Advice firms hold concentrated personal and financial data, often with a small team and no dedicated IT function. The practical security position varies widely between firms of similar size.
This matters because the common failures — reused passwords, unmanaged devices, email interception during a transaction — are well understood and largely preventable, yet still cause real harm.
Questions for discussion:
- What security measures has your firm put in place that were worth the effort?
- How do you verify payment or bank detail changes with clients?
- Where does security guidance aimed at large organisations fail small firms?
Do not post details of any live incident, and avoid describing specific weaknesses in your own systems.
This thread is an editorial prompt from Adviser Forum. Please answer from your own experience rather than on behalf of the profession, avoid presenting any response as regulatory or legal guidance, and strip out any detail that could identify a client, a case or an individual member of staff.

