Financial planning practices hold some of the most detailed client wealth data of any small business - superannuation balances, income, family circumstances - and carry record-keeping and conduct obligations tied to their AFSL relationship. Here's a practical checklist specific to the sector, not a generic cybersecurity list with the industry name swapped in.
Email Security and Funds-Transfer Verification
- SPF, DKIM, and DMARC properly configured to prevent your domain being spoofed - see our guide on SPF, DKIM, and DMARC explained
- A mandatory verbal or independently-verified callback process for any client request to transfer or redirect funds, regardless of how legitimate the email looks
- Staff training specifically on business email compromise patterns targeting this sector - see our guide on business email compromise and invoice fraud
Access Control
- MFA enforced on every account with access to client data, without exception, including admin accounts
- Practice management and platform logins reviewed to confirm minimum necessary access per role
- Former staff and departed advisers' access reviewed and revoked promptly - see our guide on the Microsoft 365 offboarding checklist
Data Handling and Retention
- Client files and Statements of Advice stored and shared through a secure system, not general email attachments
- Data retention periods matched to your specific record-keeping obligations, not a generic default
- Backup coverage confirmed for practice management software, not just email and file storage - see our guide on business backup cost for what proper coverage typically involves
Incident Readiness
- A documented incident response process, including notification obligations under the Notifiable Data Breaches scheme - see our guide on the Notifiable Data Breaches scheme
- Cyber insurance in place, with coverage terms reviewed against what insurers actually require for this sector - see our guide on cyber insurance for Perth businesses
Third-Party and Platform Risk
- Security posture of platforms and licensees you connect to or operate under reviewed, since your risk is partly tied to theirs
- APRA CPS 234-linked requirements understood where they flow down through institutional relationships - see our guide on APRA CPS 234 explained
Where to Start
If none of this is currently in place, funds-transfer verification and MFA deliver the most protection for the least effort, and should be the first two items addressed. See our broader guide on IT support for financial planners in Perth for how this checklist fits into a full IT setup for the sector.
Frequently Asked Questions
Does this checklist apply if we operate under someone else's AFSL rather than holding our own?
Yes - authorised representatives operating under another licensee's AFSL are still expected to meet the security and record-keeping standards the licensee is accountable for, so these controls matter just as much, if not more, given the added reporting relationship.
What's the single highest-risk area for financial planning practices specifically?
Business email compromise targeting client fund transfers - a compromised or spoofed email requesting an urgent transfer of client funds is one of the costliest and most common attack patterns against this sector specifically, precisely because plausible transfer requests are a normal part of the work.
How does this checklist relate to APRA CPS 234?
CPS 234 applies directly to APRA-regulated entities, which most individual financial planning practices are not, but its requirements increasingly flow down through the institutions and platforms practices deal with. See our guide on APRA CPS 234 for how that flow-down works in practice.
Do cyber insurers ask about these specific controls when underwriting a financial planning practice?
Increasingly, yes - insurers assessing risk for this sector commonly ask about MFA coverage, email security controls, and staff training specifically around funds-transfer verification, given how frequently BEC targets this type of practice.
We support Perth financial planning practices with cybersecurity built around AFSL-linked obligations and funds-transfer risk specifically.
Cybersecurity Services →Not sure how your practice measures up against this checklist?
Call 0433 087 091 - we'll run through it with you, no obligation.
Get a Free Security ReviewFor related reading, see our guides to IT support for financial planners and APRA CPS 234 explained.