X
  • About
  • Advertise
  • Contact
Get the latest news! Subscribe to the ifa bulletin
  • News
  • Opinion
  • Podcast
  • Risk
  • Events
  • Video
  • Promoted Content
  • Webcasts
No Results
View All Results
  • News
  • Opinion
  • Podcast
  • Risk
  • Events
  • Video
  • Promoted Content
  • Webcasts
No Results
View All Results
No Results
View All Results
Home Opinion

Five simple ways to improve cyber security in your advice practice

A cyber security breach is potentially catastrophic but advice practices can take some simple steps to bolster their defences.

by Fraser Hamilton
June 20, 2022
in Opinion
Reading Time: 4 mins read
Share on FacebookShare on Twitter

Cyber attacks are on the rise as the world becomes increasingly digital. And advice practices – particularly small businesses that deal with large sums of client money – are at risk of being targeted.

No one is immune. One major dealer group was recently ordered to pay $750,000 by the Federal Court over cyber security breaches that allowed criminals to gain access to confidential and sensitive client information over several years.

X

The landmark ASIC case serves as a warning to other advice practices to strengthen their cyber security defences no matter how busy they are in helping clients or running their business.

“It is not possible to reduce cyber security risk to zero, but it is possible to materially reduce cyber security risk through adequate cyber security documentation and controls to an acceptable level,” Justice Rofe said in the judgment.

Fortunately, there are simple steps that advice practices they can take to ensure they’re protecting their business and client assets from most cyber threats.

Use a password manager

Passwords are a common point of weakness. Simple passwords are easy for hackers to guess (“123456” remains the most used password in the world).

Another common point of weakness is re-using the same password across multiple sites. If one site has a data breach which exposes passwords, it leaves users vulnerable across many sites where they have used the same email address and password combination.

The solution is to use a password manager, such as Dashlane, 1Password, and LastPass. They require remembering just one strong master password – every other password can be generated randomly and stored within the password manager.

Use two-factor authentication

Two-factor authentication (2FA) provides a second line of defence beyond passwords. It requires confirmation on top of a password via a second channel, such as text message or email.

While it can be slightly inconvenient compared to using a password alone, it provides a significant security upgrade. Many people are now accustomed to 2FA, given that banking apps commonly require a second confirmation via text message when transferring money.

If your software supports 2FA, switch it on.

Use client portals for sensitive information rather than email

Email is a popular fallback to send sensitive data but it remains inherently insecure.

It leaves both advice practices and clients exposed to phishing attacks, where cyber criminals send fraudulent communications that appear to come from a reputable source. They can harvest personal data, make false requests, or change bank account details contained in emails.

Even if cyber criminals aren’t at play, it’s all too easy to send sensitive information to the wrong email address, which can undermine client trust.

The 2022 Future Ready IX advice report showed that 22 per cent of advisers say they don’t have adequate security and file encryption for transmitting sensitive data.

Good advice software should include a secure client portal to communicate or send information. Clients can set their own password (or the password can be delivered over a different communication channel, such as in person or by text message) to use the portal, which is significantly more secure than sharing client information via email.

Use cloud-based storage and software rather than local storage

A secure cloud-based workflow is more efficient and secure than storing information locally or on paper. It is easier to provide an audit trail, search for information, and ensure ongoing business continuity. It is cost-effective and flexible, with major cloud-based vendors investing huge amounts of money to secure their systems.

Software applications that run in the cloud are seamlessly updated with new features and security patches while desktop software often requires manual checks.

When using a cloud-based service, it is pertinent to check where the data will be stored. Storing data in Australian-based data centres not only ensures that it falls under Australian legislative protections but also that these protections can be enforced in case of a breach.

While most practices are using the cloud in some form, practices should also review their back-up strategy. The Future Ready report found that while 93 per cent of advisers now back up their critical data daily or in real time, one in three (32 per cent) said they haven’t tested or restored from their backups in at least six months.

Review cyber security of suppliers and software providers

The cyber security of any advice practice is only as secure as its weakest link. A breach at a small supplier could give cyber criminals a way into your sensitive client data or advice practice.

Ensure that suppliers have strong cyber security controls in place and be wary of free software – if you are not paying for the product, you are the product.

Most large companies invest heavily in security and technology and have the resources to adopt international standards such as the ISO/IEC 27001 on information security management. Compliance with these standards is independently assessed and provides a heightened level of confidence.

Fraser Hamilton, chief technology officer, Midwinter

Related Posts

Image: Bombora Advice

The age of underinsurance and the consumer gap we cannot ignore

by Niall McConville
November 17, 2025
1

From an industry perspective, it’s a consumer gap that threatens our long-term sustainability if left unchecked. Rising premiums are compounding...

Why we must be optimistic about the barriers to advice

by Neil Rogan
November 10, 2025
0

Financial advice in Australia is often perceived as something people hesitate to engage with, however there is cause for greater...

The rise of model portfolios: Global trends and developments

by Kathleen Gallagher and Sinead Schaffer
November 3, 2025
0

Model portfolios have shifted from niche to mainstream, both in the US and Australia, marking a major change in the...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL
Promoted Content

Private Credit in Transition: Governance, Growth, and the Road Ahead

Private credit is reshaping commercial real estate finance. Success now depends on collaboration, discipline, and strong governance across the market.

by Zagga
October 29, 2025
Promoted Content

Boring can be brilliant: why steady investing builds lasting wealth

Excitement sells stories, not stability. For long-term wealth, consistency and compounding matter most — proving that sometimes boring is the...

by Zagga
September 30, 2025
Promoted Content

Helping clients build wealth? Boring often works best.

Excitement drives headlines, but steady returns build wealth. Real estate private credit delivers predictable performance, even through volatility.

by Zagga
September 26, 2025
Promoted Content

Navigating Cardano Staking Rewards and Investment Risks for Australian Investors

Australian investors increasingly view Cardano (ADA) as a compelling cryptocurrency investment opportunity, particularly through staking mechanisms that generate passive income....

by Underfive
September 4, 2025

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Poll

This poll has closed

Do you have clients that would be impacted by the proposed Division 296 $3 million super tax?
Vote
www.ifa.com.au is a digital platform that offers daily online news, analysis, reports, and business strategy content that is specifically designed to address the issues and industry developments that are most relevant to the evolving financial planning industry in Australia. The platform is dedicated to serving advisers and is created with their needs and interests as the primary focus.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About IFA

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • News
  • Risk
  • Opinion
  • Podcast
  • Promoted Content
  • Video
  • Profiles
  • Events

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
  • Opinion
  • Podcast
  • Risk
  • Events
  • Video
  • Promoted Content
  • Webcasts
  • About
  • Advertise
  • Contact Us

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited