Kyle Wiggs / Writing / Technology & AI

Technology & AI

The security questions worth asking in a small firm

You hold exactly the data an attacker wants, with none of the staff a large firm has. A short list beats an unread policy.

The risk is real and specific

Advisory firms hold identity documents, account numbers, and enough personal detail to impersonate a client convincingly. Small teams, no dedicated security function, and high-value data is an attractive combination to someone else.

How do you verify a money-movement request

The single most important control. A request arriving by email, apparently from a client, asking for funds to a new destination is the most common attack against firms of this size.

A verbal callback to a known number, every time, without exception for clients you know well. The exceptions are the entire vulnerability.

Who has access to what

Most small firms have accumulated access nobody has reviewed. Former staff, former vendors, shared logins.

Review it annually and on every departure, on the day.

Is multi-factor authentication on everything

Email first, because email is the route to resetting everything else. Then the custodian, the CRM, and document storage.

Email is not one of your systems. It is the key to all of them.

What happens if a laptop is lost

Full-disk encryption, remote wipe, and knowing what was on it. This is a ten-minute configuration and it is frequently absent.

Who do you call

Decide before you need it. An incident response contact, your insurer, your compliance consultant, and counsel. The first hour matters and it is not the hour to be searching.

Vendor questions

Where data is stored, who can access it, whether subprocessors are used, and what their breach notification obligation to you is. In the contract, not the sales deck.

The unglamorous truth

Almost every incident at a firm this size traces to email compromise or an unverified request. Get those two right before anything else.