Jul 15, 2026 · 33 min · 13 segments
A former SEC enforcement director on the difference between being secure and being defensible. Ana Petrovic (Kroll) on what examiners really look for, how infosec became an insider-trading control…
Anna PetrovicGuestCyber Security Cafe HostHost
Um, what I tell clients, um, it's not a matter of if, but usually a matter of when you'll have some kind of incident, no matter if it's something minor or major.

Defensible is essentially when you take a proactive approach to understand both the regulations and the related risk profile of your firm, and then develop a plan that, that is tailored to those functions.

You need someone with the technical skill set to guide you through what are the cybersecurity risks? What are the data security risks? But you also need to have a regulatory expert [laughs] guiding you on, well, what does a regulator expect to have controls in place?
[piano music] Welcome back to the Cybersecurity Cafe, where we talk about the place where cybersecurity meets the business, not the firewall, the boardroom.
If you run an investment firm, a registered investment advisor, a private fund, a hedge fund, here's a shift that you need to understand.
For years, information security sat in the IT column.
Today, your examiner sees it as a control on insider trading.
The line between who can access sensitive information and who you, who could trade on it has effectively collapsed.
And the firms that have not internalized that are the ones getting surprised by an exam.
Our guest today has lived on both sides of that line.
Anna Petrovic has spent more than ten years at the SEC.
She oversaw the complex financial instruments unit and led some of the landmark DeFi and crowdfunding enforcement cases.
Today, she's director of financial services compliance and regulation at Kroll, which means she now helps firms stay out of the exact situation she was helped investigating before.
Anna, welcome to the show.
Read the full transcript.
Create an account to read the whole episode, search across every transcript, and follow the shows you care about.

Um, what I tell clients, um, it's not a matter of if, but usually a matter of when you'll have some kind of incident, no matter if it's something minor or major.

Defensible is essentially when you take a proactive approach to understand both the regulations and the related risk profile of your firm, and then develop a plan that, that is tailored to those functions.

You need someone with the technical skill set to guide you through what are the cybersecurity risks? What are the data security risks? But you also need to have a regulatory expert [laughs] guiding you on, well, what does a regulator expect to have controls in place?
[piano music] Welcome back to the Cybersecurity Cafe, where we talk about the place where cybersecurity meets the business, not the firewall, the boardroom.
If you run an investment firm, a registered investment advisor, a private fund, a hedge fund, here's a shift that you need to understand.
For years, information security sat in the IT column.
Today, your examiner sees it as a control on insider trading.
The line between who can access sensitive information and who you, who could trade on it has effectively collapsed.
And the firms that have not internalized that are the ones getting surprised by an exam.
Our guest today has lived on both sides of that line.
Anna Petrovic has spent more than ten years at the SEC.
She oversaw the complex financial instruments unit and led some of the landmark DeFi and crowdfunding enforcement cases.
Today, she's director of financial services compliance and regulation at Kroll, which means she now helps firms stay out of the exact situation she was helped investigating before.
Anna, welcome to the show.