← All industries
Financial advice & wealth · Industries

IT & Microsoft cloud for financial advice & wealth

Secure Microsoft 365, client portals, recoverable records and incident readiness for FCA-authorised financial planners, wealth managers and IFAs.

Book a call

Financial advice & wealth

In short: Secure Microsoft 365 and client portals, email that resists impersonation, records you can produce, and a plan for the day something goes wrong. Start with email and identity: that is where client money and client trust are most exposed, and it is the evidence the FCA and your clients will ask about first.

You can outsource your IT, but under FCA rules you cannot outsource the responsibility for it. A good IT partner should make that responsibility easier to carry, with evidence you can show rather than assurances you have to take on trust.

Oversight evidence you can show, and a runbook before the 2027 incident rules. Plays from YouTube. Nothing is requested from YouTube, and no cookie is set, until you press play. Read the transcript

The challenge

Advice and wealth firms have grown into their technology a piece at a time: a planning platform here, a client portal there, Microsoft 365 for everything in between, and more of it reached from home than ever before. That is normal, and it works. What tends to lag behind is the evidence. When a client asks how their documents are protected, when a payment request arrives that looks exactly like a client's email, or when the FCA's new incident reporting rules arrive in March 2027, the firm needs answers that hold up. The regulator is clear that you cannot contract out your obligations, so the questions land with you even when the IT does not.

What we would do

Start with email and identity. Payment-diversion attempts and account takeover are the risks most likely to reach your clients, and the controls that stop them are also the evidence the FCA, your clients and your insurer will ask about first. Then write the incident runbook, before the March 2027 reporting rules make the timing tighter.

  • If you already hold Cyber Essentials, enforce MFA everywhere and test your restores, the next useful step is the incident runbook rather than more controls.
  • If your network or platform provider runs most of your systems, focus on oversight: what they report to you, and what you can show the FCA.

When we are not the answer: If you want someone to take on your regulatory responsibility, no IT provider can, and one that offers to is overselling. We make the technology dependable and the evidence easy to produce. The judgement calls stay with you and your compliance adviser.

What we do for financial advice & wealth

Microsoft 365 security posture reviewed and hardened in stages: MFA without exceptions, Conditional Access and device compliance
Email security and impersonation protection against phishing and payment-diversion attempts, with SPF, DKIM and DMARC set correctly
Client portal access secured through Microsoft 365 identity where the portal supports it, and guest access reviewed
Backup of Microsoft 365 and key systems, with restores tested and recovery times written down
Records kept retrievable for the periods your obligations set, held separately from day-to-day mailboxes
An incident runbook that covers your FCA, ICO and client obligations, written before you need it
Supplier oversight evidence: what we do, how we report it, and what you can show the FCA
Help preparing for Cyber Essentials, which an independent Certification Body then assesses
Managed IT support from a UK team, with 24/7 monitoring available where you need it

If a client, network or insurer has asked for a certificate, our Cyber Essentials preparation covers the gap check, the fixes and the evidence before the independent assessment.

To see where your tenant stands on MFA, Conditional Access, sharing and admin accounts, start with a Microsoft 365 security posture review.

Can an advice firm outsource IT and still meet FCA expectations?

Yes, as long as the firm still oversees what is done in its name. SYSC 3.2.4G is plain about it: a firm cannot contract out its regulatory obligations, and under Principle 3 it should take reasonable care to supervise the discharge of outsourced functions.

What supervising an IT provider looks like in practice, and where SYSC 8 fits

For an IT provider that means you should be able to see what was done, not only be told. Regular reports on patching, backup results and security alerts, a named contact, a written split of who owns what, and the right to ask questions all turn trust into oversight.

SYSC 8 sets the outsourcing rules for common platform firms and says a firm outsourcing critical or important operational functions remains fully responsible for its obligations. Most small advice firms are not common platform firms, and the FCA says other firms should take account of those rules as if they were guidance. The practical answer is the same either way: choose a provider that makes oversight easy.

Do the FCA's operational resilience rules apply to a small advice firm?

Usually not. The formal operational resilience rules in SYSC 15A apply to enhanced scope SM&CR firms, banks, designated investment firms, building societies, Solvency II firms and a few other types. A typical small IFA or wealth manager is a core SM&CR firm and none of those, so SYSC 15A does not apply to it. Your own firm type is yours to confirm.

That does not make resilience optional. Principle 3 expects every firm to organise and control its affairs responsibly and effectively, with adequate risk management systems. In plain terms: clients should still be able to reach you, and you should still be able to get your systems and records back.

What changes for incident reporting in March 2027?

From 18 March 2027, every FCA-authorised firm must report serious operational incidents under the rules in policy statement PS26/2, with the first report expected within 24 hours of realising an incident crosses the FCA's thresholds. The FCA kept all firms in scope, small ones included.

Until then, Principle 11 already expects you to tell the FCA about anything it would reasonably expect notice of. The FCA's own indicators of a reportable incident include a material disruption to the financial services you provide, unauthorised access to your information systems, a significant loss of data, and losing the availability or control of your IT systems.

How the new rules work, and why the runbook matters more than the form

The bar is deliberately high: the FCA describes the new process as intended for serious incidents, and lower-impact events continue through normal supervisory channels under Principle 11. Reports go through the FCA's Connect platform. The separate material third party reporting rules apply to a narrower list of larger firm types, which a typical small advice firm is not on.

Twenty-four hours goes quickly when systems are down. The firms that meet it will be the ones that decided in advance who judges whether an incident crosses the threshold, who has access to Connect, and where the facts will come from. We help you write that runbook and make sure the IT side can produce the facts fast: what happened, what was affected and when.

When does a data breach have to go to the ICO?

If a personal data breach is likely to put people's rights and freedoms at risk, the ICO expects to hear without undue delay and within 72 hours. The clock runs from when you discovered the breach, not when it happened. If the risk to people is high, you must also tell them without undue delay.

An advice firm can face both clocks at once: 72 hours for the ICO and, from March 2027, 24 hours for the FCA's initial report on a serious incident. That is why both belong in one runbook, with the decisions written down before anyone needs them.

How long do advice records need to be kept?

Longer than most mailboxes are set up for. For non-MiFID advice under COBS 9, suitability records are kept indefinitely for pension transfers, pension conversions, pension opt-outs and FSAVCs.

For life policies, personal and stakeholder pensions and defined contribution occupational pension benefits the period is five years, and in any other case it is three years.

Why a mailbox is not a records system, and where call recording fits

SYSC 3.2.20R also expects firms to make and retain adequate records of matters covered by the regulatory system, with guidance on adequacy, access, retention periods and security. Much of an advice relationship lives in email and documents, so the IT question is whether you can produce a complete, unaltered record years later, after staff have left and systems have changed. Retention policies, an independent archive and tested restores are what make that a search rather than a hunt.

Whether call and electronic communications recording under SYSC 10A applies depends on your permissions and the instruments you advise on, so check that with your compliance adviser rather than assuming. Where it does apply, the records are kept for five years, and up to seven where the FCA asks. MiFID business sits under different suitability rules, so confirm which regime covers your advice.

How do you protect clients from email impersonation and payment diversion?

By stopping account takeover, catching lookalike senders, and never changing payment details on the strength of an email. Phishing is the most common way in: the government's Cyber Security Breaches Survey 2025 found that 85% of businesses that identified a breach or attack had experienced phishing, and 43% of all businesses reported a breach or attack in the previous 12 months.

The technical controls and the payment rule that work together

The technical side is MFA on every account, Conditional Access that challenges sign-ins that do not fit the normal pattern, alerts on new inbox rules that hide or forward messages, and impersonation protection that flags lookalike domains and display names. SPF, DKIM and DMARC set correctly make your own domain much harder to spoof to clients.

The process side matters as much. Bank details are never changed on the strength of an email alone, and any change is confirmed by phone to a number already on file. Tell clients you work that way, so a request that breaks the pattern stands out to them too.

How should client portals and Microsoft 365 be secured?

As one estate, because clients see them as one firm. Client documents often move between Microsoft 365, a planning platform and a client portal, so the weakest of the three sets the standard.

A Microsoft 365 security posture review shows where your tenant stands and fixes the gaps in stages, so nothing changes for clients without warning.

The five checks that matter most across Microsoft 365 and a client portal

MFA for every staff account, with no standing exceptions.

Conditional Access and device compliance, so client data is only reached from managed devices.

Single sign-on to the portal and planning platform through Microsoft 365 where they support it, so leavers lose access everywhere at once.

Guest and external sharing reviewed, with links that expire.

Admin accounts separated from everyday accounts.

Where does the Consumer Duty come in?

Principle 12 asks firms to act to deliver good outcomes for retail customers, and the Consumer Duty has applied since 31 July 2023 for open products and 31 July 2024 for closed ones. Clients expect to reach you, get answers and see their documents, including on a bad day.

IT will not deliver the Duty for you, but it can quietly undermine it. Tested backups, a recovery plan with realistic times, and a way to keep talking to clients during an outage all support the service your clients rely on.

Does Cyber Essentials help an advice firm?

It gives you a recognised baseline that answers many of the security questions clients, networks and insurers ask, in a form they already understand. The FCA's cyber resilience guidance asks whether your firm has a board-approved cyber security strategy; a certified baseline is a sensible part of the answer.

Systech holds Cyber Essentials certification itself, and we help firms prepare: finding what would fail today, fixing the gaps and gathering the evidence. A licensed independent Certification Body then assesses it and awards the certificate. We do not certify anyone.

Questions we hear a lot

Do you understand FCA requirements for financial advice firms?

We work to the FCA Handbook as it applies to IT: SYSC on outsourcing, systems and records, the Principles for Businesses, and the incident reporting rules coming in March 2027. We are not compliance consultants and will not give regulatory advice, but we make sure the technology side produces the evidence your compliance adviser and the FCA expect to see.

Can we outsource our IT without losing control?

Yes. The FCA expects you to supervise what an IT provider does, not to do it yourself. We give you regular reporting on patching, backups and security alerts, a written split of responsibilities, and a named contact, so oversight is something you can show rather than assert.

Does SYSC 15A operational resilience apply to us?

Probably not, if you are a typical small advice or wealth firm. SYSC 15A applies to enhanced scope SM&CR firms, banks, designated investment firms, building societies, Solvency II firms and a few others. Confirm your own firm type. Principle 3 still expects responsible systems and controls, and the 2027 incident reporting rules apply to all FCA-authorised firms.

What should we do in the first hour of a suspected email compromise?

Revoke the account's sessions as well as resetting its password, check for inbox rules and forwarding the user did not create, and warn clients not to act on payment instructions from that mailbox, using a different channel. Then work through your notification decisions: whether the ICO needs to hear within 72 hours, and whether the FCA needs to be told. A runbook written in advance makes this a checklist rather than a scramble.

Are you a Cyber Essentials Certification Body?

No. Systech holds Cyber Essentials certification itself, and we help firms prepare: we find what would fail, fix the gaps and gather the evidence. A licensed independent Certification Body assesses your submission and awards the certificate.

Reading for financial advice & wealth

Comparison guides

Free resources

Relevant client work

Our case studies are anonymised at our clients' request, so they name no sector. These are matched to the problems above rather than to the industry.

IT support for financial advice & wealth is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in Leeds, York, Harrogate, Hull, Sheffield and Barnsley and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.

Ready to talk about your financial advice & wealth IT?

A short call about how your IT works today and what your sector asks of it. We will tell you plainly where we would start.