How should an advice firm protect client financial information?
By protecting the mailbox with multi-factor authentication, verifying every change to payment or account details by telephone, managing every device that touches client information, and keeping dated evidence of all three. The evidence is not bureaucracy in this sector; it is what your licensee will ask for.
Advice firms hold an unusually concentrated set of information: financial positions, account numbers, identity documents, tax details and the instructions that move money between them. That concentration is what makes a small practice a worthwhile target, and it is why the security posture appropriate here is not the one appropriate to a similarly sized business in another sector.
The mailbox comes first because it is where attacks land and where the money is lost. Multi-factor authentication on every account, with no exceptions for principals who find it inconvenient, is the highest-value control available and the one most often incomplete. Beyond it, conditional access rules that consider the device and location of a sign-in turn a stolen password from an incident into a blocked attempt. The threat to design against is patient rather than dramatic: someone reading a mailbox for weeks, learning how the firm discusses rollovers and transfers.
Payment verification is second and is procedural rather than technical. Any change to bank or account details, whether it appears to come from a client, a product provider or a colleague, is verified by telephone to a number you already held, never a number supplied in the request itself. Make it unwaivable regardless of urgency, because manufactured urgency is exactly the pressure applied. This single rule prevents the loss that hurts most, and it costs nothing to implement beyond insisting on it.
Devices are third, and advice is a mobile profession. Advisers see clients at home, work from cars and cafes, and carry laptops and phones holding complete client financial pictures. Every one of those devices should be encrypted, managed, patched and remotely wipeable, which is what Intune or an equivalent delivers. Mansell Financial Services brought every device under Intune as part of their rebuild, and the practical effect is that a lost laptop becomes an administrative task rather than a notifiable incident.
Access control is fourth and is where small firms are often looser than they realise. Not everyone needs to see every client, particularly where staff have personal connections in a small community, and anything involving related parties or staff members deserves restriction. Structuring document storage so each area has its own permissions makes this straightforward, and it also makes departures manageable, since access can be removed cleanly rather than hunted down across a shared drive.
Then the evidence layer, which is where financial services diverges from general business advice. Being secure is necessary and insufficient; you must be able to show it. That means logging, access records, a dated maturity assessment, and an incident plan naming who is contacted and in what order, including your licensee. Firms that have this find due diligence questionnaires straightforward. Firms that do not spend a week assembling answers under time pressure, usually while a client or a licensee waits.
The Essential Eight is the practical organising framework, and it maps well onto the risks described. Multi-factor authentication, restricted administrative privileges, patched systems, application control and tested backups cover what actually happens to firms this size. Mansell replaced legacy antivirus with ThreatLocker specifically to move toward that standard. Reaching Maturity Level 1 is a one-to-three-month project rather than a transformation, and the report it produces does double duty as security and as evidence.
There is a human layer that no control replaces, and in a small firm it matters more rather than less. Staff should know how to report a suspicious email or an error, and the last person who did so should have been thanked. In a sector where the fraud arrives as a plausible email about a rollover during a busy week, the person who says something feels wrong is the most effective control you have and the cheapest to maintain.
The honest caveats. Nothing here is regulatory advice, and your obligations come from your licence, your licensee and the relevant law. Requirements differ between licensees, so confirm what yours expects rather than assuming a general standard. And no arrangement makes an incident impossible; the goal is to make it unlikely, contained, and something you can account for afterwards. If you want your controls and evidence reviewed together, call 1800 456 567.
Protect it and be able to prove it
We implement the controls an advice firm needs and produce the dated evidence your licensee or a due diligence questionnaire will ask for.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business