All insights

What should an advice firm be able to tell its licensee about cyber security?

6 min readBy Brendon Whiting, Founder · 14 April 2026

Specific, dated answers: whether multi-factor authentication is enforced everywhere, how devices are managed, when backups were last restored, who has administrative access, and what would happen in an incident. Assurances that security is taken seriously satisfy nobody any more, and a maturity report answers most of it in one document.

Licensee due diligence has tightened considerably, and the direction is one way. Where questionnaires once asked whether a firm had antivirus and a backup, they now ask about multi-factor authentication coverage, device management, patching cadence, incident response and supplier arrangements. That reflects what has actually been happening to advice firms, and it means the answers need to come from records rather than recollection.

The questions cluster into five areas, and it is worth knowing them in advance. Identity: is multi-factor authentication enforced on every account including principals, and how is access granted and removed. Devices: are they managed, encrypted and able to be wiped remotely. Data: where does client information live, is it backed up, and has a restore been tested. Incidents: who is notified, in what order, and how quickly. And suppliers: what do your providers have access to and what are their own arrangements.

Each of those has a good answer and a poor one, and the difference is evidence. A good answer to the multi-factor question is an export showing coverage across all accounts, dated. A poor one is that it is enabled. A good answer on backups is a restore log with dates. A poor one is that backups run nightly. Licensees have learned to ask for the first kind, because the second kind has too often turned out to be optimistic.

This is why an Essential Eight maturity assessment is worth more to an advice firm than its security value alone. It produces exactly the artefact these questionnaires are reaching for: a dated, control-by-control report with evidence behind each score. Firms that hold one find due diligence takes an hour rather than a week, because most questions are answered by attaching the report. And where there are gaps, having them documented with a remediation plan is a considerably better position than discovering them under questioning.

Write a short security policy to sit alongside it, and keep it honest. Two pages describing the systems you actually run, the controls in place, who is responsible and when it was last reviewed. Resist the template that describes technologies you do not have, because a reviewer notices immediately and it undermines everything else you have said. Date it, name an owner, and review it twice a year.

The incident plan is the piece most often missing and the one a licensee will care most about after something happens. One page: who declares an incident, who is contacted and in what order including the licensee, who speaks to clients, and what the first hour looks like. Names and mobile numbers, not roles. Keep it somewhere reachable when systems are down, which means not only on the file server.

Supplier arrangements are increasingly examined and firms are rarely ready. What access does your IT provider have, what do they do to secure their own environment, what happens to your data if the relationship ends, and who owns your tenant and domain. A good provider answers all four without hesitation, and asking is a reasonable part of your own due diligence rather than a sign of distrust.

Two habits keep this current rather than becoming a one-off exercise. Diarise a reassessment annually, because maturity drifts as staff, devices and software change, and an undated report from two years ago answers nothing. And treat the licensee questionnaire itself as a useful audit rather than paperwork, since it is a reasonable summary of what your licensee has learned actually goes wrong in firms like yours.

The honest caveats. Licensee requirements differ meaningfully, so confirm what yours expects rather than working from a general standard. This is not regulatory advice. And no report substitutes for the controls being real: a firm that assesses annually and fixes nothing has documented its own exposure carefully. If you want the report that answers most of these questions, the Cyber Security Scorecard is free, or call 1800 456 567.

Have the answers before you are asked

The free Cyber Security Scorecard produces a dated, control-by-control report with the evidence, which is what a licensee questionnaire is really asking for.

Frequently asked questions

Say so and attach a dated plan, which is a far better position than an inaccurate answer. Licensees and insurers deal with imperfect firms constantly and respond well to a true trajectory. An answer that turns out to be wrong is a separate and more serious problem than the gap it was concealing.

Usually yes, and it should be short, dated and describe systems you actually run. A two-page document that is accurate beats a twenty-page template that describes somebody else's business, and the second kind is easy to spot because it mentions technologies you do not have.

A named person, typically a principal, even where the work is done by a provider. Licensee obligations do not transfer to a supplier, so somebody in the firm needs to be able to speak to the arrangements. That is a governance requirement rather than a technical one, and it takes an hour a quarter.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.