Still have questions?
Speak to our team
Strong cyber security controls are a non-negotiable for investment firms. Not least because it is mandated by regulation but these businesses are also an attractive target for cyber criminals. You may have invested heavily in cyber security, but how confident are you in the organisations that have access to your systems and client information?
Investment firms increasingly rely on external technology providers to run their businesses. These can include portfolio management platforms, cloud services, CRM systems, data providers and outsourced IT support.
Each supplier relationship can introduce risk.
A supplier suffering a cyber attack could expose confidential information, disrupt client services or compromise your IT systems. And because your firm remains responsible for compliance with regulatory obligations, outsourcing technology or other services does not mean outsourcing accountability.
The FCA has reinforced this concern. In March 2026, it reported that more than 40% of cyber incidents reported to it during 2025 involved a third party. For investment firms, supply chain security should be a routine part of governance, not an exercise undertaken only when signing a new contract. This means having a process for regular risk assessments and reviews.
Here are five areas to consider when assessing the security and resilience of your technology suppliers.
Not every supplier needs the same level of scrutiny. A company providing a relatively unimportant application presents a different risk from one hosting your portfolio management system or administering your Microsoft 365 environment. Start by identifying your technology suppliers and understanding their importance to the business.
Consider three questions:
A supplier with access to sensitive client information, responsibility for a critical business system or privileged administrative access should receive greater scrutiny. For example, an investment firm might depend on a portfolio management platform for day-to-day operations. If that platform becomes unavailable, the firm may struggle to access information required to serve clients. Understanding these dependencies is the starting point for effective supplier governance.
A supplier saying it takes cyber security seriously is not enough. You need proof that appropriate controls are in place and that those controls are maintained. The depth of your review should reflect the supplier’s risk to your business, but useful areas to examine include:
Certifications can provide useful reassurance, but they should not be treated as proof that every aspect of a supplier’s service is secure. The objective is to understand how the supplier manages risk in practice. Where possible, ask for supporting evidence rather than accepting general statements.
Of all your technology suppliers, your IT provider may have the greatest potential impact on your security. That is because outsourced IT companies often have privileged access to the systems they manage. Depending on your arrangements, this could include Microsoft 365, employee devices, servers, backups, security tools and business applications. This level of access is necessary to deliver an effective service, but it also creates significant responsibility.
If an attacker compromises a supplier account with extensive administrative privileges, the consequences could extend well beyond a single application. Your IT provider should therefore be able to explain exactly how it protects its own operations and the access it holds to your business.
Questions worth asking include:
Administrative access should be limited to authorised individuals, protected with appropriate authentication and monitored.
Your provider should maintain robust security controls across its own systems, devices and employee accounts.
There should be clear processes for granting, reviewing and removing access when employees change roles or leave.
Your provider should have a documented incident response process, including how affected clients would be informed and supported.
A credible provider should be comfortable discussing its security arrangements and supplying appropriate evidence. The important point is that your IT provider should be held to the highest level of scrutiny of all your technology suppliers. This can be a challenge for firms who have outsourced IT expertise which is where specific quality and security trustmarks like Assurix become invaluable.
The FCA expects firms to manage the risks arising from outsourcing and other third party arrangements. Its guidance makes clear that firms remain responsible and accountable for their applicable regulatory obligations, even when services are delivered by external organisations. That does not mean every technology supplier is subject to identical requirements.
The rules that apply depend on factors including the type of firm, the nature of the arrangement and whether the outsourced function is critical or important. However, they make it clear that firms should understand their dependencies and manage the associated risks proportionately.
There is also an important development approaching. From 18 March 2027, new FCA requirements will introduce additional notification and annual reporting obligations for material third party arrangements for certain categories of financial services firms. These requirements do not apply to every FCA regulated investment firm. Firms will need to determine whether they fall within scope.
Regardless of whether the new reporting requirements apply, reviewing technology supplier risk is already an important part of sound governance. Your compliance team should determine the firm’s specific regulatory obligations, while your technology provider should help supply the technical information and evidence needed to support that assessment.
Supplier security should not be assessed once and then forgotten. Technology environments change. Suppliers introduce new services, employ new people, update systems and sometimes change their own subcontractors. The risks associated with a supplier can therefore change over time. We recommend a structured review process based on the importance of each supplier.
For example:
| Supplier risk | Illustrative review approach |
| High | Formal review at least annually, with monitoring of significant changes and incidents |
| Medium | Periodic review, for example every 12 months |
| Low | Basic due diligence at onboarding and review when circumstances change |
Note that these are a suggested starting point and not official guidelines; you need to decide what it right for your firm. If a weakness is identified, someone should be responsible for assessing the risk, agreeing corrective action and confirming whether it has been completed. Without that, a supplier assessment becomes little more than a ‘tick box’ exercise.
Consider a hypothetical investment management firm with 50 employees. The firm uses Microsoft 365, a specialist portfolio management application and an outsourced IT provider.
Its leadership team believes cyber security is well managed because employees receive security training and the business has Cyber Essentials certification.
A review of its supplier arrangements, however, identifies three issues:
None of these issues necessarily causes an immediate outage or security incident but each represents a risk that could have significant consequences if something goes wrong.
The firm can now take practical action: improve access controls, obtain evidence of recovery testing and introduce a proportionate supplier review process.
At Pro Drive, we believe good technology management starts with a defined standard. That means understanding what your IT environment should look like, assessing where it currently stands and making measurable improvements.
Our Pro Drive 360 approach is built around four stages:
Supplier risk forms part of the wider governance picture. An IT environment cannot be considered properly governed if important dependencies and privileged access arrangements are poorly understood.Pro Drive 360 assesses more than 200 operational, security and productivity factors, with quarterly reviews to measure progress and identify areas requiring attention.The aim is to replace assumptions with evidence and ensure technology keeps improving.
We also firmly believe in demonstrating our own compliance to our clients. This is why we are committed to the Assurix trustmark which demonstrates the highest levels of security and quality of service.
For an FCA regulated investment firm, technology supplier risk is a business issue, not simply an IT concern.Your clients trust you with sensitive information and, in many cases, important financial decisions. The systems and suppliers supporting your business need to reflect that responsibility.
You should know which suppliers are critical, what access they hold, what controls protect your information and what would happen if their services were disrupted.Above all, you should be able to demonstrate that these risks are being actively managed.
If you are unsure how your current technology arrangements compare with best practice, Pro Drive can help you establish a clearer picture of your environment, identify gaps and understand where improvement is needed.
Explore Pro Drive 360 or get in touch to learn more about securing your supply chain.
Speak to our team