Your Ultimate FINRA Cybersecurity Survival Checklist

Your Ultimate FINRA Cybersecurity Survival Checklist

Man at computer doing multi-factor authentication for cybersecurity inspection
Cyber, Remote Work, and Remediation: Closing Out Inspection Season Strong | MCG Consulting

MCG Consulting • Compliance Insights

Cyber, Remote Work, and Remediation: Closing Out Inspection Season Strong

The final stretch of a year-end branch inspection: securing the environment, supervising where people actually work now, and making sure findings don't just sit in a file.

This series has walked through the core of a year-end FINRA Rule 3110 inspection: documentation and complaints, outside activities, communications, records, and Reg BI. This final post covers the pieces that have changed the most in recent years, because remote work and evolving cyber risk have reshaped what a thorough branch review looks like: cybersecurity and physical security, remote and hybrid office supervision, and what happens after the inspection report is signed.

1. Cybersecurity and Physical Security

Branch inspections increasingly double as a cybersecurity checkpoint. Examiners expect firms to verify, in person or through documented remote testing, that a branch's technical and physical safeguards match what's written in the firm's cybersecurity and privacy policies.

What a thorough review covers

  • Access controls: who can reach client data, and whether the firm actually terminated departed employees' access
  • Device encryption and patching status on branch workstations and firm-issued mobile devices
  • Secure disposal procedures for paper records and old hardware
  • Physical security of the location: locked file storage, visitor logs, and screen privacy in client-facing areas
  • Confirmation that Reg S-P and Identity Theft Red Flags procedures are actually being followed at the branch level, not just documented at the home office
Why it matters

A written information security policy that does not reflect day-to-day branch practice is one of the more common gaps examiners identify: the policy exists, but nobody checked whether the branch is actually following it.

2. Remote and Hybrid Office Supervision

With remote and hybrid arrangements now standard at many firms, inspection programs have had to adapt beyond the traditional walk-through. The core question remains the same as it has always been: is this location properly supervised? The evidence, however, looks different, especially for firms using the Remote Inspections Pilot Program or designating a Residential Supervisory Location.

  • Confirm the location is properly classified (branch, non-branch, residential supervisory location) and inspected at the required frequency for that classification
  • Verify remote inspection procedures, such as video walkthroughs, screen-sharing reviews, and remote document requests, are documented and consistently applied
  • Check that reps working from home have adequate safeguards for client information, including secure networks and locked storage
  • Confirm supervisors have visibility into communications and activity occurring outside a traditional office setting
  • Review any residential supervisory location eligibility criteria to confirm the location still qualifies

3. Follow-Up and Remediation Tracking

An inspection that identifies findings but has no mechanism for closing them out is, from an examiner's perspective, barely better than no inspection at all. Therefore, year-end is the right time to confirm that every open item from this year, and any carried over from prior years, has an owner and a deadline.

Remediation tracking essentials

  • A centralized log of findings across all branches, not separate spreadsheets per location
  • A named owner and target completion date for every open item
  • Evidence of completed remediation, not just a status marked "resolved"
  • A process for escalating findings that remain open past their deadline
  • Trend analysis across years to catch recurring findings at the same branch or with the same rep
Common gap

Recurring findings, the same issue flagged two or three years running, are a red flag to examiners that the remediation process is not actually changing behavior at the branch level.

Heading Into Year-End

Taken together, this series covers the full scope of what a modern branch inspection program under Rule 3110 needs to address: documentation, complaints, outside activities, communications, records, Reg BI, cybersecurity, remote supervision, and remediation. Firms that treat these as one integrated program, rather than a checklist completed once a year, tend to walk into exams with far fewer surprises.

Close Out Inspection Season With Confidence

MCG Consulting helps firms build cybersecurity reviews, remote supervision protocols, and remediation tracking systems that satisfy examiners and hold up year after year.

Talk to Our Team
© 2026 MCG Consulting • mcgcomply.com • This content is for informational purposes and does not constitute legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *

Post comment