You hold a complete identity
A financial services firm holds, for each client, identity documents, income records, bank and account details, asset positions and often family information. That is a more complete identity package than a bank branch holds, concentrated in a practice that may have eight staff.
The attractiveness of that to an attacker is not proportional to your size, which is the uncomfortable arithmetic behind why small advice practices get hit.
Evidence is the requirement now
The shift worth understanding is from assurance to evidence.
Ten years ago, telling a licensee or an insurer that you took security seriously and used a reputable IT provider was broadly sufficient. It is not now. Licensee audits, professional indemnity applications and ASIC’s expectations around adequate risk management systems all increasingly ask for documentation: what controls exist, when they were reviewed, and what the review found.
That changes what an IT provider needs to give you. Doing the work is necessary and no longer sufficient — you need to be able to produce a record of it. An Essential Eight assessment is the most common proportionate way to generate that evidence for a small practice.
Payment redirection, and the process that stops it
Clients move significant sums on your instruction. That makes the conversation in which account details are exchanged the highest-value target in your business.
The technical controls matter — MFA, inbox rule alerting, correct email authentication — but the control that actually works is procedural: verify changed payment details by voice, on a number you already hold, never one supplied in the message.
Tell clients this is your process at the start of the relationship. Then a request to bypass it becomes a signal rather than an inconvenience.
Retrievability, not just retention
Long retention is straightforward. Being able to answer “who accessed this client’s file in March, and what did the advice document say before it was amended” is not, and it is what a licensee audit actually asks.
Access logging, version history on advice documents, and email retention configured deliberately are what make that answerable. All three are configuration decisions taken in advance — none can be reconstructed after the fact, which is why they are worth setting up before anyone asks.
Your licensee is probably stricter than the law
For most advice practices, the binding constraint is not legislation. It is the licensee’s own security and technology policy, which is frequently more prescriptive and changes more often.
It is worth giving us a copy. Building to a standard you are contractually held to is considerably more useful than building to a generic baseline and discovering the gap during an audit.