Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

IT and Cyber Security for Financial Advisers in the UK

In short

Financial advisers hold some of the most sensitive data a small business can: clients' wealth, identities and plans. This guide explains what the FCA expects on operational resilience and data security, how to protect client information, why secure email and tested backups matter, and how Cyber Essentials gives you a credible baseline.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

Why financial advisers carry extra responsibility

Few small businesses hold data as sensitive as a financial adviser. You know your clients’ wealth, their identities, their family circumstances and their plans for the future. You are also a regulated firm, which means the standard you are held to is higher than for the average small business. That combination, highly sensitive data and regulatory scrutiny, makes getting your IT and cyber security right a core part of running the practice, not an afterthought.

The reassuring news is that the fundamentals are achievable for a small firm. You do not need an enterprise security team. You need the right controls in place, evidence that they work, and a calm plan for when something goes wrong.

What the FCA expects

The FCA does not hand you a checklist of software to buy. Instead it expects firms to manage their risks sensibly, and technology risk is squarely part of that. Two themes are worth understanding in plain terms.

Operational resilience. The FCA wants firms to be able to keep serving clients, and to recover quickly, when something disrupts the business, whether that is a cyber attack, an IT outage or a failed supplier. In practice this means knowing which of your services matter most, understanding what could stop them, and having a tested plan to get back up and running.

Systems and controls. Firms are expected to have adequate arrangements to protect client information and run the business securely. That covers who can access what, how you guard against data loss, and how you handle an incident if one occurs.

None of this requires jargon or heavy spending. It requires deliberate, documented basics, applied consistently, that you can explain if asked.

Protecting client financial data

Client data is the crown jewel, so protect it accordingly.

  • Control access. Only the people who need to see a client’s file should be able to. Restricting access limits the damage if an account is ever compromised, and it is good practice in its own right.
  • Multi-factor authentication everywhere. Every system holding client data should require a second step beyond a password. This single control blocks the large majority of account takeovers. If it is unfamiliar, see multi-factor authentication explained.
  • Strong, unique passwords via a password manager. Reusing passwords across your platform, email and back-office tools is a real risk. A password manager such as Proton Pass removes the temptation and the memory burden. Our best password manager for small business guide compares the options.
  • Encrypt every device. Laptops and phones get lost. Encryption keeps the data on them unreadable to anyone who finds them.
  • Know where the data lives. Understand which systems hold client information and how each one is secured and backed up, including any spreadsheets or documents sitting outside your main platform.

Because you hold personal data, UK GDPR applies to you too. Our GDPR basics for UK small business guide covers the essentials without the legalese.

Secure email: where advisers are most exposed

Email is how advisers communicate, and it is also where the most damaging problems start. Two risks stand out.

The first is sending sensitive information insecurely. A valuation, a scan of a passport, or account details sent as a plain attachment can be exposed if that email is intercepted or misdirected. The fix is to use encrypted email, a secure client portal, or at minimum password-protected files where the password is shared by a separate channel. Encrypted email services such as Proton Mail make this easier to do consistently.

The second is business email compromise, where a criminal impersonates you, a client or a provider to redirect a payment or extract information. For an adviser, a fraudulent instruction to move client funds is the nightmare scenario. Verify any payment or bank-detail change through a trusted phone number, never by replying to the email. Our explainers on business email compromise and how to spot a phishing email show your team what to watch for, and tightening your Microsoft 365 security settings stops many fakes before they arrive.

For an adviser, a fraudulent instruction to move client funds is the nightmare scenario.

Backups and staying operational

Operational resilience is not an abstract idea; it is answered by your backups and your recovery plan. If ransomware locked your files tomorrow, or a hard drive failed, could you still access your client records and advice history?

Good backup practice for a small firm is simple to state:

  • Back up your important data automatically and frequently.
  • Keep at least one copy separate from your main systems, so a single incident cannot destroy both.
  • Test that you can actually restore, on a regular basis, not just assume it works.

Pair that with a short, written plan covering who does what if systems go down, and you have the substance of operational resilience that the FCA is looking for.

Cyber Essentials: a credible baseline

Cyber Essentials is a UK government-backed scheme that certifies you have the core protections in place: secure configuration, access control, protection from malware, up-to-date software, and firewalls. It already requires multi-factor authentication on your cloud services, which aligns neatly with everything above.

For a financial adviser it does two useful things. It gives you a structured way to check your basics are genuinely covered, rather than assumed. And it provides recognised evidence, for the FCA, for professional indemnity insurers and for clients, that you take security seriously. It is not a legal requirement, but it is one of the clearest ways a small firm can demonstrate good practice.

One related point worth acting on: Windows 10 support ended on 14 October 2025, so any machines still running it no longer receive security updates and should be upgraded or replaced.

How DACROS supports advisers

Most advice firms do not want to run IT themselves; they want it handled properly so they can focus on clients. That is the role of managed IT support, explained in our overview of what managed IT support is.

At DACROS we work with financial advisers across Leeds and Yorkshire to secure client data, put encrypted email and MFA in place, sort out reliable tested backups, and achieve Cyber Essentials. You can see our full services and small-business pricing online, and we are happy to speak the language of your compliance obligations rather than baffle you with technology.

If you would value a straightforward review of where your firm stands, get in touch for a no-pressure conversation.

Frequently asked questions

Does the FCA require a specific cyber security certification?

The FCA does not mandate a particular certification, but it does expect firms to manage technology and cyber risk sensibly as part of operational resilience and its systems and controls rules. Cyber Essentials is a widely recognised way to demonstrate you have the basics in place, which is why many advisers pursue it even though it is not strictly compulsory.

Is it safe to email clients about their finances?

Ordinary email is fine for general correspondence, but sending sensitive documents such as valuations, ID or account details needs more care. Options include encrypted email, a secure client portal, or password-protected files with the password shared separately. The key is not to send highly sensitive personal and financial data as plain, unprotected attachments.

How often should we back up our systems?

Client records and advice files should be backed up automatically and frequently, ideally daily, with at least one copy kept separate from your main systems. Just as important is testing that you can actually restore from those backups. A backup you have never tested is not something you can rely on when it matters.

We use a big platform provider, so isn't cyber security their job?

They secure their platform, but you remain responsible for your own firm: your email, your devices, your staff logins and the client data you hold locally. Most breaches at small firms come through a tricked employee or a weak password, not the platform itself, so your own controls matter as much as your provider's.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.