
DESSS helps New York banks, fintechs, media companies, health systems, property firms and law practices meet NYDFS expectations, lock down privileged access and detect intrusions early, with assessment, implementation and managed support delivered by one accountable team.
DESSS provides cybersecurity assessment, implementation, and managed support to New York organizations across fifteen practice areas: the Microsoft security stack (Active Directory, Entra, Defender, Intune, and Purview), identity governance and PAM, SOC and MDR, penetration testing and red teaming, cloud security, Zero Trust networking, endpoint and email security, data protection, GRC, including NYDFS 23 NYCRR 500 readiness, application security, and OT and IoT security.
DESSS is a Texas firm headquartered in Houston, and it works with New York clients remotely, using the same practice teams and written deliverables for every engagement.
Here, a security program is judged by outsiders long before an attacker tests it. A regional bank or insurer answers to examiners from the New York State Department of Financial Services. A fintech startup is asked for evidence by the bank partners that hold its customer funds. A law firm fills out security questionnaires from corporate clients before it can join a panel, and a publisher has to keep unreleased stories and subscriber data away from people who want them. The work behind our cybersecurity services in New York is making those controls real, documented and repeatable, so the next audit, client review or renewal is a matter of handing over evidence.
The threats aimed at the city follow the money and the information. Business email compromise targets wire instructions on real estate closings and settlement payments. Credential phishing goes after trading desk staff, partners and newsroom editors. Ransomware crews look for hospital and clinic systems where downtime forces a fast decision. Most of these attacks start with one compromised identity, which is why identity and privileged access sit at the center of nearly every engagement we run.
DESSS approaches each client with a scoped assessment rather than a tool recommendation. We document what you run, test it, and rank gaps by the harm they could cause, then help close them. Organizations that want a longer-term advisor can read about the DESSS cybersecurity consulting practice and its vCISO model; this page covers the hands-on services.
Dense financial activity, valuable confidential information and strict regulators make New York a demanding place to run a security program. These are the pressures that most often start a conversation with DESSS.
Firms covered by NYDFS Part 500 must keep a written program, a qualified CISO, risk assessments, MFA, asset inventories and annual certification of compliance. A policy binder alone does not satisfy an examiner who asks how a control actually operates.
Real estate closings, legal settlements and vendor payments all move large sums by wire. Attackers who compromise one mailbox can insert new payment instructions that look entirely routine to the person paying.
Administrators, developers, outsourced IT providers and SaaS tools often hold standing admin rights. Each one is a shortcut to sensitive data and a finding examiners and auditors look for first.
Fund administrators, payment processors, e-discovery vendors and managed service providers all touch client data. Their weaknesses become yours, and regulators expect a documented process for managing that risk.
Hospitals, physician groups and specialty practices hold records that ransomware crews prize. A long outage affects patient care, so tested recovery plans matter as much as prevention.
Deal documents, unreleased content, litigation strategy and tenant financials are valuable to criminals and competitors. Protecting them means knowing where they live and who can open them.
Every DESSS engagement draws from the same service catalog: five Microsoft security platforms and ten security domains. Each card opens the detailed service page with its scope, deliverables and engagement options.
Microsoft security platforms
AD DS design, hardening, migration, and forest recovery for the on-premises identity core.
Entra ID, Conditional Access, PIM, and identity governance for cloud identity and Zero Trust.
Defender XDR and Microsoft Sentinel SIEM deployed, tuned, and run as a working detection capability.
Intune security baselines, Autopilot provisioning, and co-management for compliant devices.
Information protection, DLP, records management, and eDiscovery across Microsoft 365.
Security domains
Joiner-mover-leaver lifecycle, SSO and MFA, RBAC design, and privileged access control.
SIEM implementation, detection engineering, threat hunting, and incident response.
Vulnerability assessment, penetration testing, and red and purple team exercises.
Posture management, cloud entitlements, workload and container security, IaC guardrails.
Next-generation firewalls, segmentation, Zero Trust network access, and SASE.
EDR and XDR, email threat protection, endpoint hardening, and patch management.
Encryption and key management, immutable backup, disaster recovery, and continuity.
Risk register, policy and framework development, audit readiness, and vCISO advisory.
Threat modeling, SAST and DAST, secrets management, and secure pipelines in the SDLC.
OT assessment, Purdue-model segmentation, SCADA monitoring, and IoT device security.
What does the Microsoft security stack include? The Microsoft security stack covers identity (Active Directory and Microsoft Entra), threat protection (Microsoft Defender and Sentinel), device management (Microsoft Intune) and information governance (Microsoft Purview). Many firms already own these tools through Microsoft 365 E3 or E5 licensing but run them with default settings.
Across financial and professional firms, Microsoft 365 is usually the system of record for email, documents and collaboration, which also makes it the main target. We review tenant configuration against the controls NYDFS and client auditors ask about, such as MFA coverage, privileged roles, audit logging and data retention, then enable the protections in a sequence that does not interrupt trading, closings or court deadlines.
Where firms run separate tenants after mergers, or keep legacy Active Directory domains for older applications, we document the trust relationships and plan consolidation so that one compromised account cannot move freely between them.

Microsoft Active Directory — Attack-path reduction, tiered administration and stale-account cleanup for domains that still support legacy banking and practice management applications.
Microsoft Entra — Conditional Access, phishing-resistant MFA and Privileged Identity Management that give examiners clear evidence of who holds admin rights and when.
Microsoft Defender — Defender XDR and Sentinel detections tuned for mailbox rule abuse, impossible-travel sign-ins and other early signs of wire fraud.
Microsoft Intune — Compliance policies for firm laptops and personal phones used by partners, traders and reporters, with selective wipe for departing staff.
Microsoft Purview — Sensitivity labels, retention and DLP for deal documents, client matter files, nonpublic personal information and protected health information.
These five domains determine whether an intruder gets in, how much they can reach, and how quickly your team finds out.
What do IAM and PAM cover? Identity and access management (IAM) decides who can sign in and what they can reach, using single sign-on, MFA and role-based access. Privileged access management (PAM) adds vaulting, approval and session recording for the administrator and service accounts that control critical systems.
NYDFS Part 500 puts specific weight on privileged access, and examiners ask how admin rights are granted, reviewed and removed. We build role models for trading, operations and client service teams, add access certification and recertification campaigns, and introduce CyberArk privileged access management or Entra PIM so admin rights exist only while a task is underway.
What do a SOC and MDR provide? A security operations center (SOC) combines analysts, processes and a SIEM to detect and respond to threats. Managed detection and response (MDR) delivers that function as a service, including alert triage, threat hunting and coordinated incident response.
Many firms here have a lean IT team that cannot watch alerts around the clock and an obligation to notify NYDFS promptly after certain cybersecurity events. DESSS reviews log coverage, builds detections in Microsoft Sentinel, adds proactive threat hunting, and can run or co-manage monitoring with your staff, supported by an incident response retainer.
What does penetration testing involve? Penetration testing is a controlled attack on your systems by testers who try to exploit weaknesses the way a criminal would. Combined with vulnerability assessment, it shows which flaws are reachable and what they expose. Red teaming tests detection and response against a realistic objective.
NYDFS expects covered entities to perform penetration testing based on their risk assessment, and corporate clients ask law and consulting firms for recent results. Common scopes include client portals, mobile banking apps, remote access gateways and web application penetration testing of tenant and investor platforms, plus phishing simulations aimed at finance and assistant roles.
What is cloud security consulting? Cloud security consulting reviews and hardens how workloads, identities and data are configured in providers such as Azure and AWS. It covers landing zones, network exposure, entitlements, logging, key management and container platforms, then keeps them in shape with posture monitoring.
Fintechs in the city often run entirely in AWS, while older banks and insurers are moving analytics and client reporting into Azure alongside on-premises cores. We review AWS security architecture and Azure landing zones, remove public storage and excess permissions, and set up monitoring that records the logs examiners and partner banks expect to see.
What is Zero Trust security? Zero Trust is an approach that grants access only after verifying who is asking, from what device, and in what context, every time. No user or network location gets automatic trust, and each person receives the minimum access their role requires.
Hybrid work across Manhattan offices, home offices and travel has stretched old VPN designs past their limits. We help New York firms move to Zero Trust network access and SASE, segment trading, back-office and guest networks, and limit what outsourced IT providers can reach so one stolen password does not open the whole firm.
These domains protect the devices, files and software your people depend on, and produce the evidence regulators and clients ask for.
What does endpoint and email security cover? Endpoint security protects laptops, desktops, servers and phones with EDR or XDR, secure configuration baselines and disciplined patching. Email security filters phishing, blocks impersonation and enforces sender authentication so attackers cannot easily pose as your firm or your vendors.
For real estate, legal and finance teams, email is the payment channel attackers abuse most. We tighten email security and anti-phishing controls with SPF, DKIM and DMARC enforcement, flag lookalike domains, deploy and tune EDR across firm devices, and harden the laptops partners and traders carry between office, home and client sites.
What does data protection include? Data protection keeps sensitive information private and recoverable. It covers classification, data loss prevention, encryption and key management, database hardening, and backups that ransomware cannot alter or delete, along with tested plans to restore operations.
NYDFS requires encryption of nonpublic information and a tested plan for business continuity, while the SHIELD Act sets expectations for protecting New York residents’ private information. We run a ransomware readiness assessment, design immutable backups for client files and core systems, and classify the data a breach notice would have to describe.
What is GRC in cybersecurity? Governance, risk and compliance (GRC) is the management layer of security: policies, risk assessments, control testing and reporting that show leadership, regulators and clients how well the program works. It often includes virtual CISO (vCISO) support for firms without a full-time security leader.
For covered entities, this is where NYDFS 23 NYCRR 500 readiness happens. We perform the cybersecurity risk assessment, write or update the required policies, run third-party and vendor risk management for service providers, build board reporting, and prepare evidence for the annual compliance filing, with vCISO support where a firm needs a qualified security leader.
What is application security? Application security is the practice of designing, building and testing software so that attackers cannot abuse it. DevSecOps puts those checks inside the delivery pipeline through threat modeling, code review, static and dynamic testing, dependency scanning and secrets management.
Fintech and proptech teams in the city ship code quickly, and their bank partners and enterprise customers ask how that code is secured. We run code security reviews, add SAST, DAST and dependency scanning to CI/CD, test payment and account APIs for broken authorization, and help build a secure SDLC that maps to SOC 2 and NYDFS application security expectations.
What is OT and IoT security? Operational technology (OT) and IoT security protect the control systems and connected devices that run physical environments, from building management and access control to medical and media production equipment. The goal is availability and safety as well as confidentiality.
In New York, this domain mostly concerns buildings and facilities: HVAC, elevator, badge and camera systems in office towers and residential portfolios, connected devices in hospitals, and broadcast and production equipment in media facilities. We perform IoT device security reviews, separate these systems from corporate networks, and control vendor remote access to them.
Security priorities change from one sector to the next. These are the New York industries where DESSS engagements most often begin, and what each usually needs first.
Banks, insurers, broker-dealers and investment managers: NYDFS Part 500 readiness, privileged access control, examiner-ready evidence and continuous monitoring.
Payment, lending and wealth platforms: cloud-native security, API testing, SOC 2 alignment and the controls partner banks require before launch.
Publishers, broadcasters and agencies: protection for unreleased content and source material, account takeover defenses and subscriber data privacy.
Hospitals, physician groups and specialty practices: HIPAA risk analysis, ransomware recovery planning, medical device segmentation and email security.
Developers, brokers, landlords and title firms: wire-fraud prevention, building system segmentation and tenant data protection.
Law, accounting and consulting firms: client confidentiality, document management security and evidence for client security questionnaires.
A cybersecurity assessment is a structured review of your systems, controls and governance that produces a ranked list of risks and a plan to reduce them. For New York firms, DESSS usually runs it in six stages, aligned to NYDFS where it applies.
We establish which rules apply, such as NYDFS Part 500, HIPAA or client contract terms, and agree which systems, data and business units the review covers.
Scope statement and obligations listInterviews and discovery tools record where nonpublic and client information lives, who can reach it, and which accounts hold privileged rights.
Data map and identity inventoryConfigurations are checked against CIS benchmarks and Microsoft guidance, vulnerabilities are scanned and, if agreed, targeted penetration tests are run.
Verified technical findingsEach finding is mapped to NIST CSF and to the specific sections of the regulations and contracts you identified at the start.
Requirement-by-requirement gap matrixGaps are ranked by likelihood and by the harm they would cause, from fraudulent wires to regulatory findings and client loss.
Prioritized risk registerWe turn the register into a phased plan with owners, effort and evidence requirements, and can deliver the work alongside your team.
Remediation and evidence roadmapDESSS is a Texas technology consulting firm headquartered in Houston with a dedicated cybersecurity practice. Clients bring us in for these reasons.
Contact the DESSS security teamThe consultants who identify a gap can implement the remediation across identity, cloud, endpoints and networks, so findings do not sit between vendors.
Work is documented with NYDFS, SOX, HIPAA and client audits in mind, so each change leaves evidence your compliance team can use.
Entra, Defender, Sentinel, Intune and Purview are core practice areas, which suits the many New York firms that run on Microsoft 365.
Through vCISO advisory, DESSS can provide security leadership, board reporting and program oversight for firms that need it.
Assessment, implementation, integration, managed support or training and change management, chosen to fit the need rather than sold as a package.
DESSS provides cybersecurity assessment, implementation and managed support for New York organizations.
Services include Microsoft security, IAM and PAM, SOC and MDR, penetration testing, cloud security, Zero Trust networking, endpoint and email security, data protection, GRC and NYDFS readiness, application security, and OT and IoT security.
A cybersecurity consultant identifies the gaps that carry the most risk and helps close them in a way regulators and clients will accept.
For New York businesses that typically means controlling privileged access, stopping wire fraud, preparing NYDFS or client audit evidence and testing defenses before an attacker does.
Yes.
DESSS secures Microsoft Azure and AWS environments, covering landing zones, identities and entitlements, network exposure, logging, key management, container platforms and ongoing cloud security posture management.
Yes.
DESSS runs vulnerability assessments and network, web application, API and mobile penetration tests, along with Active Directory attack path reviews, phishing simulations and red and purple team exercises. Results come with reproducible evidence and remediation guidance suitable for examiners and client reviews.
Zero Trust is a security model in which no user, device or network receives trust automatically.
Each access request is checked against identity, device health and context, users receive only the access they need, and activity is monitored continuously.
DESSS supports Microsoft Active Directory, Entra ID, Defender XDR, Sentinel, Intune and Purview, plus Azure and AWS security services.
Identity work also covers tools such as CyberArk, SailPoint, Okta and Ping Identity where a client already uses them.
A cybersecurity assessment confirms scope and obligations, maps data and identities, tests configurations and vulnerabilities, measures findings against frameworks and regulations, ranks risks by business impact, and ends with a phased remediation roadmap.
Banking, insurance and asset management, fintech, media and publishing, healthcare, real estate, and legal and professional services are the New York sectors where DESSS most often works.
Each faces different pressures, from NYDFS examinations to wire fraud and client confidentiality.
DESSS combines assessment with hands-on delivery across Microsoft, cloud, network and application environments, and documents its work for regulators and auditors.
DESSS is a Texas firm headquartered in Houston that serves New York clients remotely with one accountable team and engagement models from a single assessment to ongoing managed support.
Yes.
DESSS performs NYDFS Part 500 gap assessments and risk assessments, writes or updates the required policies, strengthens MFA and privileged access, builds asset inventories and prepares evidence for the annual compliance filing. vCISO support is available for firms that need a qualified security leader.
Wire fraud is prevented most reliably by combining technical controls with a verification process.
DESSS enforces MFA and DMARC, detects suspicious mailbox rules and sign-ins, blocks lookalike domains, and helps firms adopt call-back verification for any change to payment instructions.
Tell us which regulator, client or deal is driving the timeline, and DESSS will propose an assessment scoped to the systems and evidence that matter most.
The main DESSS cybersecurity page, the same services in other locations, and related reading.