Financial advice briefing

The technology problems that actually bite small advice firms

A plain-English briefing on where IT goes wrong in a small financial advice practice, what it costs when it does, and what the fix usually looks like. Written for sole advisers and firms of a few RIs — the ones without an IT department.

Written for advice firms without an IT department
Every figure sourced and linked
Downloadable as a PDF

Most writing about IT for financial services is aimed at firms with a COO, a compliance function and a hundred advisers. That is not much use if there are three of you, the back-office system is whatever the network mandated, and IT is whoever is least busy that day.

So this is the small-firm version. Nine problems I keep finding, why each one lands harder on an advice firm than it would on any other business of the same size, and what a sensible fix looks like. No products, no scare stories, and every figure attributed so you can check it — including the bits where the rules do not apply to you, which is at least as useful as the bits where they do.

The briefing

Nine problems, and what each one really costs.

Problem 1 of 9

The client who sends the money to the wrong account

A client is releasing tax-free cash, or funding an ISA, or settling an adviser charge. They get an email that reads exactly like the last dozen — your signature, your turn of phrase, the right reference — telling them the account details have changed. They send it. Nobody notices for a fortnight.

You are not a bank and you may never touch client money at all, which is precisely why this is dangerous: the money moves on your say-so without passing through anything you control. When it goes wrong the client does not say “I was defrauded”, they say “my adviser told me to send it there” — and that is a complaint, a Financial Ombudsman file and a PI notification, whether or not your systems were ever breached. Frequently they were not. The attacker is often sitting in the client’s own webmail reading a thread you are only one participant in. The FCA’s own consumer warnings are dominated by exactly this pattern: cloned firms and impersonated advisers using details that check out against the Register.

38%

of UK businesses experienced phishing in the last twelve months — the most common form of attack by a wide margin, and the delivery mechanism for almost every case of this kind

DSIT — Cyber Security Breaches Survey 2025/26 (43% of businesses identified a breach or attack; phishing 38%, impersonation 12%)
What good looks like
  • Multi-factor authentication on every mailbox, with legacy authentication switched off so it cannot simply be walked around
  • Alerting on new mailbox forwarding and inbox rules — the first thing an intruder sets up, and the thing that keeps them invisible
  • SPF, DKIM and DMARC set to reject, so that somebody else cannot send email as your domain
  • External-sender warnings, and impersonation protection tuned to your own advisers’ names
  • A written rule, told to clients at the outset, that payment details are confirmed by phone on a number you already held — and that they will never change by email
Problem 2 of 9

The fact-find is the most sensitive file in the building

One document holds the client’s income, their debts, their bank details, their date of birth, their National Insurance number, their marriage, their children, their will — and, if there is any protection business, their medical history.

Most small businesses hold personal data. You hold the set a fraudster would design if they could. And the moment protection or health-related underwriting is in the file, you are processing special category data under Article 9 of the UK GDPR, which needs a lawful basis of its own and carries a materially higher standard of care. The practical failure I find is not encryption — it is location. The fact-find exists in the back-office system, in an email attachment, in a scan on the office multifunction device, in a folder on the adviser’s laptop, and in the paraplanner’s downloads. Five copies, one of which is protected properly.

What good looks like
  • One place client files genuinely live, with everything else treated as a copy to be removed rather than a convenience to be tolerated
  • Sensitive documents shared by link with an expiry, not as attachments that live forever in two mailboxes
  • Encryption on every laptop and phone that has ever opened a fact-find, verified rather than assumed
  • Retention that actually deletes — a review file you no longer need is a liability, not an asset
  • Knowing, today, which folders contain health information and who can open them
Problem 3 of 9

You have outsourced the systems, not the responsibility

The back-office system is somebody else’s cloud. The platform is somebody else’s. The cashflow modeller, the risk profiler, the paraplanner and — if you are appointed representative — most of the compliance stack all belong to other people.

That is a sensible way to run a small firm, and it is not the problem. The problem is the assumption that goes with it: that because the system belongs to someone else, so does the risk. It does not. Under SYSC 8 the firm remains responsible for outsourced functions, and the Consumer Duty makes the point again in plainer language — where you can reasonably foresee harm to a retail client you are expected to act on it, including in arrangements you did not build. In practice that means you are answerable for a provider whose security you have never asked a single question about, reached through a login you cannot see the MFA status of, holding data you could not extract in a hurry if the relationship ended badly.

What good looks like
  • A one-page list of every system holding client data, who owns it, and what happens if they go dark — kept current, not perfect
  • MFA switched on at every provider that offers it, and a straight question to the ones that do not
  • Named accounts at each provider rather than a shared firm login, so that leavers can actually be removed
  • Knowing how you would get your own data out, before you need to
  • Asking your network or platform for their security position in writing — they are used to the question, and the ones who are not are the answer
Problem 4 of 9

The regulatory asks have gone technical, and one has a date on it

The PI renewal now asks whether you use MFA. The network’s annual return asks about backups. And there is a new FCA reporting regime coming that your compliance consultant has probably mentioned once.

These used to be questions a director could answer from memory. They are now technical assertions somebody has to be able to evidence, and increasingly they are pass or fail rather than best endeavours. Four dates and scope points worth having straight — including the one that does not apply to you:

  • From 18 March 2027, FCA rules on operational incident reporting apply to all firms with a Part 4A permission. There is no small-firm exemption. A reportable incident goes to the FCA via Connect as soon as practicable, and no later than 24 hours after you decide it meets a threshold.
  • The material third-party register in that same policy statement does NOT apply to a small advice firm — it is limited to Enhanced-scope SM&CR firms and other larger categories. Anyone telling you a three-adviser practice must file one is selling something.
  • Nor do the operational resilience rules (PS21/3), with their important business services and impact tolerances, apply to a Core-scope firm. Your platform and your network are caught. You are almost certainly not.
  • Separately and already in force, SUP 15.3 and Principle 11 require you to tell the FCA about significant breaches and about fraud, errors and irregularities — which is where a serious cyber incident lands today, in advance of the 2027 regime.
  • From 26 April 2026, Cyber Essentials v3.3 makes missing MFA on cloud services an automatic fail, as is failing to apply critical and high-risk updates within 14 days. Relevant if a client, a network or an insurer asks you to hold it.
What good looks like
  • Decide now, in writing, who declares an incident and who files it — the 24-hour clock in 2027 starts when you determine a threshold is met, not when you finish investigating
  • Keep the evidence continuously, so a questionnaire becomes an export rather than an investigation
  • Get the gap review done early enough that falling short is private, cheap and fixable
Problem 5 of 9

You will be asked for the file long after you have forgotten the client

A complaint arrives about advice given in 2019. The adviser who gave it has retired. The back-office system has been migrated once since then.

Almost every other business can let old records rot. You cannot. The Financial Ombudsman can consider a complaint referred within six years of the event, or — if later — three years from when the client became aware they had cause to complain, and that second limb is what makes the true tail so much longer than six years. Your defence in every one of those cases is the file: the fact-find, the research, the suitability report, the disclosure, and the emails around them. If any part of that lives only in a former adviser’s deleted mailbox, or in a system you migrated out of without a readable export, then you do not have a defence — you have a recollection. Microsoft 365 will not save you here either: deleted items empty after 30 days by default, and a deleted mailbox is gone in 30.

What good looks like
  • Leavers’ mailboxes preserved and searchable rather than deleted to save a licence — this is the single most common gap I find
  • Retention labels that reflect your own retention policy, applied automatically instead of by good intentions
  • A readable export kept from any system you migrate away from, taken before the contract ends rather than after
  • The ability to answer “produce everything on this client” without it depending on one person’s memory
Problem 6 of 9

Backups you have never actually restored

There is a backup. It runs overnight and emails a report. Nobody has read the report in a year, and nobody has ever restored anything from it.

Two gaps, and the second one surprises people. First, an untested backup is a belief rather than a control. Second, Microsoft does not back up your Microsoft 365 — Microsoft keeps the service running, and keeping your data is your side of the bargain. If an intruder empties a SharePoint library or a leaver clears a mailbox, then past the retention window it is simply gone. And the scale of what a breach of pension and financial records now costs is no longer theoretical: the ICO’s largest recent penalty in this space was against an outsourcer whose stolen data included pension records.

£14m

fine issued by the ICO in October 2025 against Capita, after an attack in which the personal data of 6.6 million people — including pension records — was stolen

ICO — Capita fined £14m in October 2025 for a data breach affecting over 6 million people, including pension records
What good looks like
  • A separate backup of Microsoft 365 — mail, OneDrive, SharePoint and Teams — held outside the tenant it protects
  • A restore genuinely performed at least once, by someone who wrote down how long it took
  • A recovery plan that lives somewhere other than the thing that has just failed
  • Clarity on what your back-office provider backs up and what it does not, in writing from them
Problem 7 of 9

Everyone is an administrator, and the password is on a note

Three people, one shared login for the provider portal everybody needs, and the administrator knows the director’s password because otherwise nothing gets done on a Friday.

You lose attribution. When something goes wrong — an instruction submitted, a document altered, a client record changed — you cannot say who did it, and in a regulated firm that is precisely the answer you most need to have. Shared accounts cannot be properly protected with MFA and are never removed when someone leaves. The route in is rarely dramatic: the ICO fined a small professional firm £60,000 after attackers walked in through an infrequently used administrator account that had no MFA on it. That is not a sophisticated attack. That is a forgotten account.

£60,000

ICO fine against a small law firm in April 2025 after attackers accessed its network through an infrequently used administrator account with no multi-factor authentication

ICO — law firm fined £60,000 in April 2025 following a cyber attack that reached its network through an infrequently used administrator account without MFA
What good looks like
  • Named accounts for every person on every service, with no exceptions for convenience
  • Everyday accounts that are not administrators, and separate admin accounts used only for admin work
  • An audit of accounts nobody uses — the dormant admin login is the one that gets you
  • A password manager, so that “it has to be memorable” stops being an argument
  • A leaver checklist that runs on the day they leave, covering every provider portal as well as email
Problem 8 of 9

The box in the corner that still holds the old client files

There is a server, or an old desktop acting as one. It holds the archive from before the current back-office system, the scanned files, and the shared drive everyone maps to.

It is a single point of failure sitting in the same building as any fire, flood or burglary, and if the operating system has gone out of support it will fail Cyber Essentials on its own account. It is also precisely where ransomware wants to land, because every workstation in the office has a drive mapped to it. The particular problem for an advice firm is what is on it: the pre-migration archive is usually the oldest material you hold, which makes it the material most likely to be demanded in a complaint and the least likely to have been looked at this decade.

What good looks like
  • Honestly: most firms this size should not have one any more, and the archive is usually a one-off migration rather than a project
  • If it stays — a supported operating system, patched on a schedule, backed up off-site, and not reachable from the internet
  • Either way, a decision made deliberately rather than arrived at by drift
Problem 9 of 9

The AI tab that is already open

An adviser has a two-hour client meeting to write up and a review pack to prepare. There is a free tool one click away that will summarise the recording in thirty seconds.

There is no good reason advice firms should not use AI, and plenty of reasons they should. But the firm stays responsible for the output, the Consumer Duty still applies to what the client is eventually told, and the moment a client-identifiable fact-find or meeting recording goes into a consumer service you have engaged a third-party processor with no data processing agreement, no retention position and — if there is any health information in it — special category data in a place you cannot account for. The realistic risk is not a dramatic leak. It is that when a client, your network or your PI insurer asks whether client data has gone into AI tools, nobody in the firm can answer.

What good looks like
  • Give people a sanctioned tool inside your own tenant, so that the convenient option is also the compliant one
  • A short, readable AI policy saying what may and may not go in — one page, not twelve
  • Visibility of which AI services staff are signing into with work accounts
  • A clear position on meeting recordings: where they are stored, how long for, and whether the client agreed
Where to start

Seven questions worth asking on Monday morning

You do not need a consultant to work through these. If the answer to any of them is “I am not sure”, that is where I would start.

  1. 1Is MFA on every account — including every provider and platform portal, not just email?
  2. 2Are there mailbox forwarding rules that nobody in the firm put there?
  3. 3Is your DMARC record set to reject, or is it sitting on “none” and doing nothing?
  4. 4Has anyone ever restored a file from your Microsoft 365 backup — and is there one at all?
  5. 5If a complaint arrived tomorrow about advice given six years ago, could you produce the whole file?
  6. 6Which folders contain health information, and who can open them?
  7. 7Who would decide, and who would file, if you had to notify the FCA within 24 hours?

Which of these actually apply to you?

None of this needs a large project. Most of it is configuration that should have been set correctly on day one, plus two or three habits that have to be agreed rather than bought.

If you would like a second opinion, I will spend half an hour on your setup and tell you which of these actually apply to you. Not a report full of red traffic lights designed to sell you something — just a straight answer about where you stand, including the rules you are not in scope for.

Getting ready for FCA operational incident reporting? Cyber security for financial advisers →

Sources

Everything above, where it came from.

Several figures that circulate widely in IT marketing are deliberately absent, including the “60% of small businesses close within six months of a cyber attack” line, which I have never been able to trace to a real study. Scope statements above have been checked against the policy statements themselves rather than against commentary on them. If anything here does not hold up, tell me and I will correct it.

  1. 1.DSIT — Cyber Security Breaches Survey 2025/26 (43% of businesses identified a breach or attack; phishing 38%, impersonation 12%)
  2. 2.FCA PS26/2 — Operational incident and third party reporting. Incident reporting applies to all firms with a Part 4A permission; third-party reporting is limited to Enhanced-scope SM&CR firms and other larger categories. In force 18 March 2027
  3. 3.FCA PS21/3 — Building operational resilience. Applies to Enhanced-scope SM&CR firms, banks, building societies and insurers, not to Core-scope advice firms
  4. 4.FCA Handbook SUP 15.3 — general notification requirements, including significant rule breaches and fraud, errors and other irregularities
  5. 5.FCA Handbook PRIN 2A — the Consumer Duty, including the obligation to avoid causing foreseeable harm to retail customers
  6. 6.FCA Handbook DISP 2.8 — the Financial Ombudsman Service time limits: six years from the event, or if later three years from when the complainant became aware
  7. 7.FCA — pension scams and clone firms: fraudsters impersonating authorised firms and advisers using details that match the FCA Register
  8. 8.ICO — Capita fined £14m in October 2025 for a data breach affecting over 6 million people, including pension records
  9. 9.ICO — law firm fined £60,000 in April 2025 following a cyber attack that reached its network through an infrequently used administrator account without MFA
  10. 10.UK GDPR Article 9 — processing of special categories of personal data, which includes data concerning health
  11. 11.IASME — changes to Cyber Essentials from 26 April 2026 (Requirements v3.3)
Get in touch

Half an hour, and a straight answer.

Tell me roughly how many of you there are, what your back-office system is, whether you are directly authorised or with a network, and which of the nine above made you wince. I’ll come back within one working day. I work with small businesses across Lancashire and the North West, and I am the person you will actually speak to.

I'll only use your details to reply to your enquiry. No newsletters, no sharing.