Playing · muted

Data · AI · Risk

AI can't outrun bad data.

Fortify your data foundation first.

Built for: Banks, Credit Unions, Fintech, Healthcare, Insurance, Private Equity, Vertical Market Software, and Wealth Management.

How we work

Master the Map. Own the Summit

Foundation First. Speed Second

Focus 01

Data Governance

Governance is the map that makes management, AI, and vendors answerable.

Policies, owners, approvals, and proof. A map you can show a board, examiner, or buyer. Not a binder on a shelf.

Policy · ownership · approvals · proof

Focus 02

Data Management

If you can't name where it lives, you can't protect it.

Catalogs, retention, access paths, and sprawl across cores, drives, and systems of record.

Inventory · location · ownership · retention

AI governance command center

Focus 03

AI Governance

Shadow AI moves data whether you approved it or not.

Find the tools. Name the data they touch. Leave a paper trail a board or examiner can follow.

Shadow AI · inventory · exam-ready trail

Focus 04

Vendor Risk Management

Your vendors already hold the data. Prove they're safe.

Third parties, white-labels, and AI APIs — including the vendor's vendor. Diligence you can act on, not questionnaire theater.

Third parties · vendor’s vendor · exam-ready diligence

The Path

From where data sits to where it belongs.

01

Listen.

A working session with your team. Same industry is not the same operating reality. We get clear on your data governance and data management practices.

02

Assess.

We inventory and follow the data: where it sits, how it moves, document real risks, then compile findings. Start small. Work iteratively.

03

Advise.

A ranked roadmap to close the risks and gaps we find, with clear Done-Done criteria for each. Your teams execute; we steer.

04

Verify.

Oversight on what’s open, pending, and closed. We also surface senior-leadership benefits as teams execute: speed, financial, risk mitigation tied to corporate goals.

About

Twenty years. One recurring question. Everyone still acts surprised.

Across mergers, spin-offs, joint ventures, divestitures, and regulatory exams, the same moment kept showing up: someone had to ask where the data lived and who owned it. That question is where the delays began.

Adam Papas spent two decades in operations and advisory across banking, fintech, private equity, and technology. COO and Chief of Staff for a large fintech core-banking division. VP of Strategy & Data Enablement at one of the Big Three credit bureaus. Operations leader at the second-largest U.S. lender through crisis-era consolidations.

APSTRAT exists to build that data foundation before the deal, the integration, the exam, or the plaintiff’s attorney forces the question.

Contact

Let’s talk about where the data sits.

A working conversation, not an intake maze. Tell us what you’re looking at, we’ll tell you what we’d look at first.

Message

Send a note

Not ready to book a call? Send a note and we’ll follow up.

0 / 300

Calendar

Schedule a working session

Ready to talk? Pick a time. You’ll get a calendar invite.

CITATIONS NEW

Every citation on this site, in one searchable table.

Filter by industry or type, or search for a regulator, a dollar figure, or a company name. Nothing here is summarized twice, this is the same evidence behind every page, just queryable.

← Industries

BANKS

NPI is a GLBA duty.
Third-party guidance already covers the vendor, and the vendor's vendor.

Cataloging, paths, controls, and AI: the same four questions an examiner asks about nonpublic personal information, now complicated by employees quietly routing it through unapproved AI tools.

← Industries

BANKS.SYS
Figures and Stats
Data provided from cited sources. Citations
BK-1
$6.29M
Average cost of a data breach, financial industry, 2025 study.
Details
IBM / Ponemon Institute, Cost of a Data Breach Report 2025. Financial industry: banking, insurance, and investment companies. Not Credit Unions specifically. Up from $5.56M in the 2020 study.
BK-5
92%
Share of organizations with an AI-related breach that lacked proper AI access controls.
Details
IBM Cost of a Data Breach Report 2025. Among organizations that experienced an AI-related breach specifically.
BK-8
4 days
Business days a registrant has to file Form 8-K Item 1.05 once a cybersecurity incident is determined material.
Details
SEC, SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance and Incident Disclosure by Public Companies, February 2023. Governing rule as of 2026-08-30. Clock starts at materiality determination, not at incident discovery.
BK-7
May 2026
A Pennsylvania community bank filed what appears to be the first SEC Item 1.05 disclosure specifically for unauthorized employee use of an AI application exposing non-public customer information.
Details
CB Financial Services, Inc. Form 8-K, Item 1.05. Date of report 2026-05-07; filed 2026-05-15. Disclosed data: customer names, account numbers, SSNs, dates of birth.
BK-2
739
Financial-services data compromises tracked by ITRC ranged from 136 (2020) to 739 (2025), with dips in 2022 and 2024, not a steady climb.
Details
ITRC 2025 Annual Data Breach Report, Financial Services breakout. Commercial banks and insurance, not Credit Unions or Fintech.
BK-4
43%
The share of security incidents involving unapproved "shadow AI" more than doubled, from 20% in 2025 to 43% in 2026.
Details
IBM Cost of a Data Breach Report 2026. 602-organization study, IT industries broadly, not Financial-only.
CREDIT UNIONS

Your examiner will ask where member data goes.
NCUA can't sit inside that vendor. You can.

Core, loan files, call recordings, emails, shared drives, five places member data lives, and one regulator with no authority to examine the vendors holding it.

← Industries

CREDIT_UNIONS.SYS
Figures and Stats
Data provided from cited sources. Citations
CU-8
539
Reportable cyber incidents, latest NCUA congressional-report window.
Details
1 May 2024 – 30 April 2025. Federally insured credit unions. NCUA, Cybersecurity and Credit Union System Resilience Report, June 2025. ATM jackpotting, BEC/phishing, ransomware, and third-party service providers. No incident was systemic.
CU-12
72 hours
Federally insured credit union: maximum time to notify NCUA of a reportable cyber incident, including after a third-party notice.
Details
12 CFR § 748.1(c), eCFR. Effective 2023-09-01. Third-party clock starts at vendor notification or reasonable belief, whichever is sooner.
CU-3Y
$13,525,000
Opened class common funds, member-data incidents, 30 Aug 2023–30 Aug 2026. Not fines.
Details
Court-authorized settlement agreements and notices. Not fines. Does not include the DFPI penalty. Claims-made, vendor-fund, overdraft, and non-CU matters are omitted.
CU-10
742 / 70%
742 of 1,072 reportable cyber incidents (about seven in ten) in the first full NCUA reporting year involved a third-party vendor.
Details
NCUA Board briefing, Oct 24 2024. 742 reports grouped into 13 third-party events. Window 1 Sept 2023–31 Aug 2024.
CU-11
234
A single third-party incident affected 234 credit unions in the first NCUA reporting year, the largest of 13 such events that year.
Details
NCUA Cybersecurity Briefing, Oct 24 2024. Second largest 200; third 55; fourth 50; fifth 40. Total third-party reports = 742.
CU-E1
$100,000
A California DFPI cybersecurity consent order penalized an entity $100,000, a regulator fine, not a figure for all credit unions.
Details
California DFPI Consent Order, effective 2025-02-04. Not summed with the class-settlement funds in CU-3Y.
FINTECH

Data is in everything these companies do.
The leak is not inside the named core.

Products, cores, surrounds, and third-party white labels. Every layer holds a different slice of customer data, and every layer has its own vendor chain beneath it.

← Industries

FINTECH.SYS
Figures and Stats
Data provided from cited sources. Citations
FT-1
500 / 30d
FTC notification threshold (consumers) and clock (days) for unencrypted customer information.
Details
16 CFR 314.82(c), FTC Safeguards Rule. Effective 2024-05-13; eCFR current as of 2026-08-27. Financial institutions subject to FTC jurisdiction.
FT-LD
16,924,007
People affected in the January 2024 loanDepot customer-data incident.
Details
In re loanDepot Data Breach Litigation, D. Mass. Court order and Final Approval Hearing, 2026-08-19. A people count, not a dollar figure and not the class-funds total.
FT-CFPB-1
$25,000,000
CFPB civil money penalty for unfair information-security practices over sensitive consumer financial information.
Details
ACI Worldwide / ACI Payments, Inc. CFPB Consent Order 2025-CFPB-0006. Filed 27 June 2022; payments processor. Not a fintech-wide average, a single-company civil money penalty.
FT-LF-4
$17,858,259.09
Evolve Bank / Synapse opened a class settlement fund, a class fund, not a regulator fine.
Details
Court-authorized settlement agreement and notice.
FT-DF-1
$2,000,000
PayPal, Inc. paid a NYDFS Part 500 civil monetary penalty tied to unredacted SSNs and access-control failures.
Details
NYDFS press release, Consent Order, In the Matter of PayPal Inc., dated 2025-01-23.
FINRA-C1
$375,000
FINRA fined Cash App Investing LLC for failing to safeguard customer information under Regulation S-P.
Details
FINRA Disciplinary and Other Actions, December 2025. Reg S-P Rule 30(a). Reported scope: ~5.3 million customer account numbers and related PII.
HEALTHCARE NEW

192.7 million records.
One missing login step.
The largest healthcare breach in history.

Change Healthcare's CEO confirmed under Senate testimony that the breach came down to one remote-access portal without multi-factor authentication, company policy required it, but it hadn't been enabled. EHR, scribe AI, billing, and claims clearinghouses all touch PHI the same way; cataloging your own exposure is the only version of this that's actually in your control.

← Industries

HEALTHCARE.SYS
Figures and Stats
Data provided from cited sources. Citations
HC-PIN2 ★ LANDMARK
192,700,000
The Change Healthcare / UnitedHealth breach is now the largest healthcare data breach ever recorded, caused by a remote-access portal with no MFA enabled.
Details
UnitedHealth Group CEO Andrew Witty confirmed under Senate testimony that attackers used a compromised credential on a Citrix remote-access portal that lacked MFA, company policy required it, but it wasn't enabled. The affected count grew from an initial 500 to 100 million to a final 192.7 million as of 2025-07-31. UnitedHealth paid a $22M ransom that did not prevent data leakage; total cost is estimated above $3B. This has replaced Anthem's 2015 breach as the field's reference point for scale.
HC-1
60 days
Maximum time a business associate has to notify a covered entity after discovering a breach of unsecured PHI.
Details
45 CFR § 164.410(b). "Without unreasonable delay and in no case later than 60 days from discovery of the breach." Applies to every business associate, not just the covered entity. Contracts can shorten this window; HIPAA does not require them to.
HC-2
500
Individual threshold above which a breach must be reported to HHS within 60 days and listed publicly on the HHS breach portal.
Details
45 CFR § 164.408. Breaches under 500 individuals can be batched into an annual report, but are still reportable. HHS.gov, Breach Notification Rule.
HC-3
$10,000
OCR's total federal penalty against a business-associate software vendor whose breach exposed 15 million patients' PHI.
Details
MMG Fusion, LLC (patient-communication software for dental practices), HHS OCR resolution agreement, 2026-03-05. OCR set the penalty at $10,000 specifically because the company had gone out of business, not because the harm was small.
HC-4
$590,000
Combined federal + state penalties against one ambulance-billing business associate for a single ransomware breach.
Details
Comstar, LLC, serving 70+ covered entities. HHS OCR settlement: $75,000 (2025-05-30). Massachusetts + Connecticut AG settlement for the same 2022 breach: $515,000 (2026-01-28). HIPAA's federal penalty was a fraction of what state regulators later required for the identical incident.
HC-REG1
Proposed
A pending HIPAA Security Rule update would make MFA and encryption mandatory rather than "addressable", the exact gap that caused HC-PIN2 above.
Details
NPRM published in the Federal Register 2025-01-06; 4,000+ comments received. Not yet final, one tracker cites OMB targeting as late as July 2027. The current 60-day rule (HC-1) still governs until this is finalized.
INSURANCE NEW

28 states have the same rule now.
Two insurers turned into eight.
And there's a second NAIC rule just for AI.

The NAIC model law reads almost clause-for-clause like the GLBA vendor-oversight duty your Banks page already covers. The 2024 quoting-tool breach wasn't a two-company story either, regulators eventually fined eight auto insurers for the same pattern. And a separate NAIC bulletin now requires insurers to govern their AI the same way they govern everything else.

← Industries

INSURANCE.SYS
Figures and Stats
Data provided from cited sources. Citations
IN-1
28
Jurisdictions the NAIC considers substantially similar to its Insurance Data Security Model Law (#668), as of its August 2025 update.
Details
NAIC Model Law #668, adopted 2017; 28 of 56 NAIC member jurisdictions as of the August 2025 legislative brief. Requires a written information security program and due diligence over third-party service providers. Penalties vary by state statute: Pennsylvania sets $1,000/violation (max $20,000/year aggregate) for unknowing violations and $5,000/violation (max $100,000/year) where the licensee knew or should have known, 40 Pa. C.S.A. § 4501 et seq. Connecticut allows up to $50,000 per violation. Confirm the specific state before citing a figure to a prospect.
IN-2
$2,000,000
NYDFS civil penalty against a licensed insurance agent and independent adjuster for cybersecurity-regulation violations.
Details
Healthplex, Inc., NYDFS Consent Order, announced 2025-08-14. A phishing attack on an employee's email account led to exposure of private health data and NPI for tens of thousands of consumers. NYDFS found the company had used MFA on its email previously but failed to reinstate it after a system migration, a straightforward, avoidable control gap, not a novel attack.
IN-3 / IN-5
$19,000,000
The GEICO/Travelers penalty wasn't isolated. NY regulators ultimately fined eight auto insurers a combined $19M+ for the same quoting-tool vulnerability.
Details
IN-3: GEICO ($9.75M) and Travelers ($1.55M), joint settlements announced 2024-11-25, driver's license numbers and dates of birth for 120,000+ New York consumers stolen, some used for fraudulent pandemic-era unemployment claims. IN-5: joint NY OAG/NYDFS settlements with a total of eight auto insurers, announced 2025-10-14, confirming this was an industry-wide exposure pattern, not a two-company incident. The breach was in the insurers' own customer-facing applications, not a downstream vendor.
IN-AI1
Dec 2023
A separate NAIC bulletin requires insurers to maintain a written AI governance program, and explicitly states a third-party AI vendor's compliance problem is the insurer's problem too.
Details
NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted 2023-12-04. Distinct from the Data Security Model Law (IN-1), this one covers AI specifically: governance, risk management, bias testing, and vendor accountability. As of mid-2026, 25+ states have adopted it. Guidance, not binding law, until a state adopts it.
IN-7
$3,250,000
Progressive paid $3.25M after a third-party call center vendor let unauthorized individuals access 347,100 customers' data, the vendor caused the breach, not Progressive itself.
Details
Okonski v. Progressive Casualty Insurance Co., N.D. Ohio. Breach period May 2021-May 2023, discovered via third-party call-center vendor credential misuse. Settlement reached January 2025. The exact vendor-chain pattern this whole site is built around.
IN-6
$6,000,000
One third-party administrator's breach triggered a single class settlement covering customers of six different life insurance companies, a vendor-chain breach, not a single-carrier incident.
Details
Landmark Admin LLC breach (May-June 2024) affecting customers of American Benefit Life, American Monumental Life, Capitol Life, Continental Mutual Insurance, Liberty Bankers Life, and Accendo Insurance. $6M settlement, final approval 2026-01-29.
PRIVATE EQUITY

Regulation S-P: 30 days to notify.
72 hours for a vendor to tell the adviser.
It is not a PE survey.

Shadow AI is becoming one of the defining diligence issues of the next several years, and the absence of a centralized AI record is, on its own, a material finding.

← Industries

PRIVATE_EQUITY.SYS
Figures and Stats
Data provided from cited sources. Citations
PE-S1
30 days
Covered institution: maximum days to notify affected individuals after becoming aware of unauthorized access to customer information (includes SEC-registered advisers). Does not apply by force of Reg S-P to firms that are not covered institutions.
Details
17 CFR § 248.30(a)(4)(iii), Regulation S-P Safeguards Rule as amended. Adopted 2024-05-16; effective 2024-08-02; eCFR current as of 2026-08-27. Private funds themselves are not covered institutions, the adviser is.
PE-S2
72 hours
Covered institution: maximum hours for a service provider to notify the firm after becoming aware of a breach of a customer information system it maintains. Applies in the Reg S-P covered-institution regime only.
Details
17 CFR § 248.30(a)(5)(i). eCFR current as of 2026-08-27. Service-provider oversight required of covered institutions, including SEC-registered investment advisers.
PE-E2
$8,200,000
Class settlement fund for the LastPass data security incident (not a regulator CMP).
Details
In re LastPass Data Security Incident Litigation, D. Mass, 1:22-cv-12047-PBS. Court-authorized notice, opened 2026-08-30. Class settlement, not a fine. LastPass US LP is the named defendant; its PE sponsors are excluded parties, not the defendant.
PE-E4
$20,000,000
A Boston-based private equity firm was defrauded of $20M after investing in a startup that marketed itself as an "AI-powered" payments platform which, per federal prosecutors, never actually functioned.
Details
United States v. Marcus Cobb, indicted 2025-11-20 (justice.gov press release). Wire fraud conspiracy charge. Fraud discovered by the investor itself in Feb 2025; investor confirmed via press reporting as Volition Capital.
PE-E3
$3,000,000
A Canadian court approved a $3,000,000 class settlement against LastPass and GoTo entities, separate from the larger US LastPass class fund; never add the two together.
Details
Karan Keswani and N.W. v. GoTo Technologies USA Inc. et al. Settlement approved 2026-02-18.
PE-EX1
FY2026
The SEC's FY2026 exam priorities name AI risk, Regulation S-P/S-ID compliance, and third-party vendor oversight as explicit focus areas for private fund advisers.
Details
SEC Division of Examinations, FY2026 Examination Priorities, released 2025-11-17. Applies broadly to registered investment advisers including PE-affiliated ones.
VERTICAL MARKET SOFTWARE

The product has data.
The company has data.
Usually, neither one is cataloged.

Vertical software sits inside nonprofits, schools, healthcare, dealerships, and more, holding customer data in the product and in the vendor's own systems. AI is increasingly embedded in what they sell, and multi-unit operators often cannot point to one map.

The settlements and filings that prove the pattern are in Sources below, not in the headline.

← Industries

VERTICAL_MARKET_SOFTWARE.SYS
Figures and Stats
Data provided from cited sources. Citations
VMS-E2
$49,500,000
A vertical-market software company serving nonprofits, schools, and healthcare organizations paid a 50-state settlement for downplaying a 2020 ransomware breach instead of disclosing it.
Details
Blackbaud, Inc. Multistate AG settlement, announced 2023-10-05, all 50 states plus DC. Regulators alleged Blackbaud failed to remediate known security gaps and then downplayed the incident, delaying or preventing notification to its own customers, the same "vendor decides what you get told" dynamic APSTRAT exists to catch before it happens.
VMS-E3
$25,000,000
An auto-dealer software vendor's ransomware attack took its platform offline for ~19 days across 15,000 dealerships; industry losses are estimated above $1 billion. Litigation is still pending.
Details
CDK Global. Ransomware attack attributed to the BlackSuit group, June 2024. Two plaintiff classes have emerged: dealerships seeking business-interruption damages, and consumers whose PII was stored in the platform. No settlement reached as of this research, status: pending.
VMS-1
A holding company's own FY2025 MD&A names AI as a risk factor for data privacy, security, and misuse of personal information.
Details
Constellation Software Inc., FY2025 MD&A, Risks and Uncertainties, dated 2026-03-09. Filed by the parent holding company, not any individual portfolio business.
VMS-4
A peer holding company discloses reliance on third-party AI platforms that can implicate its own end users' personal data.
Details
Roper Technologies, Inc., Form 10-K FY2025, Item 1A. "The use of AI applications may result in cybersecurity incidents that implicate the personal data of end users of such applications."
VMS-5
29
Independently operated business units at one peer holding company, a scale of decentralized IT that makes central data cataloging structurally hard.
Details
Roper Technologies, Inc., Form 10-K FY2025, Item 1C. A single company's own count, not a figure for the vertical market software industry as a whole.
VMS-E1
$5,100,000
Multistate AG civil penalties and costs against an education-software company for failing to protect student data.
Details
Illuminate Education, Inc., still sourced only from the client's earlier document, not independently verified against a primary AG filing. Treat as needing verification before publishing.
WEALTH MGMT NEW

Private wealth is not one registration story.

One tile. Three optional views. Wealth Management, RIA, and Family Offices (single / multi). Same data, AI, and vendor questions. Different clocks, opacity, and who the exam theater reaches.

Traditional wealth platforms and broker-dealer / advisory stacks. Data sprawl across CRM, custody, planning tools, and third-party processors, often with Reg S-P coverage when the firm is a covered institution.

Lead: inventory the map, then AI governance and vendor-held data, not a generic control deck.

← Industries

TRACE_THE_DATA.SYS · WEALTH_MGMT
Figures and Stats
Data provided from cited sources. Citations
WM-E3
$45,000,000
Robinhood Securities and Robinhood Financial paid the largest Reg S-P/S-ID penalty on record for failing to safeguard customer information and maintain an adequate identity-theft program.
Details
SEC settled order, January 2025. Combined civil penalties against Robinhood Securities LLC and Robinhood Financial LLC. Broker-dealers, not RIAs strictly, but Reg S-P/S-ID apply identically to SEC-registered advisers, same regulatory framework as WM-1/WM-2.
WM-E4a
$1,250,000
Fidelity paid a Massachusetts state consent order after failing to notify all affected individuals in a 2024 data breach exposing ~77,000 customers' information.
Details
Consent order, Secretary William Galvin. ~77,000 individuals affected nationally, ~2,768 in Massachusetts. An unauthorized third party accessed document images containing sensitive information; the state found Fidelity failed to notify some affected individuals.
WM-E4b
$2,500,000
Fidelity separately paid $2.5M to settle a consolidated class action for the same 2024 breach, a class settlement, not a regulator fine, and not additive to the Massachusetts penalty above.
Details
Consolidated federal class action settlement, same underlying incident as WM-E4a. Two separate proceedings for two separate purposes, do not sum the figures.
WM-REG1
Dec 2025 / Jun 2026
Amended Regulation S-P took effect for larger RIAs ($1.5B+ AUM) on Dec 3, 2025, with smaller RIAs given until June 3, 2026, many smaller advisers are only now coming into scope.
Details
SEC Regulation S-P amendments, adopted 2024-05-16. Larger RIAs: compliance by 2025-12-03. Smaller RIAs (below $1.5B AUM): compliance by 2026-06-03.
WM-C1
10+
At least ten major RIAs, including Mercer Advisors, Edelman Financial Engines, Beacon Pointe, CW Advisors, Betterment, Pathstone, EP Wealth, Cetera, Ameriprise, and Hightower, disclosed cyberattacks or data breaches within roughly a single year.
Details
InvestmentNews, "Hightower knocks 'baseless' lawsuit as cyberattacks spread across RIAs," April 2026. A pattern/context citation showing this is systemic across wealth management, not isolated to one firm.
WM-NASAA1
100 / 471
State securities regulators opened 471 investigations into registered investment advisers in 2024 and brought 100 enforcement actions against them.
Details
NASAA 2025 Enforcement Report, released 2025-10-16, covering 2024 activity. Part of a broader $259M in state securities fines and restitution that year, that total figure spans all categories (broker-dealers, agents, IAs, unregistered firms), not investment advisers alone.