IT support for Financial Services

Advisory and financial offices where regulators, custodians and clients all ask what your controls are.

Financial firms face security questions from several directions at once: regulators, custodians, insurers and clients. The questions are broadly the same, and they are much easier to answer when the underlying work has been done and written down.

Most of what is asked comes down to access control, multifactor authentication, encryption, backup and recovery, logging, and a written incident response plan. The gap in most offices is not the controls themselves but the evidence that they exist and are maintained.

Communication records are the other recurring theme. Retention, archiving and supervision of email need to reflect the obligations the firm actually operates under, which is worth establishing before it is asked about.

What usually brings people in

  • Security questionnaires arrive with no evidence to answer them
  • Email retention and archiving obligations are unclear
  • Staff use personal devices for client communication
  • Access reviews have never been documented
  • An incident response plan does not exist in writing
  • Remote access was built for convenience rather than control
Next step

Fifteen minutes, no preparation needed

A short call is usually enough to work out whether this is a sensible fit for your business. Nothing is sold on it.

Book a 15 minute call