Choosing a platform is one of the most important decisions you'll make for your clients. Performance, functionality and cost all play a part, but security deserves just as much attention.
Your platform provider isn't only responsible for processing transactions and holding assets. They're also trusted with your clients' personal and financial information, making them an important part of your firm's overall approach to security.
If you're reviewing a platform for the first time, or carrying out platform due diligence on an existing provider, it's worth knowing what good platform security for advisers looks like.
Here are some of the key areas to consider, the risks to be aware of, and the questions worth asking before you trust a provider with your clients' assets and data.
Why platform security matters more than ever
Cyber criminals are increasingly targeting third-party providers as a way of reaching the wider network of firms and clients that rely on them. A single breach at a platform can affect thousands of end clients, which makes platforms an attractive target. Understanding cyber risk in financial services has become an essential part of protecting your business and your clients.
The consequences can be significant, both commercially and from a regulatory perspective. The Financial Ombudsman Service considered a complaint where fraudsters accessed a client's ISA held on a third-party platform. Although the adviser argued the incident related to the platform, the adviser (EFS) did not contest liability and agreed to compensate the client for distress and inconvenience.
Consumer Duty has also raised expectations around how firms assess the products, services and providers they use. That includes considering whether your technology partners have the right controls in place to help deliver good outcomes for clients.
If you're reviewing your obligations under the regime, you can find practical guidance and resources in our Consumer Duty hub.
Alongside regulatory expectations, guidance from the FCA continues to highlight the importance of managing operational resilience and cyber threats, making FCA cybersecurity guidance an increasingly important consideration when assessing providers.
What advisers should look for in a secure investment platform
Recognised security standards
A good starting point when assessing investment platform security is to look for alignment or certification with recognised standards and frameworks such as ISO 27001, Cyber Essentials, Cyber Essentials Plus, NIST or SOC 2.
These standards provide independent assurance that a provider has appropriate policies, controls and governance in place across the business.
Multiple layers of protection
Strong financial platform security relies on several layers of protection working together rather than a single control or technology.
Look for controls such as multi-factor authentication (MFA), endpoint protection, vulnerability management, data loss prevention tools and continuous monitoring of systems and accounts for unusual activity.
Extra protection for high-risk actions
Some activities present a greater risk than others. Changes to bank details, withdrawals, and adding new payees are often the actions fraudsters target.
Ask what additional checks are applied when these requests are made. Strong providers will typically build in extra verification steps to help protect clients and reduce the risk of fraud.
These additional safeguards are often a good indicator that you're working with a secure investment platform.
Independent testing
Security should be tested regularly, not assumed.
Your platform provider should be able to explain how often they carry out independent penetration testing and security assessments, who performs them and how findings are addressed. Independent testing helps provide reassurance that controls continue to work as intended.
Incident response and communication
It's equally important to understand what happens when something goes wrong.
A mature provider will have a well-rehearsed incident response process, clear escalation procedures and a commitment to keeping you informed. If suspicious activity is identified, you should expect proactive communication rather than having to discover the issue yourself.
Supplier and insider risk
A platform's security is only as strong as the wider ecosystem that supports it.
Ask how suppliers are assessed and monitored, how privileged access is managed and reviewed, and what training employees receive. Supply chain attacks and insider threats continue to be a growing concern across financial services, so it's important that providers take these risks seriously.
A culture of security
Technology is only part of the picture.
One of the strongest indicators of a provider's approach to security is whether it's seen as a responsibility shared across the business rather than something owned solely by an IT team.
Regular staff training, phishing simulations, clear reporting processes and ongoing investment in security all help demonstrate that security forms part of the organisation's culture.
Questions to ask your platform provider
When carrying out platform due diligence, consider asking:
- What security standards are you certified against, and when were they last independently assessed?
- What additional checks do you apply to high-risk actions such as withdrawals and bank detail changes?
- How will you notify us if unusual activity is detected on an account?
- What does your incident response process look like, and how often is it tested?
- How do you assess and monitor the security of your suppliers?
- Do you offer MFA or single sign-on for adviser access, and is it mandatory?
Using a checklist like this during onboarding, and returning to it as part of your regular reviews, gives you a clear and repeatable way to assess platform security. It can also help demonstrate to clients and regulators that you've carefully considered the providers you rely on.
If you're carrying out platform reviews or gathering information about providers, our Due Diligence Hub brings together key documents and resources in one place.
How we approach platform security
Security is part of how we work every day. It influences how we design our systems, build our processes and support advisers.
Our systems, processes and infrastructure are aligned with recognised international standards, including ISO 27001, NIST and SANS. That approach extends beyond technology teams and forms part of how we operate across the business.
We use multiple layers of protection to help defend against evolving threats. These include additional checks around high-risk actions such as withdrawals and bank detail changes, continuous monitoring of accounts and infrastructure, and tools that help us identify unusual activity as early as possible.
Our internal security specialists work alongside independent experts to regularly test our platform and networks. We also carry out due diligence on suppliers before onboarding them and maintain robust incident response plans so we can respond quickly when needed.
And where we identify something unusual, such as suspicious login activity or a phishing campaign targeting adviser firms, we'll contact you directly. Protecting clients' assets and data works best when advisers and platform providers work together, which is why cybersecurity for financial advisers remains a shared responsibility.
You can read more about our approach to security on our Cyber Security Hub.
The bottom line
Platform security isn't something to review once and forget about. It's an ongoing part of choosing and monitoring the providers you trust with your clients' assets and information.
By asking the right questions, looking for evidence rather than assurances, and choosing providers that take security seriously, you can better protect your clients, your reputation and your business.
This article is for financial professionals only. Any information contained within is of a general nature and should not be construed as a form of personal recommendation or financial advice. Nor is the information to be considered an offer or solicitation to deal in any financial instrument or to engage in any investment service or activity.
Parmenion accepts no duty of care or liability for loss arising from any person acting, or refraining from acting, as a result of any information contained within this article. All investment carries risk. The value of investments, and the income from them, can go down as well as up and investors may get back less than they put in. Past performance is not a reliable indicator of future returns.

