberterrorism Against Their Enemies?**](https://www.ontimetech.com/blog/cyberterrorism/)

[**The Cybersecurity Threats from China No One is Talking About**](https://www.ontimetech.com/blog/china/)

[**Cloud Security: Is the Cloud Safe to Store Your Data In?**](https://www.ontimetech.com/blog/cloud-security/)

- [Tweet](https://twitter.com/share)

#### ![BusinessOwnerGuidetoM&A-1](https://ontimetech.valeonetworks.com/hs-fs/hubfs/BusinessOwnerGuidetoM%26A-1.png?width=303&height=209&name=BusinessOwnerGuidetoM%26A-1.png)

#### Download our eBook*THE ULTIMATE ROADMAP TO CMMC COMPLIANCE* by filling out the form below!

[![How Accounting Software is Helping Countless SMBs Save Time, Money and Resources](https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/ThinkstockPhotos-655567024.jpg)](https://ontimetech.valeonetworks.com/blog/how-accounting-software-is-helping-countless-smbs-save-time-money-and-resources)

#### [How Accounting Software is Helping Countless SMBs Save Time, Money and Resources](https://ontimetech.valeonetworks.com/blog/how-accounting-software-is-helping-countless-smbs-save-time-money-and-resources)

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/ulisticadmin) : Oct 26, 2017, 12:14:00 PM

It’s a familiar story and every business has been there. Deadlines are looming, customer requests are at an all-time high and to-do lists are longer...

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services) 

[Read More](https://ontimetech.valeonetworks.com/blog/how-accounting-software-is-helping-countless-smbs-save-time-money-and-resources)

#### [Effective Resource Management](https://ontimetech.valeonetworks.com/blog/itsolutions/effective-resource-management)

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/ulisticadmin) : Apr 24, 2018, 5:25:13 AM

Your success is directly related to effective resource management, especially in today’s fast-paced world. If your employees don’t work productively...

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services) 

[Read More](https://ontimetech.valeonetworks.com/blog/itsolutions/effective-resource-management)

#### [Confident In Your FINRA Compliance? Have One Of Your San Francisco IT Companies Make Sure](https://ontimetech.valeonetworks.com/blog/confident-in-your-finra-compliance-san-francisco-it-companies-make-sure)

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/ulisticadmin) : Feb 26, 2020, 3:46:04 PM

Your San Francisco IT Company Can Make Sure Your Business Is FINRA Compliant When was the last time you had your FINRA compliance assed by someone...

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services) 

[Read More](https://ontimetech.valeonetworks.com/blog/confident-in-your-finra-compliance-san-francisco-it-companies-make-sure)

![OTT White logo](https://ontimetech.valeonetworks.com/hs-fs/hubfs/VN%20-%20Division%20Logos/OTT%20Logo/OTT%20White%20logo.png?width=524&height=140&name=OTT%20White%20logo.png)

 

##### About

About

On Time Tech is an IT Support and Computer Services company serving California. We provide services to the areas in and around We know businesses like yours need technology support in order to run highly-effective organizations. Leverage pro-growth technology services for your company now.

##### Explore On Time Time

Explore On Time Time

- [Our Services](https://ontimetech.valeonetworks.com/our-services/)
- [Industries](https://ontimetech.valeonetworks.com/industries/)
- [Resources](https://ontimetech.valeonetworks.com/resources/)
- [About](https://ontimetech.valeonetworks.com/about/)
- [Contact](https://ontimetech.valeonetworks.com/contact/)

##### Contact

Contact

**San Francisco:**  
1717 Fifth Ave  
San Rafael, CA 94901

[415-294-5250](tel:4152945250)

Business Hours:   
M-F: 8AM-9PM

- [Privacy Policy](https://ontimetech.valeonetworks.com/privacy-policy/)

© 2026 On Time Tech

[*Facebook*](https://www.facebook.com/ontimetechsf/)[*Twitter*](https://twitter.com/on_time_tech?lang=en)[*LinkedIn*](https://www.linkedin.com/company/ontimetech/)[*YouTube*](https://www.youtube.com/channel/UCubqs9PU_WWF-RFhfK9xNpw)

[![Alura White logo](https://ontimetech.valeonetworks.com/hs-fs/hubfs/VN%20-%20Division%20Logos/Alura%20White%20logo.png?width=295&height=115&name=Alura%20White%20logo.png)](https://alura.valeonetworks.com/) [![Next.I.T._White-Logo](https://ontimetech.valeonetworks.com/hs-fs/hubfs/Next.I.T._White-Logo.png?width=328&height=136&name=Next.I.T._White-Logo.png)](https://next-it.net/) [![White-OTT-Logo-1-768x253](https://ontimetech.valeonetworks.com/hs-fs/hubfs/White-OTT-Logo-1-768x253.png?width=313&height=103&name=White-OTT-Logo-1-768x253.png)](https://www.ontimetech.com/) [![Valeo-Logo-White (1)](https://ontimetech.valeonetworks.com/hs-fs/hubfs/Valeo-Logo-White%20(1).png?width=288&height=123&name=Valeo-Logo-White%20(1).png)](https://valeonetworks.com/)

*Return to Top*

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Lance Stone",
    "url" : "https://ontimetech.valeonetworks.com/blog/author/ulisticadmin"
  },
  "dateModified" : "2024-01-10T16:36:40.581Z",
  "datePublished" : "2020-02-04T14:52:08.000Z",
  "headline" : "Should IT Companies In San Francisco Support FINRA Cybersecurity Compliance?",
  "mainEntityOfPage" : {
    "@id" : "https://ontimetech.valeonetworks.com/blog/it-companies-in-san-francisco",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://ontimetech.valeonetworks.com/hubfs/OTT%20-%20Color%20Logo.png"
    },
    "name" : "Valeo Networks"
  }
}
```