Skip to content

For an investment firm, IT problems are rarely just IT problems.

An outage can prevent people from serving clients. A compromised account can expose sensitive financial information. Poor governance can create questions from clients, insurers, auditors and regulators. A failure at a critical technology supplier can quickly become your problem too.

A best practice IT environment therefore needs to achieve three things: keep the firm operating, protect its data and reputation, and provide evidence that technology risks are being properly governed.

At Pro Drive IT, we believe this requires a defined standard against which your IT can be regularly audited and improved.

Here are 15 areas we believe an FCA regulated investment firm should consider when assessing whether its IT meets that standard.

  1. 1. Is there clear accountability for technology?

Someone needs to own IT at a senior level.

That does not mean a partner or director needs to become a technology expert. It means the firm should have clear accountability for technology risk, investment, suppliers and improvement.

Your IT provider should be able to give the leadership team a clear view of performance, risks and priorities, rather than overwhelming them with technical information.

  1. 2. Is access to systems properly controlled?

Investment firms hold highly sensitive financial and personal information.

Multi Factor Authentication should be standard, but good identity security goes considerably further.

Access should be provided according to business need. Privileged administrator accounts should receive additional protection, and access should be removed promptly when somebody leaves the firm or changes role.

  1. 3. Is Microsoft 365 configured to a defined security standard?

Simply using Microsoft 365 does not mean it is secure.

Configuration should follow an agreed security baseline covering areas such as identity, email, devices, data sharing and administrative access.

Crucially, that standard needs to evolve as Microsoft’s technology and security recommendations change.

  1. 4. Are laptops and other devices managed to a consistent standard?

Every device accessing company information creates potential risk.

Business devices should be centrally managed, encrypted, patched, monitored and configured consistently.

This also applies to remote and hybrid working. People should be able to work securely regardless of whether they are in the office, at home or travelling.

  1. 5. Is email protected against modern financial fraud?

Email remains one of the most common routes into an organisation.

Investment firms need protection against phishing, malicious links, impersonation and email spoofing. This is particularly important where attackers may attempt to impersonate senior employees, clients or suppliers to initiate payments, obtain information or gain access to systems.

Effective protection should combine appropriate technology with ongoing staff awareness.

  1. 6. Is sensitive client information properly protected?

Knowing where sensitive information resides and controlling what happens to it is becoming increasingly important.

Controls such as data classification, sensitivity labels and Data Loss Prevention can help prevent confidential information from being shared with the wrong recipient or leaving the organisation unintentionally.

This becomes even more important as firms adopt AI.

  1. 7. Is the environment continuously monitored for compromise?

Waiting for somebody to notice suspicious behaviour is not an effective security strategy.

Microsoft 365, workstations, servers and other critical infrastructure should be monitored for indicators of compromise, with a defined process for responding when suspicious activity is identified.

  1. 8. Are vulnerabilities actively identified and managed?

Technology changes continuously and new vulnerabilities are discovered every day.

Firms need a repeatable process for identifying outdated software, insecure configurations and vulnerabilities. These should be prioritised according to risk, with clear responsibility for ensuring remediation takes place.

  1. 9. Can the firm recover from a serious incident?

Backups are important, but having a backup is not the same as being resilient.

Firms should understand which systems are critical, how quickly they need to be recovered and whether recovery arrangements actually work.

That requires regular testing rather than assumption.

  1. 10. Are your technology suppliers part of your risk management?

An investment firm’s security extends beyond its own organisation.

Cloud platforms, financial applications, data providers and IT support companies may all have access to important systems or information.

Critical suppliers should therefore be subject to appropriate due diligence and ongoing review.

This is particularly important for your IT provider, which may have highly privileged access across almost your entire technology environment.

  1. 11. Can you evidence that IT is being properly governed?

Being secure and being able to demonstrate that you are secure are increasingly different requirements.

Leadership should have access to meaningful information about technology risk, security, resilience and improvement.

That evidence may also be important when responding to questions from clients, insurers, auditors and other stakeholders.

Good governance means being able to demonstrate what controls are in place, why they are appropriate and how you know they are working.

  1. 12. Are staff regularly trained to recognise cyber threats?

Technology cannot eliminate every threat.

Employees should receive regular cyber security awareness training and practical exercises, such as phishing simulations, so they understand how attacks work and what to do when something looks suspicious.

Training should not be treated as an annual compliance exercise. Awareness needs to be reinforced throughout the year.

  1. 13. Is AI being adopted with appropriate governance?

Investment firms are understandably interested in the productivity opportunities presented by AI.

However, adoption needs appropriate controls.

Firms should understand which AI tools employees are using, what information can be entered into them and how confidential data is protected.

There should also be clear accountability for the use of AI and appropriate checks over any AI generated work that could affect clients or business decisions.

The objective should not be to prevent AI adoption. It should be to enable people to take advantage of AI while maintaining appropriate control over sensitive information, risk and the quality of their work.

  1. 14. Is IT regularly benchmarked rather than simply maintained?

One of the biggest problems with IT is that it naturally drifts over time.

New users are added. Applications change. Microsoft releases new capabilities. Cyber threats evolve and regulatory expectations develop.

That is why a one off IT audit is not enough.

Your environment should be regularly benchmarked against a defined standard so that gaps can be identified and corrected before they become significant problems.

  1. 15. Is your IT getting better every quarter?

This may be the most important question.

Good IT should not simply remain operational. It should continuously improve.

At Pro Drive IT, our approach is to audit, roadmap, align and enforce.

We first establish where the environment sits against our standards. We identify gaps and risks, align the technology with those standards and then continue monitoring and auditing as technology, threats and expectations change.

Alongside this, strategic technology planning should look to the future. How can new technology improve productivity? Where can AI provide genuine value? How will the business grow? What changes in the investment sector should leadership be preparing for?

The result should be technology that gets progressively better rather than gradually falling behind.

How does your IT compare?

For an FCA regulated investment firm, dependable technology is fundamental to operating the business.

But leadership should not have to rely on an IT provider simply telling them that everything is fine.

You should have a defined standard, evidence showing how your environment compares with it, visibility of outstanding risks and a clear process for continual improvement.

That is the principle behind Pro Drive 360.

We assess more than 200 operational, security and productivity factors to provide regulated firms with a measurable picture of their IT environment and identify where improvement is required.

Because when your reputation depends on technology, “it seems to be working” is not a sufficient standard.

To learn more about how Pro Drive 360 enforces the standards that FCA regulated investments firms need to meet, book an IT review meeting with us now.

Still have questions?

Speak to our team