Skip to content

Strong cyber security controls are a non-negotiable for investment firms. Not least because it is mandated by regulation but these businesses are also an attractive target for cyber criminals. You may have invested heavily in cyber security, but how confident are you in the organisations that have access to your systems and client information?

Investment firms increasingly rely on external technology providers to run their businesses. These can include portfolio management platforms, cloud services, CRM systems, data providers and outsourced IT support.

Each supplier relationship can introduce risk.

A supplier suffering a cyber attack could expose confidential information, disrupt client services or compromise your IT systems. And because your firm remains responsible for compliance with regulatory obligations, outsourcing technology or other services does not mean outsourcing accountability.

The FCA has reinforced this concern. In March 2026, it reported that more than 40% of cyber incidents reported to it during 2025 involved a third party. For investment firms, supply chain security should be a routine part of governance, not an exercise undertaken only when signing a new contract. This means having a process for regular risk assessments and reviews.

Here are five areas to consider when assessing the security and resilience of your technology suppliers.

  1. Which technology suppliers present the greatest risk to your firm?

Not every supplier needs the same level of scrutiny. A company providing a relatively unimportant application presents a different risk from one hosting your portfolio management system or administering your Microsoft 365 environment. Start by identifying your technology suppliers and understanding their importance to the business.

Consider three questions:

  • What information can they access? This could include client records, financial information, investment data or employee details.
  • What systems do they support? Consider the impact if their service becomes unavailable or the data in it is compromised.
  • What level of control do they have? Some suppliers simply process information, while others can make changes across your technology environment.

A supplier with access to sensitive client information, responsibility for a critical business system or privileged administrative access should receive greater scrutiny. For example, an investment firm might depend on a portfolio management platform for day-to-day operations. If that platform becomes unavailable, the firm may struggle to access information required to serve clients. Understanding these dependencies is the starting point for effective supplier governance.

  1. What cyber security evidence should you request from suppliers?

A supplier saying it takes cyber security seriously is not enough. You need proof that appropriate controls are in place and that those controls are maintained. The depth of your review should reflect the supplier’s risk to your business, but useful areas to examine include:

  • Security certifications: Does the supplier hold relevant accreditations, such as Cyber Essentials Plus, SOC2 or ISO 27001, and what activities do those certifications actually cover?
  • Access controls: How does the supplier protect accounts with access to your systems and data?
  • Security monitoring: How are threats identified, investigated and addressed?
  • Vulnerability management: How does the supplier identify and resolve security weaknesses?
  • Incident response: What happens if the supplier experiences a cyber incident that could affect your business?
  • Business continuity: What recovery arrangements exist, and how are they tested?
  • Subcontractors: Does the supplier rely on other organisations to deliver its services, and how are those relationships governed?

Certifications can provide useful reassurance, but they should not be treated as proof that every aspect of a supplier’s service is secure. The objective is to understand how the supplier manages risk in practice. Where possible, ask for supporting evidence rather than accepting general statements.

  1. Why does your IT support provider deserve particular scrutiny?

Of all your technology suppliers, your IT provider may have the greatest potential impact on your security. That is because outsourced IT companies often have privileged access to the systems they manage. Depending on your arrangements, this could include Microsoft 365, employee devices, servers, backups, security tools and business applications. This level of access is necessary to deliver an effective service, but it also creates significant responsibility.

If an attacker compromises a supplier account with extensive administrative privileges, the consequences could extend well beyond a single application. Your IT provider should therefore be able to explain exactly how it protects its own operations and the access it holds to your business.

Questions worth asking include:

How is privileged access controlled?

Administrative access should be limited to authorised individuals, protected with appropriate authentication and monitored.

How do you protect your own business?

Your provider should maintain robust security controls across its own systems, devices and employee accounts.

How do you manage employee access?

There should be clear processes for granting, reviewing and removing access when employees change roles or leave.

What happens if you experience a cyber incident?

Your provider should have a documented incident response process, including how affected clients would be informed and supported.

How can you demonstrate that these controls are working?

A credible provider should be comfortable discussing its security arrangements and supplying appropriate evidence. The important point is that your IT provider should be held to the highest level of scrutiny of all your technology suppliers. This can be a challenge for firms who have outsourced IT expertise which is where specific quality and security trustmarks like Assurix become invaluable.

  1. What does the FCA expect investment firms to do about third party risk?

The FCA expects firms to manage the risks arising from outsourcing and other third party arrangements. Its guidance makes clear that firms remain responsible and accountable for their applicable regulatory obligations, even when services are delivered by external organisations. That does not mean every technology supplier is subject to identical requirements.

The rules that apply depend on factors including the type of firm, the nature of the arrangement and whether the outsourced function is critical or important. However, they make it clear that firms should understand their dependencies and manage the associated risks proportionately.

There is also an important development approaching. From 18 March 2027, new FCA requirements will introduce additional notification and annual reporting obligations for material third party arrangements for certain categories of financial services firms. These requirements do not apply to every FCA regulated investment firm. Firms will need to determine whether they fall within scope.

Regardless of whether the new reporting requirements apply, reviewing technology supplier risk is already an important part of sound governance. Your compliance team should determine the firm’s specific regulatory obligations, while your technology provider should help supply the technical information and evidence needed to support that assessment.

  1. How often should investment firms review their technology suppliers?

Supplier security should not be assessed once and then forgotten. Technology environments change. Suppliers introduce new services, employ new people, update systems and sometimes change their own subcontractors. The risks associated with a supplier can therefore change over time. We recommend a structured review process based on the importance of each supplier.

For example:

Supplier risk  Illustrative review approach
High Formal review at least annually, with monitoring of significant changes and incidents
Medium Periodic review, for example every 12 months
Low Basic due diligence at onboarding and review when circumstances change

 

Note that these are a suggested starting point and not official guidelines; you need to decide what it right for your firm. If a weakness is identified, someone should be responsible for assessing the risk, agreeing corrective action and confirming whether it has been completed. Without that, a supplier assessment becomes little more than a ‘tick box’ exercise.

What might a technology supplier audit uncover?

Consider a hypothetical investment management firm with 50 employees. The firm uses Microsoft 365, a specialist portfolio management application and an outsourced IT provider.

Its leadership team believes cyber security is well managed because employees receive security training and the business has Cyber Essentials certification.

A review of its supplier arrangements, however, identifies three issues:

  1. The IT provider has administrative accounts that are not sufficiently restricted.
  2. The firm has never reviewed the recovery arrangements for a critical hosted portfolio management application.
  3. There is no documented process for reviewing the security of important technology suppliers.

None of these issues necessarily causes an immediate outage or security incident but each represents a risk that could have significant consequences if something goes wrong.

The firm can now take practical action: improve access controls, obtain evidence of recovery testing and introduce a proportionate supplier review process.

How can investment firms make supplier assurance part of IT governance?

At Pro Drive, we believe good technology management starts with a defined standard. That means understanding what your IT environment should look like, assessing where it currently stands and making measurable improvements.

Our Pro Drive 360 approach is built around four stages:

  1. Audit: Assess the technology environment against defined standards and identify gaps.
  2. Roadmap: Plan strategic technology investment around business objectives, productivity, growth and developments within the investment sector.
  3. Align: Bring systems and controls into line with the agreed technical standards.
  4. Enforce: Continuously monitor, review and improve the environment as technology and risks change.

Supplier risk forms part of the wider governance picture. An IT environment cannot be considered properly governed if important dependencies and privileged access arrangements are poorly understood.Pro Drive 360 assesses more than 200 operational, security and productivity factors, with quarterly reviews to measure progress and identify areas requiring attention.The aim is to replace assumptions with evidence and ensure technology keeps improving.

We also firmly believe in demonstrating our own compliance to our clients. This is why we are committed to the Assurix trustmark which demonstrates the highest levels of security and quality of service.

Can you demonstrate that your technology suppliers are secure?

For an FCA regulated investment firm, technology supplier risk is a business issue, not simply an IT concern.Your clients trust you with sensitive information and, in many cases, important financial decisions. The systems and suppliers supporting your business need to reflect that responsibility.

You should know which suppliers are critical, what access they hold, what controls protect your information and what would happen if their services were disrupted.Above all, you should be able to demonstrate that these risks are being actively managed.

Don’t just manage IT. Govern IT.

If you are unsure how your current technology arrangements compare with best practice, Pro Drive can help you establish a clearer picture of your environment, identify gaps and understand where improvement is needed.

Explore Pro Drive 360 or get in touch to learn more about securing your supply chain.

Still have questions?

Speak to our team