Pistos Compliance Sentinel

Your compliance in one place —
and the proof beside it.

PCS turns the regulation into questions you can actually answer, keeps the supporting document behind every answer, and produces the compliance record on the day somebody asks to see it.

Know what you have. Prove it is secured. Present the evidence. Most organizations run those as three separate projects, and they drift apart. PCS runs them as one loop.

Request a briefing See pricing
The rule Your policy The question The evidence The proof
Version 1.0

Pistos Compliance Sentinel V1 will be released on September 10!

From that day your compliance lives in one place instead of a folder of spreadsheets and a hope.

Why a checked box stopped working

A checked box is no longer an answer.

New York's Department of Financial Services requires every covered entity to develop, deploy, and maintain a cybersecurity program. Until recently, the Certification of Material Compliance was the finish line: log into the DFS portal, find your agency icon, check the boxes, done.

That era is over. DFS placed strict due diligence obligations on insurance carriers, and carriers are now pushing those obligations downstream to the agencies and aggregators selling their products. Questionnaires that once asked Yes or No now ask if yes, show us the evidence.

The gap is rarely the control. It is the document that proves the control was there — and that is what fails an examination. PCS closes that gap by design: every answer carries its evidence, its date, and the name of whoever accepted it.

23 NYCRR Part 500  ·  42 sections  ·  Second Amendment effective 1 November 2023

How PCS fits together

Know. Prove. Present.

Every part of PCS is one of these three steps, or feeds one of them. Nothing can be secured, or scored, until it is on a list — so the loop starts there.

Step 1  ·  Know

Your IT environment

Your equipment, your software, and your people.

Those are the three things that can be attacked, and the three that have to be secured. PCS keeps a live list of each: every machine and how it is protected, every application and whether you could survive losing it, every person and what they are allowed to reach.

Step 2  ·  Prove

Evidence that it is actually secured

Saying a control is in place is not the same as it being in place.

PCS scans your workstations, your applications, your Microsoft 365 or Google tenant, your line-of-business systems — your agency management system, your practice management system, your ERP — and everything of yours facing the internet — then reports, control by control, what is switched on and what is not.

Step 3  ·  Present

The record, on the day they ask

When somebody asks, you produce it.

Risk assessment and risk register, the scored results of every scan, who took which training and when, your disaster recovery and incident response plans, your asset inventories, and your security policies. Current, dated, and in one place.

Three steps, not three projects

Run them as separate projects and they drift: the inventory goes stale, the scans check last year's machines, and the evidence gets thrown together in the week before an examination. PCS runs them as one loop. Your inventory decides what gets scanned. Your scans become your evidence. Your evidence is ready before anyone asks.

The rule › your policy

It starts with the rules — and your answer to them.

The regulation in language you can actually read, and the policies that answer it section by section. One piece of work, several frameworks satisfied at once.

The rule, in plain English

All 42 sections, said the way a person would say them.

PCS restates every section of 23 NYCRR Part 500 in plain language, alongside the regulatory text itself. No one has to interpret a statute before they can act on it.

A regulation your staff can read without a lawyer.
Your policies

Fourteen policies, each citing the exact section it satisfies.

Every policy carries its mapped references — the DFS sections it answers, and the HIPAA, ISO and NIST requirements that share the same underlying control. Clients with more than one obligation do not do the work twice.

Written once. Counted everywhere it applies.
PCS showing 23 NYCRR Part 500 restated in plain English, section by section, with applicability and compliance notes.
The rule, in plain English
The PCS shared policy library: each policy with its purpose, scope, policy statement, and mapped references to NY DFS, HIPAA, ISO 27001 and NIST.
Your policies, with their citations
One piece of work, four frameworks

NY DFS requires two things: that you run a cybersecurity program, and that you can prove it. PCS turns each requirement into a plain question you can answer — and gives you the tools to put evidence behind every answer.

The question

The rules become a risk assessment you can answer.

Thirty controls, each a plain question with evidence behind it — scoped, evidenced, weighted, and scored.

Does it apply to us?

Applicability is set per control. A rule about a data center you do not have is marked out of scope — with the reason written down.

What proves it?

Each answer carries a document, a date, and the name of whoever accepted it. Nothing rests on recollection.

What is it worth?

Inherent risk and risk addressed are tracked separately, so remediation effort goes where it actually moves your exposure.

Where do we stand?

Your score, and how it compares with the rest of the portfolio — so the number means something outside your own four walls.

Your score is counted, not claimed

The number on the front page is worked out from the answers — which means it moves when the answers move, and never because somebody decided it should. We do not score you against a rule that does not apply to you, and the reason it does not apply is on the record.

The PCS risk assessment: each control with its applicability, inherent risk, risk addressed, evidence status, evidence date and attached document, above a score compared against the portfolio.
Every control, scoped, evidenced and scored
The evidence  ·  process controls

Half the assessment rests on knowing what you have.

Three inventories sit under everything else PCS does. They are not paperwork — they are the denominator.

Hardware inventory

Every machine, who has it, and how it is protected.

Asset tag, serial, operating system, owner, encryption state, and endpoint protection — the record that turns “we encrypt our laptops” into something an examiner can verify.

Application inventory

Every application you run, and which ones you cannot lose.

Application, version, owner, and business criticality — feeding both the supported-software controls and the recovery priorities in your DR plan.

Team members

Who works here, and what each of them may reach.

The roster behind access review, offboarding, and training completion. Without it, “are your people trained?” has no denominator.

Why the inventories come first

“Is every machine encrypted?” cannot be answered until PCS knows every machine. “Are your applications supported?” needs the software list. “Are your people trained?” needs to know who your people are. Scripts populate most of each list for you — but the list has to exist before any control above it can be scored honestly.

The evidence  ·  technology controls

PCS looks at your organization the way an outsider would.

Your mail, your website, your tenant, and every door facing the internet — scanned by Skopein, with findings that file themselves.

Run a scan

Pick what to look at and start it.

Internal network, external perimeter, web application, and tenant configuration. It runs on its own and reports when it is finished — no analyst has to sit with it.

What comes back

A score, what passed, what needs attention, and how to fix it.

Findings are framed against the frameworks that govern you and paired with step-by-step remediation instructions — not a generic CVE list somebody still has to interpret.

The findings file themselves

Every finding lands on the control it answers, with the date it was found. Nobody retypes anything, and your score moves because the scan moved it — not because somebody remembered to update a spreadsheet.

The Skopein scanner suite inside PCS: Microsoft 365, Google Workspace, Windows, Linux, host information, internet-facing device and web application scans, each launched from one screen.
Skopein, inside PCS
The evidence  ·  your people

The unsung control: training that people actually finish.

560 courses, 14 documentaries, and 4 games — from what a phishing email looks like, up to governing your agency's use of AI.

Narrated, with a knowledge check

Over 80 cybersecurity topics, illustrated and voiced.

Rich infographic modules with generated voice-over and a graded quiz at the end. The syllabus is current — AI governance is on it, which most awareness libraries still lack.

Games that make it stick

400 questions across 38 categories.

Not decoration. People finish them, and a finished course is the evidence the control needs. Completion is what the framework asks for; engagement is what produces it.

A completed course is evidence, not a tick in a box

Who took it, which course, what date — recorded against the person and filed against the control that asks whether your staff are trained. When somebody asks for proof of security awareness training, that record is the answer.

Explore Mathisi  →

For the day it goes wrong anyway

Controls reduce how often. They do not reduce it to never.

The plan for what happens next is written while everyone is calm. A plan written calmly in September is worth more than one improvised at two in the morning in March.

Incident response plan

Who does what, in what order, from the first hour.

Playbooks for phishing, account compromise, ransomware, and data breach — with roles, escalation paths, and notification obligations already decided.

Disaster recovery plan

Activation criteria, life safety first, then systems.

Recovery priorities tied directly to your application inventory, so the order of restoration reflects what your business actually cannot run without.

And it writes the report afterwards

Each step is marked off with a time and a note as it is completed, so the record of what you actually did builds itself while you are doing it. “We responded within the hour” is a claim; a timestamped step list is evidence — and that record is what your carrier and your regulator will ask for.

The PCS incident response plan: activation criteria, affected computers and applications, and step-by-step actions that record who did what and when.
The incident response plan, and the report it writes
Inside PCS

The whole compliance program, in one record.

Every artifact is versioned, dated, and mapped against the eight authoritative frameworks Pistos supports. When a regulation amends, the mapping updates — and PCS flags the evidence that needs refreshing before it goes stale.

Risk Assessment
Thirty scored controls with per-control applicability, inherent risk, risk addressed, and a prioritized remediation roadmap.
Incident Response
Documented playbooks with timestamped step tracking that produces the post-event report as the response unfolds.
Disaster Recovery
Activation criteria, life-safety sequencing, and recovery priorities tied to your application inventory.
Hardware & Software Inventory
The canonical record of every device and application — what you own, who owns it, how it is configured, and where the recovery keys live.
Security Policies
Fourteen policies with mapped citations to the exact sections they satisfy, across DFS, HIPAA, ISO and NIST.
Technology Security Posture
Quarterly review of what is actually configured in your environment against your written baseline — not what the vendor dashboards report.
Process Security Posture
Quarterly review of the human and operational controls — offboarding, access reviews, change management, the practices policies depend on.
Two engines inside PCS

Where the evidence comes from.

Skopein produces the technical findings. Mathisi produces the workforce records. Both write directly into the PCS assessment — they are not separate modules to reconcile.

What you can hand over

Your regulator, your carrier, your bank, your biggest client.

One place to point at, on the day they ask.

Your score

One number, worked out from the answers, with the whole assessment standing behind it.

Your evidence

Every document, dated, attached to the control it answers — and to the section of the regulation that control satisfies.

Your record

Training taken, scans run, incidents handled — with times, so the sequence of events is not a matter of memory.

Aegis delivery

PCS is the platform. Aegis is who runs it.

Every Aegis engagement runs on PCS. The only question is who fills the CISO role.

Pistos-supplied CISO

A named senior advisor serves as your designated CISO.

A former Big-X partner is responsible for your compliance program, regulatory filings, board reporting, and examiner interactions — with PCS running the program continuously behind them.

Client's internal CISO

Your CISO leads. PCS does the engineering work.

Your internal CISO keeps ownership — and gains a platform that produces the configurations, policies, training, DR/IR plans, and reports they would otherwise assemble by hand.

Learn more about Aegis  →

Getting started

What we need from you is three lists. Then very little.

Three inventories

Your people, your equipment, your applications.

Scripts populate most of each one for you. What is left is the handful of facts only you know.

Time to load and check

Enough runway to fix anything odd before go-live.

We load the data, reconcile it, and resolve the inconsistencies every inventory turns up — before the first assessment runs against it.

Then nothing

We do the assessment.

You supply only what PCS cannot know on its own — your cyber insurance evidence, your organizational structure, and the judgment calls that are genuinely yours to make.

PCS V1 releases 10 September 2026

From release day, your compliance lives in one place instead of a folder of spreadsheets and a hope. If the timing is going to be a problem, tell us early rather than on the day — we can work with a late inventory, not with a surprise.

Get in touch

See PCS against your own environment.

Tell us about your stack, your frameworks, and your headcount. We will show you exactly what PCS produces for an organization like yours.

Request a briefing