Protect our clients and yourself from cyber attacks
Cyber vigilance: Protecting your practice and our clients
Cyber risk continues to be one of the most important operational and client protection issues facing advisors. Advisors hold sensitive personal and financial information, maintain trusted relationships with clients, and often support high-value transactions—making advisory practices attractive targets for phishing, business email compromise, account takeover, ransomware, and fraudulent transfer attempts.
Protecting clients starts with consistent, disciplined cyber hygiene. Please take the following steps to help safeguard your practice and reinforce client trust:
• Verify before acting: Verbally confirm any request to transfer/withdraw funds, change banking instructions, update contact details, or access client accounts—especially when received by email or text.
• Use multi-factor authentication: Enable MFA on all business, custodian, email, CRM, and client-facing systems wherever available.
• Be alert to phishing and impersonation: Treat unexpected links, attachments, QR codes, password reset requests, and urgent messages with caution, even if they appear to come from a known client, colleague, vendor, or carrier.
• Protect client information: Use approved secure channels for sharing documents and avoid sending sensitive personal or financial information through unencrypted email or unauthorized messaging platforms.
• Keep devices and software current: Apply security updates promptly, use endpoint protection, and avoid accessing business systems through unsecured public Wi-Fi.
• Strengthen passwords: Use unique, complex passwords and a reputable password manager; never reuse passwords across personal and business accounts.
• Know your escalation path: Report suspected cyber incidents, suspicious emails, credential compromise, or potential client fraud immediately through your approved incident reporting process. Consider which insurers need to be notified of potential client impact.
Cybercriminals increasingly rely on urgency, familiarity, and trust to bypass normal controls. A short pause to verify a request can prevent financial loss, privacy breaches, regulatory issues, and reputational harm.
Thank you for making cyber vigilance part of your day-to-day client service. If something seems unusual, do not proceed until it has been verified through an independent and trusted channel.
Cyber risk continues to be one of the most important operational and client protection issues facing advisors. Advisors hold sensitive personal and financial information, maintain trusted relationships with clients, and often support high-value transactions—making advisory practices attractive targets for phishing, business email compromise, account takeover, ransomware, and fraudulent transfer attempts.
Protecting clients starts with consistent, disciplined cyber hygiene. Please take the following steps to help safeguard your practice and reinforce client trust:
• Verify before acting: Verbally confirm any request to transfer/withdraw funds, change banking instructions, update contact details, or access client accounts—especially when received by email or text.
• Use multi-factor authentication: Enable MFA on all business, custodian, email, CRM, and client-facing systems wherever available.
• Be alert to phishing and impersonation: Treat unexpected links, attachments, QR codes, password reset requests, and urgent messages with caution, even if they appear to come from a known client, colleague, vendor, or carrier.
• Protect client information: Use approved secure channels for sharing documents and avoid sending sensitive personal or financial information through unencrypted email or unauthorized messaging platforms.
• Keep devices and software current: Apply security updates promptly, use endpoint protection, and avoid accessing business systems through unsecured public Wi-Fi.
• Strengthen passwords: Use unique, complex passwords and a reputable password manager; never reuse passwords across personal and business accounts.
• Know your escalation path: Report suspected cyber incidents, suspicious emails, credential compromise, or potential client fraud immediately through your approved incident reporting process. Consider which insurers need to be notified of potential client impact.
Cybercriminals increasingly rely on urgency, familiarity, and trust to bypass normal controls. A short pause to verify a request can prevent financial loss, privacy breaches, regulatory issues, and reputational harm.
Thank you for making cyber vigilance part of your day-to-day client service. If something seems unusual, do not proceed until it has been verified through an independent and trusted channel.