"Financial services" is not one industry, and treating it as one is why most security advice aimed at it is useless.
An RIA answers to an examiner and a custodian. A CPA firm answers to the IRS and to a filing calendar that concentrates its entire year of risk into about ten weeks. An insurance agency answers to the carriers it represents, and holds client data it never actually asked for.
Same controls, mostly. Completely different reasons, different documents, and different moments when someone asks you to produce them.
So rather than write another piece about how financial firms should take security seriously, here is what each of the three is actually asked for, and what it means for what you should be spending.
Every firm holding client financial data is being evaluated by someone. Not hypothetically, and not by an attacker. By a party with paperwork and a schedule.
The pattern worth noticing: all of them accept documentation, and none of them accept intent. You cannot answer any of these by describing how carefully your firm operates. Every one of them ends in a request for a specific artifact.
That is the gap we find most often. Not missing protection. Missing proof.
Your obligation is the most predictable of the three, which is genuinely an advantage. Exams happen on a cycle, and the questions do not change much year to year.
The document that gets requested first is a written information security program. Not a folder of invoices from your IT provider. A document stating what you protect, how, who is responsible, and what happens when something goes wrong.
The second thing, and the one firms are least prepared for, is vendor due diligence. You are accountable for the security of every firm you hand client data to: your technology provider, your CRM, your portfolio management software, your document storage, your email. Most firms have never documented a single review of any of them.
Your custodian is a separate check, and a more immediate one. Schwab, Fidelity, and Pershing all have security requirements attached to advisor access, and unlike an examiner, a custodian can restrict access this week.
Your obligation is a written security plan, and it is not optional. The IRS requires one to maintain a PTIN, which means it applies to firms of every size, including sole practitioners.
The distinctive thing about your risk is not what you hold. It is when.
From late January through mid-April, and again in the weeks before September and October deadlines, your firm holds more sensitive data in active circulation than at any other point in the year, and it is the moment you can least afford to lose access to any of it. A three-day outage in June is an inconvenience. A three-day outage on April 10 is a different conversation with every client you have.
Which is why the single most valuable thing a CPA firm can do is unglamorous: test a full restore before filing season, not after. Confirm it works, write down the date, and keep the record. Most firms have backups. Very few have ever restored from them, and nobody wants to discover the difference during the busiest fortnight of the year.
Your obligations arrive from a direction the other two do not deal with: the carriers you represent. Appointments come with data handling requirements attached, and those requirements are contractual.
You also hold a category of data you did not choose to collect. Quote submissions come in with dates of birth, driver license numbers, medical history depending on the line, and property details. A lot of it belongs to people who never became clients, and it is still sitting in an inbox two years later.
That makes retention and disposal the question worth asking first. Not what are we protecting, but what are we still holding that we no longer need? Data you have deleted cannot be exposed, and no product on the market protects it more cheaply than that.
Two patterns, consistently.
Governance platforms bought without a governance function. Enterprise compliance software is built for organizations with a compliance officer whose job is to feed it. A twelve-person RIA that buys one ends up with an expensive dashboard nobody updates, which is genuinely worse than a maintained spreadsheet because it creates the appearance of a control that is not actually being exercised.
Monitoring without response. Around-the-clock alerting produces alerts. Alerts create value only when someone is positioned to act on them. If nobody at your firm is on call at 2 a.m. and there is no documented escalation path, you have bought a notification.
Both products are real and both eventually make sense. At most firm sizes in this market, neither is the next dollar you should spend.
Verification procedure on money movement.
The realistic loss event at a financial firm is not a sophisticated intrusion. It is a client instruction that was not actually from the client. An email about a wire, arriving at a plausible moment, from an address one character off from a real one, or from a genuine client mailbox that someone else is reading.
What defeats it is procedural and nearly free: a verbal callback to a number you already had on file before the request arrived, for every change to payment instructions, with no exceptions for good clients or urgent timelines. Write it down, make it a rule, and apply it when it is inconvenient. That is the entire control.
Alongside it: email authentication so your domain cannot be convincingly spoofed, and filtering that catches lookalike domains. Neither is expensive. Both get skipped in favor of products that demo better.
None of this is an argument to buy everything.
We sort security into three tiers, and where a firm belongs is set by its obligations rather than its budget. Secured is the floor for any business: firewall, multi-factor authentication, endpoint protection, offsite backup, email security. Insured adds what carriers now require: training with completion records, password management, managed detection, advanced email protection. Compliant adds centralized logging, formal governance, and documentation, and it makes sense when somebody outside your firm can compel you to produce proof on their timeline.
Most financial firms we look at sit at Insured and belong there, while paying for pieces of Compliant they cannot use.
The full framework is in our security spending guide, Overpaid and Underprotected, including what actually moves a firm up a tier.
Here is the awkward part underneath all of it.
Most firms get one bundled line on the invoice. Something like "security and compliance." The number moves occasionally and nobody can explain why, because nobody can see inside it.
That means you cannot tell whether you are paying for the tier you are actually in, whether two products are doing the same job because one was added years ago and never removed, or whether the user count still matches your headcount after turnover.
We itemize every component with a monthly report behind it. Not generosity. A client who can see what they are buying makes better decisions.
If your provider cannot produce a line-item breakdown of your security spend within a day, that is the finding. You do not need to understand endpoint detection to know that is a problem.
Yes. SEC and state examiners expect registered advisors to maintain written policies and procedures covering information security, and the written program is typically the first document requested in an exam. A collection of invoices from an IT provider does not satisfy it. The document should state what data you protect, what safeguards are in place, who is responsible, and what happens during an incident.
Yes. The IRS requires tax professionals to maintain a written information security plan as a condition of holding a PTIN, which applies to firms of every size including sole practitioners. The requirement is not scaled away for small firms, though the plan itself should be proportionate to the size and complexity of the practice.
Custodian requirements vary but consistently include multi-factor authentication on advisor access, controls around how client instructions are verified before funds move, and increasingly, attestations about the firm's broader security posture. Custodian requirements matter more urgently than examiner requirements for a practical reason: a custodian can restrict access far faster than a regulator can act.
The most effective control is procedural, not technical: a verbal callback to a phone number already on file, made before executing any change to payment instructions, applied without exception. Supporting technical controls include email authentication so the firm's domain cannot be spoofed and filtering that catches lookalike domains. This combination costs very little and addresses the way losses actually occur.
Longer than most agencies realize they are keeping it, and shorter than they actually do. State requirements and carrier agreements set the floor, and agencies should document a retention and disposal policy that meets both. The practical point is that quote submissions contain sensitive personal data from people who never became clients, and data that has been properly disposed of cannot be exposed.
Ninety-second version: take the three-question self-check. No email required to see your result.
Longer version: send us your cyber policy or your most recent renewal application, whichever you have handy. A client or custodian security questionnaire works too. We will tell you which of those controls your firm can actually prove today, which ones you cannot, and which tier you are genuinely operating at. Send your IT invoice along with it if you want us to check whether your spend matches your tier, though that part is optional.
No charge. No meeting required. Five business days.
Four Winds IT is a technology company serving 300+ businesses across Southwest Florida, headquartered right here in Sarasota. Call us at (941) 315-2380 and an engineer picks up.