Attention Managing Partners: Stop Assuming Compliant and Secure Are the Same Thing

Attention Managing Partners: Stop Assuming Compliant and Secure Are the Same Thing

In Q3 2026 alone, our clients avoided over $1.2 million in fraudulent wire transfers and payments to accounts controlled by criminals.

These attempts started with a phishing email that got an employee to hand over credentials. A second was worse: an attacker hijacked an SMS-based MFA token and walked straight past the “second factor” that leadership assumed was protecting them.

Case in point: Microsoft is retiring SMS and voice as authentication methods in Entra ID. Passkeys became the default sign-in experience as of September 2026. Microsoft-provided SMS and voice delivery is being phased out entirely by February 2027.

Microsoft doesn’t fast-track anything. When a company running identity infrastructure for a meaningful share of the Fortune 100 moves that fast to kill a feature, that’s not a UX decision. That’s an admission that SMS-based MFA has become a major, active liability.

Every financial firm still leaning on a text-message code as its “second factor” should read that as a five-alarm signal, not a line item for next year’s roadmap.

The pivot needs to happen now. Firms need single sign-on consolidated through a real identity provider, paired with phishing-resistant authentication, a hardware security key or a passkey held in a password manager. Not a text message an attacker can intercept. Not a SIM they can swap.

I’m not writing this to brag about the save.

I’m writing it because every one of those catches happened despite how most financial firms are organized, not because of it. And I’m tired of the security industry tiptoeing around the actual cause.

Here it is, plainly: nobody’s arguing that compliance, security, and IT call for different skill sets. Everyone already agrees on that.

Where financial firms get it wrong is the chain of command. They let security report through IT, or through compliance, or through whoever’s convenient, instead of giving it its own accountability straight to the top.

That structural failure, a chain of command built by boards and executive teams with no security expert in the room to challenge it, is why the bad guys keep winning.

The FBI’s BEC numbers climbed again this year. They climbed because security isn’t a priority with the authority to say no.

Employees call IT to fix problems. Compliance checks boxes. Security is the overwatch.

A Security Operations Center watches and monitors continuously. When it finds a problem, it acts before the problem becomes an incident. Everyone else in the org chart reacts.

A good SOC doesn’t solve problems. It stops them before they ever have the chance to happen.

When you bury that function inside IT or hand it to compliance as a side responsibility, you don’t just create an inefficiency. You arm the attacker.

Compliance turns security into a checkbox: policies written, audits passed, breach happens anyway.

IT turns security reactive: respond to the ticket, keep the lights on, worry about the phishing-resistant MFA migration next quarter.

Either way, the one function built to act before the damage is done gets stripped of the authority to act at all.

Let’s be precise about this, because too many boardrooms still conflate two things. A financial firm can pass an SEC exam with flying colors, sail through a compliance audit, and get breached the next morning.

Compliant and secure are not the same thing.

One measures whether you followed the rules on paper. The other measures whether an attacker can get in.

You can score 100% on the first and still be wide open on the second. And if compliance is the only lens your firm uses to judge its own security, you will not find out which one you actually are until it’s too late.

That’s exactly where ATG plants its flag.

We are not in the business of helping you pass an SEC exam. That’s compliance’s job, and it should be, because the SEC has real authority to pull a license or levy a penalty, and someone at your firm needs to own that risk.

ATG is in the business of one thing: making sure client data and the assets under management sitting behind your systems are 100% secured.

Compliance’s job is passing the exam. IT’s job is keeping the lights on. ATG’s job is making sure the data and the AUM are actually secure. Three different jobs. Firms keep collapsing them into two, folding security into whichever one is convenient. It unequivocally needs to be three. Hoping the SEC catches the gap before an attacker does is not a strategy, and it isn’t working, not according to what the FBI is reporting.

Stop Assuming Security Is a Function of Compliance, or Something IT Can Handle

Five years ago, folding security into IT or compliance was almost defensible. Most financial firms were still running on-premise, and the attack surface was mostly contained inside your own walls.

Then COVID hit. Everyone went remote overnight, and firms rushed to the cloud just to keep functioning, which was every cyber criminal’s dream: exposed endpoints, home networks, VPNs stood up in a weekend, employees clicking on anything that looked like a helpdesk request.

That shift is exactly what should have pulled security out into its own independent role. For a lot of firms, it never did.

Everything evolved but the org chart.

Security just stayed assumed into whichever function was already in the room: compliance treats it as a subset of the regulatory checklist, or IT treats it as another ticket type.

Either way, security never becomes its own function. It becomes a chore quietly attached to somebody else’s job description.

Look at the actual job descriptions and you’ll see why this fails on its own terms. The compliance officer’s job description is clear, and it matters: interpret the regulation, file the paperwork, pass the exam.

IT’s job description is just as defined, and it’s a list of fires: fix the printer, resolve the blue screen, replace the broken laptop, order the new monitor, reset the password nobody remembers. That’s a full day before lunch.

Security can’t be a line in either job description. It’s the one thing everyone agrees matters, that almost nobody fully understands the complexity of, and that nobody has the time to prioritize. So it gets kicked down the road, and that’s how security holes get created.

That complexity isn’t static, either. Security is dynamic: threats change, systems change, and everything today is connected to everything else. A vendor’s API, a home network, a cloud app nobody remembers approving: any one of them can be the way in. That interconnectedness is exactly why getting this role right matters more now than it ever has.

So what does real security ownership actually look like, day to day? The CISO, or in ATG’s case the SOC (security operations center), is there to question everything. Every access grant, every application, every third-party connection into the tech stack gets scrutinized and assigned a risk factor.

Nothing gets a pass because it’s convenient, because IT is in a hurry, or because a vendor relationship predates the last security review.

If it touches the tech stack, resides on a laptop, or has a login, it gets questioned. If it can’t justify itself, it gets flagged, restricted, or removed.

This Isn’t a Budget Problem. It’s an Org Chart Problem.

None of this requires a bigger org chart. It requires three decisions your firm’s leadership has probably been avoiding:

Compliance keeps regulatory interpretation and attestation, and loses the authority to run security operations or wave off a security exception.

IT keeps infrastructure and uptime, and loses the authority to slow-walk a security finding because it’s inconvenient for this quarter’s roadmap.

Security, whether an in-house CISO or an outsourced SOC, gets its own reporting line straight to the top, with explicit standing to flag risk in what compliance signs off on and what IT ships.

Most firms don’t actually need to hire a CISO, and not for the reason you’d expect.

Hire one, and the first thing that CISO does is start assigning security roles and responsibilities.

From there, there are only two paths: build a dedicated security team under them, which is expensive and slow to stand up, or hand those roles back to whoever’s already in the building, which almost always means IT.

That second option is the fatal blow. You just spent the budget and the political capital to install independent oversight, and the first real decision that CISO makes recreates the exact conflict of interest this entire piece is about: it hands the security function right back to the IT team.

If you’re too small for a full-time CISO, that’s not an excuse.

It means your outsourced security function still needs to report to leadership independently of whoever runs your IT. It should not live as a line item buried inside the IT services contract, where it has no teeth.

And when I say “outsourced security function,” I don’t mean a single contractor wearing a CISO title. I don’t mean a call center triaging your tickets by whoever happens to pick up.

One person can’t be the security apparatus for a financial firm. The scope of it, the round-the-clock monitoring, the breadth of systems and access to watch: it isn’t a one-person job, no matter how good that person is.

ATG’s answer is a Security Operations Center: a dedicated team of six people assigned to your account, specifically. Not a rotating queue.

The same team handles every email, every phone call, every Teams meeting. They’ve spent the time becoming experts inside your business: your systems, your risk profile, your people. That’s instead of starting from zero on every ticket like a help desk would.

The $1.2 Million Wasn’t a Tooling Win. It Was an Authority Win.

Every one of those catches happened because a team with real independence looked at a transaction or a login and had the standing to say “this doesn’t check out” before anyone hit submit. Compliance wouldn’t have caught this. IT wouldn’t have caught this. Structure did.

The FBI’s BEC numbers do not have to keep climbing every year.

They keep climbing exactly as long as CEOs and managing partners keep treating security as IT’s problem or compliance’s checkbox instead of what it actually is: an independent function with the authority to stop a loss before it happens.

Fix the org chart, and that number starts moving the other way.

Leave it broken, and you’re not unlucky when it happens to you. You’re next.

The FBI’s numbers need to stop climbing. ATG is going to make that happen.