Using digital tools is something nearly every advice firm now does, with the profession well into the digital age.
However, while digitalisation does create efficiencies within a practice, it also opens you up to an entirely new set of risks, including cyber-crime, which could jeopardise clients’ data.
According to The Cyber Collective and VA Platinum (VAP), smaller advice practices are particularly attractive targets for cyber criminals.
“Just having one client means that you have so much information on them,” Fraser Jack, founder of The Cyber Collective, told ifa.
“All of their investment information, their banking information, their tax information, their estate planning information, their beneficiaries, their company structures [are all available to cyber criminals].”
For founder of Fradley Advice, Nathan Fradley, much of the industry, while very aware of cyber security, are still engaging in practices that might compromise client data.
“You’ve got these portals and things set up for clients, you’ve got everything secure, no email ever, but then the way you’re dealing with product providers is you’ve got to just email this information across,” he told The ifa Show Podcast.
“We’re trying at the same time to have two-factor authenticated upload directly into our system portal that we’re extremely strict on, and then we request information from an accountant and they just send us everything in an email.”
On top of this, he argued that AML/CTF obligations are clashing with privacy expectations.
“The practical reality is if you’re going to require that ID on a regular basis for this client, practically, you’re going to keep it on file. And then when you don’t need it anymore, you get rid of it. But we’re kind of in between a rock and a hard place with no clear guidance.”
For Fradley, one simple step to protect client data is only collecting what is necessary, minimising the risk to clients as much as possible.
He added that extra steps in securing data may add more friction to process, but in this day and age, it is an essential sacrifice.
“We talk about the effort we go to protect their data in the first place. Like, do not email me anything. We use this portal, upload it to the portal. Yes, this is more friction, however it’s really important and we really value information security.”
Fradley also addressed concerns around data sovereignty when employing artificial intelligence, something he has observed many clients are concerned about.
“As soon as you use the AI tool, it has to leave the country. As soon as the system is operating, it leaves Australia, and therefore the data leaves.”
“So, unless my tools are de-identifying it before it sends it away, which mine certainly wouldn’t be, we’ve got a problem. That’s the same for all these other tools that just use AI.”
He emphasised that these concerns about data security are holding back some advisers when it comes to AI integration.
“There’s this real push to use these tools, and we forget where data is, where data is being stored. I feel like that might save us one day in the amount of client data that ends up in unsecured plagiarism machines. We’ll be sitting there going, ‘That’s lucky that my client data isn’t over somewhere else in a way that I can’t control it’.”




