Blog

A brief adviser guide to cyber security

With many of us continuing to work from home and spending more time online, the issue of cyber security has increasingly come to the fore

Graeme Stewart

Graeme Stewart

30 November 2020
The threats and risks associated with cyber attacks seem to be growing, both in volume and intensity. 

There are a number of key things for firms to consider in order to counter this growing threat, and encouragingly, a wide range of resources available to help. 

To begin with, and perhaps unsurprisingly, the FCA has quite a lot to say on the subject of cyber crime. 

In its annual report for 2019/20, the regulator said it had assessed 824 incident reports, of which 790 were cyber or technology-related.

It also noted there had been 324,000 online video views of its latest ScamSmart campaign as at 31 March this year. 

The FCA has built up a considerable library of support and help for firms on this matter, for example its good cyber security infographic, an industry insights paper and information for consumers on protecting yourself from scams.

The regulator says generally firms need to make sure they have the right systems in place to tackle this issue. 

The FCA has also published a document on banks' fraud controls which, though it has largely gone under the radar, could prove really useful for firms.

Banks gave responses to the following questions:

  • What is the firm’s approach to fraud prevention?
  • How and when can the firm’s customers contact them?
This could be used by firms to not only understand what to expect from their bank, but to become more alert to fraudulent behaviours and perhaps to educate their clients as well. 

Combating scams and helping clients stay safe

The FCA and The Pensions Regulator launched their latest joint campaign in July to help prevent pension scams. 

There were two key aims behind the campaign: firstly to provide savers aged between 45 and 65 with the knowledge and tools to avoid pension scams, and secondly to provide the pensions industry with the knowledge and tools to help savers. 

It outlined the four simple steps people can take to protect themselves:

  1. Reject unexpected pension offers
  2. Check the status of a firm with the FCA before changing your pension arrangements
  3. Don’t be rushed or pressured into making any decision about pensions
  4. Consider getting impartial information and advice 
The National Cyber Security Centre (NCSC) has a lot of useful resources to share with clients through its Cyber Aware service, the UK government’s advice on how to stay secure online, particularly during coronavirus. 

Its top tips are:

  • Create separate passwords for your email
  • Create strong passwords using at least three random words
  • Save passwords in your browser
  • Turn on two-factor authentication
  • Update your devices
  • Turn on back-up
Other NCSC resources for clients include guidance on protecting devices from viruses and malware, as well as a glossary of common cyber security terms

But the most important thing firms can do is give their clients confidence about how their data is being handled and protected.

It's worth educating your clients as to how exactly your firm will contact them and flagging that if this protocol isn't followed, they should be suspicious.

Clients should be encouraged to call you to verify any suspicious communications, just as you will call to verify any suspicious communications from them.

Firms can keep their clients up to date on cyber crime by highlighting the range of resources available both at the initial advice stage and when delivering ongoing advice, or when completing suitability assessments. 

At a firm level, the NCSC has guidance for companies of under 250 people which includes business advice and support on Covid-19, how to get your firm Cyber Essentials certified and the ability to test and practice your response to a cyber attack. 

What to ask your IT support firm

Many firms choose to contract out cyber security work to a professional IT support firm. 

There are though some due diligence questions you may want to ask before appointing (or renewing contracts with) an IT support firm.

For example:

  • What is the knowledge and experience of the firm? Ask to speak to their customers to find out their experiences, or ask for accredited testimonials
  • What support do they actually offer? What's available during office hours and outside of these, and at weekends
  • How often will their security be updated? You want to be assured that the firm will regularly be updating software
  • What training and further support can they provide your staff?You need to know that your staff will be able to get the IT support they need when dealing with problems or issues
It's also worth making sure you fully understand their procedures on:

  • Account management
  • Anti-virus protection
  • Change management
  • Data back-up and data loss prevention
  • Secure email
  • Encryption policy
  • Incident response
  • Network access
  • Password policy
  • Patch management
  • Physical security
  • Portable computing
  • Data protection policy
Ultimately, while the threat of cyber crime is real and growing, firms have a wealth of information at their fingertips to help their business address this. 

Staff training should be carried out regularly, keeping them up to date of company procedures and protocols.

Updating protection software should also become part of a firm’s culture, often becoming a weekly if not daily activity.

Reading this blog counts towards your CPD!

Click here to add this session to your Paradigm CPD log.


18 December 2025

Three weeks on from the Budget, the dust has settled but concerns remain


11 December 2025

How Lenders’ New Freedoms are Undermining Client Relationships


8 December 2025

Navigating the Autumn Budget: What It Means for Mortgages and How Accord is Responding


4 December 2025

Ministerial letter on cyber security to small businesses


25 November 2025

AI: from uncertainty to opportunity


11 November 2025

What the Chancellor’s pre-Budget words may mean for the housing market


10 November 2025

Budget via the rumour mill creates no bread for anyone


30 October 2025

Why first-time buyers need advice as well as incentives


8 October 2025

Stamp duty shockwaves fade as landlords get set to expand


29 September 2025

A Broker’s Guide to Busting Mortgage Barriers for Homebuyers


22 September 2025

The government has now confirmed the next Budget will take place on 26 November


17 September 2025

The FCA’s AI vision – opportunity for advisers or a threat to advice?


15 September 2025

Just one week left to make the case for advice


10 September 2025

Economic abuse: What is it and who is at risk?


1 September 2025

Beyond student lets: the rise of HMOs


15 August 2025

Just because the option exists, doesn’t mean it should be taken


12 August 2025

Understanding the FCA’s Discussion Paper: The other side of the SWOT analysis


24 July 2025

Understanding the FCA’s Discussion Paper: Potential benefits… and risks


16 July 2025

From Niche to Necessary: Why Specialist Lending is the New Normal


15 July 2025

What does the FCA actually want for mortgage borrowers?


27 June 2025

When 'perfect’ isn’t good enough – the strange case of the regulator and mortgage risk


16 June 2025

Working together to fight home insurance fraud


29 May 2025

Help all your clients protect what’s important with Refer & Protect


23 May 2025

Execution-only or (Consumer) Duty of care? The FCA can’t have it both ways


21 May 2025

FCA’s latest Consultation Paper seeks to diminish the value of advice once again


8 May 2025

Keep your eyes on the business, but don’t stop scanning the horizon


1 May 2025

Is 5 a Magic Number?


28 April 2025

Downsizers, downhill skiers and classic car collectors – how regulated bridging can help


24 April 2025

The mortgage market resurgence commands equal measures of hope and caution


16 April 2025

Trump, tariffs, and the rise of later life lending


14 April 2025

Impact of US Tariffs on UK Property Investors: A Market Analysis


20 March 2025

How the FCA’s mortgage proposals could undermine consumer protection


17 March 2025

Is ‘cashing out’ leading to worse outcomes for borrowers?


5 March 2025

Start 2025 smarter: Streamline your financial planning with an exclusive Paradigm member offer


13 February 2025

First-time buyers still driving market


6 February 2025

FCA ‘Dear CEO’ Letter to Mortgage Intermediaries


10 January 2025

The 2025 PT shift will be dictated by an attractive remortgage market


9 January 2025

Read Between The Lies – Mortgage Fraud in 2025


Paradigm

THIS SITE IS FOR PROFESSIONAL INTERMEDIARY USE ONLY AND NOT FOR USE BY THE GENERAL PUBLIC.

APCC MemberConsumer Duty Alliance

Paradigm Consulting is a Member of the Association of Professional Compliance Consultants and also the Consumer Duty Alliance.

Paradigm Consulting is a trading name of Paradigm Partners Ltd
Office address: Paradigm Partners Ltd, Paradigm House, Brooke Court, Wilmslow, Cheshire, SK9 3ND
Paradigm Partners Ltd is registered in England and Wales. No.09902499. Registered Office: As above

Paradigm Mortgage Services LLP
Office address: 1310 Solihull Parkway, Birmingham Business Park, Birmingham B37 7YB
Registered in England and Wales. Company No: OC323403. Registered Office: Paradigm House, Brooke Court, Lower Meadow Road, Wilmslow, SK9 3ND
Paradigm Mortgage Services LLP is a Limited Liability Partnership.

Paradigm Protect is a trading name of Paradigm Mortgage Services LLP
Office address: 1310 Solihull Parkway, Birmingham Business Park, Birmingham B37 7YB
Paradigm Mortgage Services LLP is registered in England and Wales. Company No: OC323403. Registered Office: Paradigm House, Brooke Court, Lower Meadow Road, Wilmslow, SK9 3ND
Paradigm Mortgage Services LLP is a Limited Liability Partnership.