What an external cyber review actually asks you for

What an independent cyber review asks an advisory firm for, and the one question most firms cannot answer from records.

Back to Insights
Photo: What an external cyber review actually asks you for

12

Advisory, accounting and wealth firms

5

Users onboarded to a managed security bundle

The Story

If you run an advisory, accounting or wealth management firm, someone is going to ask you how client data is protected. A client, an insurer, a licensee, or an auditor acting for one of them.

The firms that handle that question well are not the ones with the most security products. They are the ones who can answer it from a document rather than from memory.

Start by having someone independent look

One wealth management firm we support goes through an external cyber review every year. Not us reviewing our own work, an outside party reviewing it.

We were not told what that review concluded, so we are not going to characterise it. What is worth copying is the sequence. Have somebody independent look first, get the findings in writing, then work through the list in order rather than buying whatever is front of mind.

In the weeks after that firm’s report landed, the work was exactly that list being worked. A review of email security, data protection and endpoint policies. A managed security bundle rolled out across users. Phishing tests put in front of staff.

None of it was dramatic. All of it was in an order somebody else had set.

The question most firms cannot answer

Who outside your firm has access to your files, and why?

Outside access is normal and often necessary. An advisory firm we support needed an external auditor given access to SharePoint. Earlier it had given a contractor administrator rights to the same place. Both were granted for good reasons.

Here is the part worth writing on a wall. Access is granted for a reason, and the reason almost always finishes before the access does.

The audit ends. The contractor’s project wraps up. The temporary administrator rights stay exactly where they were, usually until someone goes looking, which is usually during the next review.

Granting outside access properly takes a few minutes longer: scoped to the folders actually needed, with an end date, and written down. It is the difference between a reviewer seeing a controlled process and a reviewer seeing a list of people you have lost track of.

What to have ready before your next review

You can assemble all of this yourself, and it is worth doing whether or not anyone has asked yet.

  • A current list of every account with administrator access.
  • Multi-factor sign-in confirmed on every account, shared ones included.
  • Your email security settings and data protection policies, written down rather than remembered.
  • The date backups were last restored from, not the date they last ran.
  • A list of who outside the firm can reach your files, and why each of them still needs to.
  • Evidence of staff security awareness training, such as phishing test results.

If you cannot produce that last one from records rather than recollection, start there. It is the item reviewers press hardest on, and the one firms most often get wrong.

Why advisory firms end up with us

Because the question is not really about technology. It is about whether your provider can hand you evidence when a client or an insurer asks for it, without a fortnight of scrambling.

If you would like help getting ready for your next external review, get in touch.

  • The Impact of Inaction

    "A review arrives and the firm scrambles to work out who holds administrator access, what its email security settings are, and when a backup was last restored. Access granted for an audit stays open long after the audit finished."

  • The Bastion Fix

    An independent review first, then its findings worked in order: a policy review, managed security across users, phishing tests in front of staff. Outside access scoped to the folders actually needed, with an end date, and written down.

Next Action

Gather the six items in this post before your next external review, so the review tests your security instead of your paperwork.

Teaching Moment

Access is granted for a reason, and the reason almost always finishes before the access does.

Want these results for your business?