If you run an advisory, accounting or wealth management firm, someone is going to ask you how client data is protected. A client, an insurer, a licensee, or an auditor acting for one of them.
The firms that handle that question well are not the ones with the most security products. They are the ones who can answer it from a document rather than from memory.
Start by having someone independent look
One wealth management firm we support goes through an external cyber review every year. Not us reviewing our own work, an outside party reviewing it.
We were not told what that review concluded, so we are not going to characterise it. What is worth copying is the sequence. Have somebody independent look first, get the findings in writing, then work through the list in order rather than buying whatever is front of mind.
In the weeks after that firm’s report landed, the work was exactly that list being worked. A review of email security, data protection and endpoint policies. A managed security bundle rolled out across users. Phishing tests put in front of staff.
None of it was dramatic. All of it was in an order somebody else had set.
The question most firms cannot answer
Who outside your firm has access to your files, and why?
Outside access is normal and often necessary. An advisory firm we support needed an external auditor given access to SharePoint. Earlier it had given a contractor administrator rights to the same place. Both were granted for good reasons.
Here is the part worth writing on a wall. Access is granted for a reason, and the reason almost always finishes before the access does.
The audit ends. The contractor’s project wraps up. The temporary administrator rights stay exactly where they were, usually until someone goes looking, which is usually during the next review.
Granting outside access properly takes a few minutes longer: scoped to the folders actually needed, with an end date, and written down. It is the difference between a reviewer seeing a controlled process and a reviewer seeing a list of people you have lost track of.
What to have ready before your next review
You can assemble all of this yourself, and it is worth doing whether or not anyone has asked yet.
- A current list of every account with administrator access.
- Multi-factor sign-in confirmed on every account, shared ones included.
- Your email security settings and data protection policies, written down rather than remembered.
- The date backups were last restored from, not the date they last ran.
- A list of who outside the firm can reach your files, and why each of them still needs to.
- Evidence of staff security awareness training, such as phishing test results.
If you cannot produce that last one from records rather than recollection, start there. It is the item reviewers press hardest on, and the one firms most often get wrong.
Why advisory firms end up with us
Because the question is not really about technology. It is about whether your provider can hand you evidence when a client or an insurer asks for it, without a fortnight of scrambling.
If you would like help getting ready for your next external review, get in touch.
