
Small funds get IT wrong in a specific way: they buy a generic small-business setup, then discover during an investor due diligence questionnaire or an SEC exam that it doesn't answer the questions being asked. These are the ten questions The NetSys Group fields most often from COOs and CFOs at NY-metro funds running 10 to 50 people.
Questions fund COOs ask
What does IT support for a hedge fund actually include?
The usual managed IT — help desk, patching, backup, device management — plus four things a general provider often skips:
- Archived and searchable communications across every channel your staff actually use.
- Documented access controls you can hand to an examiner without a scramble.
- Market data and trading application support.
- A written incident response plan. That one's now a rule, not a nice-to-have.
Did we miss the Reg S-P incident response deadline?
Probably, if you haven't done it. The SEC's 2024 amendments require covered institutions to develop, implement, and maintain written policies and procedures for an incident response program. Larger entities had to comply by December 3, 2025; smaller entities by June 3, 2026. Both dates have passed. Advisers under $1.5 billion AUM fell in the smaller-entity group.
How fast do we have to tell investors about a breach?
Thirty days. Reg S-P requires notice as soon as practicable, but not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred.
Read that trigger carefully — it fires on reasonable likelihood, not on confirmation. You can't investigate for six weeks first. We covered the detail in our guide to Reg S-P for RIAs.
Do we still have to archive WhatsApp and text messages?
Yes, and the reason has shifted. Advisers Act Rule 204-2 requires you to keep written communications about advice, orders, and the movement of funds for not less than five years. The obligation follows the content, not the app.
The SEC's off-channel enforcement sweep produced 95 actions and $2.3 billion in penalties before the current Commission repudiated it in April 2026 as a misreading of the law. The recordkeeping rule itself is unchanged.
What's our real wire fraud exposure?
Higher than your headcount suggests, because the payments are large and the approval chain is short. The FBI's 2025 Internet Crime Report logged $3.05 billion in business email compromise losses across 24,768 complaints. That's all sectors, not fund-specific, but the mechanism is identical: a fund moving seven-figure subscriptions and redemptions through a two-person approval chain is a soft target.
The control that works is a callback to a known number on every payment instruction change, with no exception for the CIO. More in our BEC guide.
Does Reg S-ID apply to us?
Sometimes. The SEC says covered entities include some registered investment advisers — generally those holding transaction accounts for individuals, or able to direct transfers to third parties on an investor's instruction. A manager whose only clients are the funds themselves often falls outside it.
Run separately managed accounts and you should assume you're in.
Cloud or on-premises for a fund our size?
Cloud, in almost every case. A 20-person fund gets better security, better continuity, and a cleaner audit story from Microsoft 365 and Azure than from a server closet nobody has time to maintain.
The exception is a trading or data application that genuinely needs local hardware or low latency. Run that on its own network segment, not on a general file server.
How should traders and analysts connect from home?
Through managed devices with conditional access, not a shared VPN. The pattern that holds up in a due diligence questionnaire has four parts:
- A company-owned or enrolled device.
- Phishing-resistant MFA.
- Access granted per application, not per network.
- No company data on unmanaged personal machines.
A flat VPN that drops a home laptop onto the office network is what examiners and allocators ask about first.
What do investor due diligence questionnaires actually ask about IT?
Consistently, six things:
- Who has administrative access, and how that access is reviewed.
- Whether MFA is enforced everywhere.
- Backup and recovery time objectives.
- Your written incident response plan, and when it was last tested.
- Vendor risk management for critical service providers.
- Whether you've had a security incident.
Have documented answers ready before an allocator asks, not after.
In-house IT, an MSP, or both?
Below about 40 people, an outsourced provider plus a fractional security leader usually beats a single internal hire. You get coverage across more disciplines, and you're not exposed when one person takes vacation. Above that, a hybrid works: one internal person who knows the business, with a co-managed IT partner for depth and after-hours. A virtual CISO covers the policy and exam-readiness work either way.
Talk to NetSys about fund IT
If you're preparing for an exam, responding to an allocator's questionnaire, or just tired of an IT provider who doesn't know what Reg S-P is, The NetSys Group works with funds and advisers across New York, New Jersey, and Connecticut. See our hedge fund IT page, or get in touch for a free risk assessment.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



