Independent cybersecurity advisory · New York

Someone is about to ask you to prove your security program.

TRM Solutions helps investment advisers, law firms, and growing SaaS companies answer it, with proof a client, an insurer, or an examiner can use.

Start With a Free Readiness Snapshot
41-question assessment · about 5 minutes

Practical questions across governance, access, monitoring, incident response, recovery, and AI governance. Get a directional view of your readiness and the next step that matters.

Moderate
readiness
Govern
Identify
Protect
Detect
Respond
Recover
Recommended next step Strengthen incident response and documentation before client or insurer review.
Sample output. Take the assessment for your own.

Directional guidance only. Not a penetration test, audit, certification, or guarantee of security.

On the other side of the audit table

American Express Deloitte Morgan Stanley

Cybersecurity and IT audit at American Express. Cyber Risk advisory at Deloitte. Client Data Privacy Officer at Morgan Stanley.

Employer names reflect professional experience only. TRM Solutions is an independent advisory practice and is not affiliated with, endorsed by, or sponsored by any current or former employer.

Why you're here

Someone with leverage asked a question you couldn't fully answer.

A client, an insurer, or an examiner asked for proof. Each one needs a different kind.

The client

The deal is waiting on you

An enterprise prospect sent a 200-question security questionnaire, asked for your SOC 2, or made a signed contract contingent on evidence of a real program. The deal is waiting on your answer.

Vendor Questionnaire Response Pack →$399. Pre-written answers carrying SIG Lite and CAIQ identifiers, downloading in your browser the moment you finish the intake.

The insurer

The policy is being underwritten

A cyber policy is being underwritten or renewed, and the application now asks about MFA, backups, incident response, and governance. The wrong answers mean higher premiums, or no coverage.

Incident Response Plan Starter Kit →$349. The plan every insurance application asks whether you have, with the response team sized to your headcount.

The examiner

The regulator is asking

An SEC exam is scheduled, a regulator is asking, or the board raised a question in a meeting. You need documentation that holds up to scrutiny from someone whose job is to find the gaps.

Data Classification & Handling Standards →$249. The document that answers how you know where client data lives, with six appendices you complete once.

How we work

Three rungs, one senior practitioner.

Most engagements follow the same path: understand where you stand, close the gaps that matter, and keep it defensible over time. Every document is built by Teddy directly.

Weeks 1–3

Security Maturity Assessment

A NIST CSF 2.0 assessment of where your security program stands today, scored across the six Functions of the Framework plus supply chain and AI governance, against your size and sector. You leave with a prioritized, executable roadmap, not a 90-page PDF nobody reads.

  • Scored maturity report
  • Top-10 prioritized gaps
  • 12-month roadmap
  • Board-ready summary
$3,000–$8,000fixed scope
Weeks 3–7

Remediation & Documentation

We close the gaps the assessment surfaced: audit-ready policies mapped to SOC 2 and NIST CSF, an incident response plan, and the evidence package clients and insurers actually ask to see. Written to be used on Monday morning.

  • Core policy set
  • Incident response plan
  • Questionnaire responses
  • Evidence package
$3,500–$7,500fixed scope
Ongoing

Virtual CISO Retainer

A named senior on retainer when client reviews, board updates, and questionnaires keep landing, and the next ask is already on the desk.

  • Named senior advisor
  • Quarterly board reporting
  • Questionnaire & audit support
  • On-call guidance
From $3,000/moretainer

Working to a date sooner than that? Focused engagements (questionnaire support, tabletop exercises, insurance readiness, policy drafting) are scoped to your deadline and quoted on request, including the week you have left. See the full engagement catalog →

If what you need is the document rather than the engagement, the five self-service documents are written from your answers and download in your browser when you finish the intake, from $149. Every purchase is credited in full against an engagement booked within 90 days. See the documents →

Client work

What the work produced.

Client identities are withheld under NDA. Quotes are verbatim and used with permission. No client logos.

Law firm · ~35 employees · New York metro

Trigger
A client security questionnaire, due on a date.
Engagement
Security maturity assessment.
Outcome
Questionnaire submitted on deadline.
“We had no idea where to start. The assessment gave us a clear picture of where we stood and exactly what to do next, in plain English, not jargon.”

Managing Partner · Litigation firm · identity withheld under NDA

Verbatim quote used with written permission.

B2B SaaS · ~20 employees · Northeast

Trigger
An enterprise deal waiting on security documents.
Engagement
Documents prepared for that review.
Outcome
Enterprise contract signed.
“Teddy moved faster than I expected and the documents were genuinely better than what I've seen from much larger firms. We would have lost the deal without this.”

CEO & Co-Founder · B2B SaaS · identity withheld under NDA

Verbatim quote used with written permission.

Registered investment adviser · ~15 employees · Southeast

Trigger
An SEC examination.
Engagement
Senior advisory on the regulatory questions in front of a small firm.
Outcome
SEC exam, no material findings.
“Having someone who understood both the regulatory requirements and the practical constraints of a small firm made all the difference. This wasn't generic advice.”

Chief Compliance Officer · Registered investment adviser · identity withheld under NDA

Verbatim quote used with written permission. This is the outcome of one engagement, not a guarantee of any examination result.

Verbatim quotes used with written permission. Client names, logos, and identifying details are withheld under NDA. The RIA examination result is one engagement’s outcome, not a guarantee.

Why TRM

Senior judgment, without the enterprise overhead.

Four reasons the buyers above choose an independent practitioner over a platform or a staffing firm.

01

You work with the senior person

Every engagement is delivered personally by Teddy Mutterperl, not scoped by a partner and handed to junior staff. The person who assesses your program is the person who writes the report and briefs your board.

02

Calibrated at financial-institution scale

Nine years auditing security and technology risk inside American Express, Deloitte, and Morgan Stanley. The same standards regulated institutions are held to, applied at a size and price that fits your firm.

03

Weeks, not quarters

Fixed scope, fixed price, agreed in writing before work begins. A full engagement runs three to seven weeks end to end. If the deadline on your desk is shorter than that, say so first: focused engagements are scoped to the date you have to hit, and the self-service documents download the same afternoon.

04

Deliverables built to be used

Policies your team can follow, evidence auditors accept on first review, and roadmaps you can actually execute. Documentation written to survive scrutiny, not to sit in a drawer until the next questionnaire.

The practitioner

You're hiring a person, not a platform.

Teddy Mutterperl, founder and principal consultant of TRM Solutions

Teddy Mutterperl brings nine years of cybersecurity, IT audit, and risk advisory experience across American Express, Deloitte's Cyber Risk practice, and Morgan Stanley, spanning internal audit, third-party risk, security control assessment, and advisory work in financial services, technology, and professional services.

TRM applies the same audit discipline, risk-based thinking, and executive-ready documentation standards developed in regulated enterprise environments, scaled for growing companies that need that quality without enterprise pricing or enterprise timelines. Every engagement is delivered personally, start to finish.

The job is to translate cybersecurity risk into business language, so leadership can prioritize, respond to client scrutiny, and make defensible decisions.

Independence. TRM Solutions is an independent advisory practice not affiliated with, endorsed by, or sponsored by any current or former employer. Engagements are conducted in a personal capacity and do not involve employer systems, data, clients, vendors, or confidential information. Employer names describe professional experience only. Client engagements are covered by NDA.

Book a call

Start with a 15-minute call.

A short, no-obligation conversation to understand what's being asked of you and whether TRM is the right fit. Every inquiry gets a response within one business day.

Currently accepting a limited number of new engagements.

15 minutes · No obligation

Book a call with Teddy

Bring the questionnaire, the email from your client, or the exam notice. We'll talk through what's actually being asked and the shortest credible path to answering it.

Book a 15-minute call →
Free · about 5 minutes

Or take the readiness assessment

41 questions across the six Functions of the NIST Cybersecurity Framework 2.0: a directional grade, the gaps a questionnaire or an exam would mark, and a next step based on your answers.

Directional maturity view based on your responses. Not a penetration test, audit, certification, or guarantee of security.

Or reach out directly:

Emailinfo@trmsolutions.io
LocationNew York Metro Area. Serving clients nationwide.
Response TimeWithin one business day

Quick Inquiry

Have a quick question? Send a message and you'll get a reply within one business day.

Please do not submit passwords, sensitive system details, regulated personal data, or confidential client information through this form.