Managed IT for publicly traded companies

A Cyber Incident Can Become a Disclosure Question

Public issuers face obligations private companies don't: material incidents may need disclosing, financial systems fall under internal controls, and your auditors test whether IT controls actually operate.

IT general controls documented, with evidence prepared for your auditors' testing
Audit trails designed to give you the facts a materiality assessment needs
Change management that respects your reporting calendar
SOC 2 Type 2 — a service auditor's report intended for use by your auditors

Talk to us about your controls

Including if you're preparing for an audit or responding to an auditor's finding.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We don't share your data. No spam, ever.

Public companies and subsidiaries we support

Incident to disclosure

The Question You'll Be Asked Is "When Did You Know?"

Materiality assessment requires facts: what was accessed, when, and whether it affects financial reporting. Without evidence you cannot make that judgement — or defend it afterwards.

Detection

Something happened

An alert, a report, or an anomaly. At this point nobody yet knows scope — and that uncertainty is the problem.

What it requires
Monitoring that detects in hours, not months
Hours after

Establish the facts

What was accessed, by whom, over what period, and whether financial systems or reporting data were touched.

What it requires
Retained, tamper-resistant audit logs
Assessment

Is it material?

A judgement for management, counsel, and the audit committee — but it can only be made against evidence.

What it requires
A documented factual record
Disclosure

Decide and file

If material, disclosure follows on your regulator's timeline, and the record of your process gets scrutinised too.

What it requires
An evidenced incident response file

General sequence, not legal or securities advice — your disclosure obligations are for your counsel and audit committee to determine. Our part is making sure the facts exist to inform that decision.

IT general controls

Your Auditors Test IT Controls, Not IT Intentions

Internal control over financial reporting depends on IT general controls — access management, change management, and operations around the systems that produce your numbers. Auditors don't accept that a control exists; they test whether it operated throughout the period.

Most deficiencies we're brought in to remediate aren't missing controls. They're controls that were real but never evidenced, so there was nothing for the auditor to sample.

Our Compliance Approach
What auditors ask us for
User access listings, per period
Who had access to financial systems and when — including privileged accounts and service accounts.
Evidence of access reviews
Not that reviews happen, but that a specific review occurred on a date and what it found.
Change management records
Every change to in-scope systems: requested, approved, tested, deployed, by whom.
Segregation of duties
That the person who develops a change isn't the person who approves and deploys it unchecked.
Backup and recovery evidence
Restores actually performed and documented, with recovery times measured rather than estimated.
Job monitoring and exception handling
That scheduled processes ran, and where they failed, that someone noticed and resolved it.
Material non-public information

Some Files Move Markets

Draft results, transaction models, and board packages are market-moving until released. Leakage isn't only a security incident — it's a regulatory and market-integrity problem, and it usually happens through ordinary carelessness rather than an attack.

The controls that matter here are unglamorous: who can reach the folder, whether access is logged, and whether a departing executive's access actually ended.

Restricted folders, logged access

Draft results and deal material in access-controlled locations where every open is recorded.

Executive offboarding, same day

A departing officer's access ends immediately — with a record of what they accessed beforehand.

Controls on external sharing

Deliberate rules about what can leave the tenant, so a convenient link doesn't become a public one.

Advisers inside the controls

External counsel and bankers working within a controlled space rather than over unmanaged email.

The reporting calendar

Quarter End Is Not a Time to Be Patching

Public companies have immovable filing deadlines. Change management has to respect them, which means the maintenance calendar is built around your reporting calendar rather than ours.

Mid-quarter

Do the work

Upgrades, migrations, and infrastructure changes land when a rollback wouldn't threaten a filing.

Change window open
Pre-close

Freeze in-scope systems

No changes to financial reporting systems while the numbers are being assembled.

Restricted
Close and filing

Support only

Response and monitoring, nothing discretionary. Availability matters more than progress.

Change freeze
Post-filing

Evidence and review

Control evidence packaged for the period, and the next quarter's change plan agreed.

Evidence pack
What we provide

Evidence as a Deliverable

Access governance

Identity, privileged access, and periodic reviews run as a documented process — the control auditors sample most often.

Change management with a trail

Requests, approvals, testing, and deployment recorded in a system rather than in email threads and memory.

Audit log retention

Log retention set to the periods agreed with you, protected against alteration.

Tested disaster recovery

Recovery objectives agreed with the business, then tested and documented — because an untested RTO is an assumption.

Incident response, rehearsed

A written plan with defined roles, escalation to the audit committee, and a tabletop exercise so it isn't first used live.

Third-party assurance on us

Our SOC 2 report, so your auditors can assess your service provider from documentation rather than a questionnaire.

Questions, answered

Public Company IT FAQs

Our auditors raised an ITGC deficiency. Can you remediate it?

Usually, and the first step is understanding whether the control is genuinely absent or simply unevidenced — they're very different pieces of work. Most findings we're brought in for are the second: the practice existed but produced nothing an auditor could sample. Send us the finding and we'll tell you which it is.

Will your own controls be examined as part of our audit?

Likely yes, as a service organization in scope for your ITGCs. That's why we hold a SOC 2 Type 2 report — it's intended for your auditors' use, so they can assess us from documentation rather than interviewing us. Providers without one create work for your finance team every year.

Who decides whether an incident is material?

You do — management, counsel, and the audit committee. We're not securities advisers and won't pretend otherwise. Our job is to make sure the factual record exists so that judgement is informed rather than guessed, and defensible if it's later questioned.

We're preparing to go public. When should we start on this?

Earlier than most companies do. Control environments take a few reporting cycles to produce clean evidence, and auditors want to see controls operating over time rather than implemented last month. Starting a year out is comfortable; three months out is expensive.

Can you work with our internal audit and IT functions?

Yes, and that's the normal arrangement at this scale — co-managed, with the split written down. Internal audit tests, internal IT owns direction, and we cover specified layers and produce evidence. Ambiguity about who owns what is what causes findings.

Do you support subsidiaries of foreign-listed parents?

Yes. Canadian subsidiaries frequently inherit control requirements from a US or European parent's framework, and the practical challenge is meeting the parent's standard with a smaller local team. That's a good fit for co-managed delivery.

Let's connect

Controls that survive testing.

Tell us what your auditors flagged, or what your audit committee is asking. We'll tell you what's a real gap and what just needs evidencing.

Request a conversation

We'll reply within one business day.

We don't share your data. View Privacy Policy.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
NetFusion Designs

A globally recognized IT service provider with clients across North America. We hold a SOC 2 Type 2 report, independently audited.

SOC 2 Type 2 provider
Infrastructure
Project PlanningHardwareTelephony & VoIPApplication DevelopmentCloud DesktopSecurity CamerasHyperConverged Computing
Managed IT