Kyle Wiggs / Writing / Technology & AI
Technology & AI
You hold exactly the data an attacker wants, with none of the staff a large firm has. A short list beats an unread policy.
Advisory firms hold identity documents, account numbers, and enough personal detail to impersonate a client convincingly. Small teams, no dedicated security function, and high-value data is an attractive combination to someone else.
The single most important control. A request arriving by email, apparently from a client, asking for funds to a new destination is the most common attack against firms of this size.
A verbal callback to a known number, every time, without exception for clients you know well. The exceptions are the entire vulnerability.
Most small firms have accumulated access nobody has reviewed. Former staff, former vendors, shared logins.
Review it annually and on every departure, on the day.
Email first, because email is the route to resetting everything else. Then the custodian, the CRM, and document storage.
Email is not one of your systems. It is the key to all of them.
Full-disk encryption, remote wipe, and knowing what was on it. This is a ten-minute configuration and it is frequently absent.
Decide before you need it. An incident response contact, your insurer, your compliance consultant, and counsel. The first hour matters and it is not the hour to be searching.
Where data is stored, who can access it, whether subprocessors are used, and what their breach notification obligation to you is. In the contract, not the sales deck.
Almost every incident at a firm this size traces to email compromise or an unverified request. Get those two right before anything else.
Read next
The data you do not own →