Industries·Six we know

Specialists, not generalists.

South Florida's economy is concentrated. So is our practice. We do the work to understand each regulatory landscape we operate inside — and we say no to industries we don't.

01·Financial services

Financial Services & Family Offices

SEC · FINRA · 17a-4 · NYDFS 23

RIAs, hedge funds, private wealth, and family offices. We've built environments around the working day of a portfolio manager and the documentation needs of an SEC examiner — two audiences that rarely align without deliberate engineering.

  • Books-and-records retention on WORM storage, indexed and queryable per 17a-4
  • Communications archive (email, chat, mobile SMS, voice) with surveillance hooks
  • Identity isolation between trading systems and general productivity
  • Bloomberg / FactSet / OMS integration on segregated VLANs
  • Same-day evidence packets for regulatory exams
  • Cyber-insurance attestation aligned to NYDFS 23 NYCRR 500 / Florida §501.171
03·Healthcare

Healthcare & Dental

HIPAA · HITECH · FL §456.057

Multi-location medical practices, surgery centers, and dental groups. PHI safeguards are baseline — what separates a clean OCR audit from a bad one is documentation discipline. We carry the discipline so you don't have to.

  • Annual HIPAA risk analysis on the OCR Audit Protocol
  • Business Associate Agreement stack with downstream subcontractors mapped
  • EHR vendor liaison — Athena, eClinicalWorks, Epic, Open Dental, Dentrix
  • Breach-notification readiness — pre-drafted templates, regulator escalation paths
  • Workstation lock-down and PHI-on-screen mitigations for waiting-area machines
  • Medical-device network segmentation (imaging, infusion, EKG)
04·Hospitality

Hospitality & Restaurants

PCI DSS 4.0 · PA-DSS · FL §501.171

Hotels, resorts, and restaurant groups. Our objective is to shrink your cardholder data environment to as close to nothing as the payment gateway will allow, and segment the guest network so the IoT estate doesn't take down the front desk on a Saturday night.

  • P2PE-aware payment paths and tokenization — scope reduction first
  • Guest-network isolation with captive portal and bandwidth shaping
  • POS vendor liaison — Toast, Aloha, Micros, Lightspeed
  • Property management system (PMS) integration on hardened identity
  • IoT-estate inventory and segmentation (locks, thermostats, AV)
  • PCI quarterly scans and annual attestation evidence
05·Accounting & real estate

Accounting & Real Estate

IRS Pub 4557 · FTC Safeguards · FREC

CPA practices, brokerages, title agencies. The FTC Safeguards Rule landed teeth in 2023 — what was historically "best practice" is now an enforceable duty. WISP documentation, implemented controls, and an annual review fall in our lane.

  • Written Information Security Plan (WISP) drafted, signed, and reviewed annually
  • IRS Publication 4557 control mapping for tax-preparer obligations
  • Wire-fraud defense — bank-account verification flows, dual-control approvals
  • Tax-season surge support — temporary capacity, no rate inflation
  • Closing-document and earnest-money handling for title agencies
  • Client-portal hardening with MFA and watermarking
06·Architecture & creative

Architecture & Creative Studios

TPN · M&E security · MPA tier

Architecture firms, post-houses, and design studios. Big files, long render queues, vendor IP segregation, color-managed pipelines — and the occasional ransomware actor who has noticed creative shops carry uninsured studio assets.

  • Large-asset workflows on tiered storage (NVMe → spinning → object)
  • Render-node provisioning, on-prem or burst-to-cloud
  • Vendor-IP segregation per project, with NDA-bound access logs
  • Color-managed pipelines, calibrated display fleet, hardware lifecycle
  • Off-site mastered backups with air-gapped quarterly archive
  • TPN content security audit readiness
Out of scope

We say no to a lot.

Industries we don't take on, because doing them well requires either depth we lack or trade-offs that conflict with how we operate. We will refer to specialists we trust.

Federal & DoD prime contracts (CMMC L3+) Critical infrastructure (electric, water, gas) Cryptocurrency exchanges & custody Cannabis vertical (regulatory volatility) Adult content / gambling platforms K–12 / higher-ed (different bidding model)
Next

Yours one we know?

Tell us what your industry's quirks are. We'll tell you honestly if we're the right fit.

Talk to an engineer