Skip to content

IT and cybersecurity for financial services firms that have to prove it.

An annexure from your licensee, a questionnaire from your insurer, a third-party review from your platform. Advisers, authorised representatives, retirement planners and financial brokers all get the same asks. So do self-managed super fund (SMSF) administrators, wealth managers, boutique investment firms, accounting firms with financial services work, and mid-tier dealer groups. If you hold client money, financial records or tax data, you get the same list. Big banks, major super funds and general insurers need a different delivery model, and we will say so upfront.

What's actually different

Financial services IT in 2026 is mostly evidence and oversight.

You almost certainly have the controls already. Multi-factor authentication (MFA), endpoint detection and response (EDR), backups, allowlisting, logging, offboarding. None of that is exotic. The hard part is evidence. Your licensee, your broker and your platform all want proof that a control was on and stayed on. So does the Australian Securities and Investments Commission (ASIC). Most firms we assess have the controls in name but can't produce the evidence when someone digs in.

Then there is everyone else who touches your data. Platforms, advice software, practice management, client records, SMSF administration, tax and modelling tools. Every one of them adds another login and another set of people to trust. CPS 234, ASIC guidance, your licensee's annexure and the broker's questionnaire all want that oversight documented now. Someone has to read the vendor's assurance report, track their breach history and keep the access register current. When a vendor's security slips, someone has to notice. That is a real job, and it does not fit in the gaps of someone else's week.

If you are an authorised representative, your dealer group has already reacted to the Fortnum proceedings. ASIC's position is that licensees must set and enforce minimum cyber controls on their representatives. Failing to do so, it says, breaches the licence obligations. Annexures got tighter, attestations appeared, and audits became more frequent. That is not hostile. Their licence depends on your controls. Sorting the annexure before the audit costs less than sorting it during one.

You get one team for the day-to-day IT, the cybersecurity layer and the vendor oversight. We own the tenants, the devices, the identities and the vendor register. Nowhere for a problem to fall between providers, and a straight answer on the day your licensee, your broker, your auditor or ASIC asks.

Live right now

The 2026 pressure points we're actively working on with clients.

The specific asks, deadlines and enforcement actions shaping 2026 conversations in your sector.

ASIC v Fortnum Private Wealth (July 2025)

ASIC has filed civil penalty proceedings against Fortnum. It alleges Fortnum failed to set minimum cyber training and security controls for its authorised representatives (ARs) after the 2022 Wealthwise breach. The directions hearing is listed for July 2026. Every licensee group holding an Australian Financial Services Licence (AFSL) is now pushing MFA, EDR, baseline controls and staff training onto its ARs in writing. If you are an AR, expect your next licensee audit to ask for evidence. If you are the licensee, what you owe your ARs is now spelled out.

Licensee cyber annexures arriving through 2025/26

Fortnum, Count, Centrepoint, Oreana, Infocus, WT Financial, Lifespan, Clearview and Insignia have all tightened their cybersecurity policy for ARs in the past 12 months. Most ask for the same list: phish-resistant MFA, EDR on every device, documented patching, awareness training, a managed password vault. Then onboarding and offboarding run by HR, a written incident response plan, and evidence that all of it is operating. They are not suggestions. They are the basis of your next AR audit.

Cyber insurance renewal 2025/26 is an audit

Underwriters have stopped quoting financial services firms without the full set: MFA on every account, EDR on every device, tested backups. Then DMARC email authentication, phishing training for staff, and a written incident response plan. "We'll fix it after renewal" is why firms are being declined outright. The Fortnum proceedings are speeding this up.

ASIC 2026 enforcement priorities

Operational resilience, third-party risk and data governance are all named in ASIC's enforcement priorities this year. They apply to licensees the Australian Prudential Regulation Authority (APRA) does not regulate. ASIC will look at your controls before it looks at your advice.

Frameworks and regulators

Industry frameworks, regulations and audit standards for financial services in Australia.

AFSL obligations (Corps Act s912A / s912D)
ASIC regulatory guides RG 104 and RG 271
Licensee cyber annexure
APRA CPS 234
Privacy Act 1988 and the Australian Privacy Principles
Mandatory ransomware payment reporting
ACSC Essential Eight

Common questions

The things financial services clients ask us first.

Our licensee just sent us a new cybersecurity annexure to sign. What do we actually need to action?
Our platform (Netwealth / HUB24 / Praemium / Macquarie Wrap) just sent us a third-party risk questionnaire. How do we answer it?
We're a 4-person advisory firm. Is this level of IT really necessary?
Our cyber insurance renewal questionnaire keeps getting longer. Can you help?
Can our staff use Microsoft 365 Copilot, ChatGPT Enterprise or Claude for Work on client financial data?
What should we do if we think an adviser or admin staff member clicked a phishing link?
We use XPLAN / AdviserLogic / Iress / Practifi / MyProsperity / Class / BGL. Does that change the IT conversation?
We're a small AFSL with outsourced everything. Is that safer or riskier?

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit