TorchLight Secured & Managed It

TorchLight Secured & Managed It TorchLight Secured & Managed IT is an established provider of Information Technology and Information Security services across the United States.

If pe*******on testing or vulnerability scanning is showing up on your budget, audit list, cyber insurance questionnaire...
09/02/2026

If pe*******on testing or vulnerability scanning is showing up on your budget, audit list, cyber insurance questionnaire, or regulatory calendar, make sure you know what you are actually buying.

The difference is simple:

Vulnerability scanning identifies where you may be vulnerable. Pe*******on testing shows what an attacker could actually do about it.

They solve different problems, and depending on your industry, regulator, insurer, or compliance requirements, you may need one, the other, or both.

We put together a comprehensive guide for executives covering the difference, what each type of testing proves, and what to ask before approving a purchase.

Read the full article here:
https://torchlight.io/blog/pe*******on-testing-vs-vulnerability-scanning/

No hard sell, we just want you to understand the difference before you spend the money.

Vulnerability scanning finds potential weaknesses. Pe*******on testing shows what an attacker could actually do with them. Learn what regulated organizations should know before buying either service.

Quick question for our fellow executives with teams using AI, officially or not:Who approved all of it?Unfortunately, th...
08/26/2026

Quick question for our fellow executives with teams using AI, officially or not:

Who approved all of it?

Unfortunately, that's not a joke. This is becoming a very real, extremely common governance problem.

We're coming at this one from a RIA & Wealth Management point of view, but it's just as important for Credit Unions, Schools & Colleges, Healthcare, & Government entities.

AI is showing up everywhere in regulated organizations. Employees use it to speed up a tedious task, vendors are adding it to software, and almost every meeting tool is using it heavily. Sensitive information can move into AI systems before leadership even knows those systems exist.

For RIAs, the SEC may not have an official rule, but it has officially made AI part of its 2026 examination priorities.

And the questions are pretty straightforward:

Where is AI being used?
What information can it access?
Who approved it?
Who is responsible for overseeing it?

If your answer to any of those is “we think we know,” please, keep reading.

🎯 Read the full article from TorchLight:
https://torchlight.io/blog/sec-ai-regulation-2026-rias/

The goal is not to entirely ban AI.

The goal is simply to know where it is, know what it can touch, and know who owns the risk.

If your organization needs help building that visibility and putting practical guardrails around AI use, learn more about TorchLight’s AI Governance services here:

🎯 https://torchlight.io/services/ai-governance/

AI is moving fast.

Your governance shouldn't be six months behind it.

Stay alert,
The TorchLight Team

Risk Aligned. Reward Defined.

AI is in the SEC's 2026 exam priorities. Could your firm show an examiner where AI operates, what it can access, and who approved it?

The 2026 questionnaire is not the same as the one in 2024. The questionnaire is now an audit.Whatever you attest to on t...
06/10/2026

The 2026 questionnaire is not the same as the one in 2024. The questionnaire is now an audit.

Whatever you attest to on the way in gets re-checked against forensic evidence on the way out, and the average global ransomware claim more than doubled to roughly $713,000 between 2024 and 2025.

This week’s blog post covers what actually changed, the one control that decides whether the claim pays, the business-interruption math that should worry you more than the forensic bill, and the five moves worth making before your next renewal.

If your renewal is inside the next ninety days, the question in the closer is one I would definitely benchmark against your current attestation.

TorchLight Blog Post link in the first comment.

Your compliance team is focused on SEC Regulation S-P requirements. Your IT team says your cybersecurity is solid.Both d...
06/09/2026

Your compliance team is focused on SEC Regulation S-P requirements.
Your IT team says your cybersecurity is solid.
Both depend on the same IT foundation.

S-P compliance requires specific security measures. If your IT infrastructure doesn't deliver, compliance fails. Think of it like HVAC and electrical in a building. Both systems are required to pass inspection.

Most firms hire separate vendors to handle these separately. Two teams. Two solutions. Two invoices.

TorchLight take a different approach. One partner. One solution. One invoice.

Nearly two decades in regulated industries. Our clients pass SEC exams on the first attempt. Cyber insurance premiums drop by up to 35 percent. Critical response hits 30 minutes, around the clock.

SEC Regulation S-P isn't a checkbox. It's your IT and cybersecurity roadmap.

Download our SEC Regulation S-P Cybersecurity Checklist for RIAs. (Link in Comments) See exactly what regulators expect and where most firms miss the mark.

Would your team second-guess a link that points to the real chatgpt website?Most people wouldn't, and that's the problem...
06/03/2026

Would your team second-guess a link that points to the real chatgpt website?

Most people wouldn't, and that's the problem.

Criminals are now hiding malware on pages hosted right on ChatGPT and Claude. Because the link is a genuinely trusted AI domain, the usual advice to check the URL before clicking silently fails. The trap is a fake “ChatGPT is busy, download our app” page that serves malware disguised as the desktop app.

Security researchers call it the LLMShare attack, and it's the same social engineering as last year’s ClickFix scam, just wearing a brand everyone trusts. Whether your business already leans on AI tools or is only starting to, the time to put guardrails in place is now.

We walk through how it works, and how to protect your team, in the article linked in the comments.

05/29/2026

A time lapse of the 2 hour storm passing through last night .Pretty gnarly storm for our section of the country.

Nearly half of all exploited zero-days last year targeted edge infrastructure: firewalls, VPNs, and security appliances....
05/29/2026

Nearly half of all exploited zero-days last year targeted edge infrastructure: firewalls, VPNs, and security appliances. For healthcare clinics, community banks, and wealth management firms, that's a wake-up call.

Your perimeter devices run with high privilege and are often the least monitored. New vulnerabilities in Cisco, VMware, and others are already active. If you'd like to discuss how to strengthen your defenses, we're here to help.

Device Login Phishing is spreading faster than most security teams have heard about.Over 340 organizations: Credit Union...
05/27/2026

Device Login Phishing is spreading faster than most security teams have heard about.

Over 340 organizations: Credit Unions, Healthcare Practices, Law Firms, Nonprofits, you name it; fell victim to a new attack that bypasses both MFA and password-based defenses.
Employees did everything right. They went to a real Microsoft login page and entered real multifactor authentication, and were still compromised.

The real worry? This attack works because most mid-market organizations have never disabled or restricted device code flow.
Regulators at the NCUA, OCR, and SEC are now watching for these breaches because token-based compromise is harder to detect than password theft.

View our Full Blog Post in the comments!

The deadline to patch was on May 12th. ConnectWise ScreenConnect Vulnerability!If you haven't patched yet, do so immedia...
05/14/2026

The deadline to patch was on May 12th.

ConnectWise ScreenConnect Vulnerability!

If you haven't patched yet, do so immediately!

Click the link below to view the full Blog Post and learn more!

05/11/2026

PALO-ALTO FIREWALLS are being actively exploited right now, and patches don't land until May 13.

If you run a credit union, RIA, or healthcare clinic, Palo Alto Networks firewalls protect your perimeter.

That's true for an estimated 70%+ of mid-market organizations in regulated industries. And right now, all PA-Series and VM-Series firewalls face a critical unauthenticated buffer overflow in the Captive Portal service, discovered and published May 6.

This isn't theoretical. CISA's Known Exploited Vulnerabilities Catalog confirms in-the-wild exploitation is already happening.

The patch window is seven days. If you haven't already scheduled your update, this week is the week to do it. Any delay puts your perimeter, your client data, and your audit stance at risk.

Have you confirmed your Palo Alto devices are covered in your current patch schedule? Your security team should have answers by Monday.

Address

23505 East Appleway Avenue Suite 200
Spokane Valley, WA
99019

Alerts

Be the first to know and let us send you an email when TorchLight Secured & Managed It posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share