You almost certainly have the controls already. Multi-factor authentication (MFA), endpoint detection and response (EDR), backups, allowlisting, logging, offboarding. None of that is exotic. The hard part is evidence. Your licensee, your broker and your platform all want proof that a control was on and stayed on. So does the Australian Securities and Investments Commission (ASIC). Most firms we assess have the controls in name but can't produce the evidence when someone digs in.
Then there is everyone else who touches your data. Platforms, advice software, practice management, client records, SMSF administration, tax and modelling tools. Every one of them adds another login and another set of people to trust. CPS 234, ASIC guidance, your licensee's annexure and the broker's questionnaire all want that oversight documented now. Someone has to read the vendor's assurance report, track their breach history and keep the access register current. When a vendor's security slips, someone has to notice. That is a real job, and it does not fit in the gaps of someone else's week.
If you are an authorised representative, your dealer group has already reacted to the Fortnum proceedings. ASIC's position is that licensees must set and enforce minimum cyber controls on their representatives. Failing to do so, it says, breaches the licence obligations. Annexures got tighter, attestations appeared, and audits became more frequent. That is not hostile. Their licence depends on your controls. Sorting the annexure before the audit costs less than sorting it during one.
You get one team for the day-to-day IT, the cybersecurity layer and the vendor oversight. We own the tenants, the devices, the identities and the vendor register. Nowhere for a problem to fall between providers, and a straight answer on the day your licensee, your broker, your auditor or ASIC asks.