The email asking you to change wire instructions is the whole attack, and it looks entirely ordinary.
Financial firms do not usually get broken into. They get asked politely. An email arrives from a client, or apparently from a client, saying the wire should go to a different account this time.
The second problem is documentation. An examiner will ask for your written security program, your incident response plan, and your vendor reviews. Producing those quickly is most of the outcome.
Wire instruction changes get verified by a process, not by one person.
Your written information security program exists and stays current.
Email impersonation gets caught before it reaches an advisor's inbox.
Examiner document requests get answered from files already maintained.
Retention policies cover email and messaging, which regulators now check.
You can get in touch with an engineer within thirty minutes when you nee help.
Multi-factor authentication is enforced, which the Safeguards Rule requires.
Two very different risks sit in a financial firm. One is a fraudulent instruction that moves real money in an afternoon. The other is a document request that arrives with a deadline and expects records going back years. Both get handled in advance.
Any change to payment or wire instructions triggers a callback to a number already on file, never one supplied in the email. That single step stops most of these attempts.
Impersonation and lookalike domains get filtered before they arrive, and your own domain is published correctly, so nobody else can send mail that appears to come from your own firm.
The Safeguards Rule expects a written information security program rather than good intentions. Yours gets drafted around how the firm actually operates, then revised whenever something material about it changes.
Retention gets configured so business communications stay preserved and searchable. Messaging apps are where firms have been caught out most recently, and that gap is far easier to close beforehand.





This is the attack that actually takes money out of financial firms, and it involves no malware at all. Somebody watches an inbox long enough to learn how your firm writes, then sends an instruction at a plausible moment: a distribution, a new bank, a request marked urgent because the client is traveling. There is nothing technical to detect because nothing technical happened. What stops it is a procedure nobody is allowed to skip.
The procedure part matters more than the technology part, and it is genuinely simple: any change to where money goes gets verified by voice, on a number already in your records, before anything moves. The technical side makes impersonation harder to pull off, through filtering, authentication records on your domain, and alerts on mailbox rules an attacker sets to hide replies.
Instruction changes get verified by callback to a number already held in your own records.
Lookalike domains and display name impersonation get filtered out before delivery.
Mailbox rules that hide an attacker's replies get flagged rather than sitting unnoticed.
The FTC Safeguards Rule, as amended, expects a written information security program, a named individual responsible for it, a documented risk assessment, multi-factor authentication, encryption, and a written incident response plan. State regulators and the SEC ask for broadly the same things. None of it is exotic, and most firms of your size have some of it informally and none of it written down, which is the position an examination finds least convincing.
We build the documents from your actual environment, which means the program describes the firm rather than a template. It also means the evidence behind it exists: the access reviews, the restore tests, the vendor list. When a request arrives with a deadline, the work is retrieval rather than reconstruction, and that difference is usually two weeks of somebody senior’s time.
The The security program describes your own firm, not a template with your name inserted.
The risk assessment, access reviews, and vendor list all exist as files, already current.
A document request becomes a retrieval job rather than three weeks of reconstruction.
Business communications have to be preserved, and regulators have spent the last few years making the point about messaging in particular. Advisors text clients because clients text, and those conversations are records whether or not anybody planned for that. Email is usually handled adequately by accident. Text and chat are usually not handled at all. The uncomfortable version is a firm producing five years of email and nothing else.
Because we manage your Microsoft 365 tenant, retention and search on email and Teams is configuration rather than a new purchase. Where the requirement extends to personal devices and text messages, that usually needs a dedicated product and a policy about which channels are permitted at all. We will tell you which of those two situations you are in before you buy anything.
Retention Retention and search across email and Teams gets configured inside your existing tenant.
Where messaging genuinely needs a dedicated archiving product, you hear that before buying.
A written policy on which channels advisors may use closes the part policy can close.
Two things tend to prompt the first call. Either a fraudulent instruction got close enough to be genuinely frightening, or a custodian sent through a security questionnaire that nobody at the firm could answer with any real confidence at all about it.
Money Moves Verified
Any instruction to change where money goes triggers a callback to a number already on file rather than the one in the email. It is a small step that stops the vast majority of these attempts.
The Program Exists
Your written information security program exists, describes how the firm actually operates, and gets revised when something material changes. It is the first document requested in an examination and the one that firms most often lack.
Records Stay Searchable
Retention covers email and messaging, configured so business communications remain preserved and searchable years later. Messaging apps are where firms have been penalized most recently, and closing that particular gap beforehand really costs you very little.
Committed Support
White glove support for firms like yours means an odd wire instruction is addressed by one of our IT experts inside thirty minutes, and not left to the end of the day. This is just one reason why our satisfaction score across the clients we support sits at 96.7 percent.
Usually the firm that sent the money, which is the uncomfortable part and the reason the verification procedure matters more than any product. Banks are generally under no obligation to reverse a properly authorized transfer, and recovery depends almost entirely on how quickly the receiving institution is contacted. Some professional liability and cyber policies cover social engineering fraud, and many exclude it or cap it at a low sub-limit, so it is worth reading that specific section of your policy rather than assuming.
Probably, and the amended rule caught a lot of firms by surprise because it reaches well beyond banks into advisers, mortgage brokers, and other non-bank financial institutions. There is a partial exemption for firms holding information on fewer than five thousand customers, which reduces some documentation obligations but does not remove the underlying requirements. The practical answer is that the controls it asks for are ones you would want anyway, so the useful question is whether they are written down rather than whether the rule technically applies.
If they are business communications, they are records, regardless of which device they were sent from. That is the area where enforcement has concentrated recently, and the usual finding is not that a firm archived badly but that it never archived that channel at all. There are two workable approaches: capture the channel properly with a product built for it, or prohibit it in writing and give advisers an approved alternative they will actually use. Prohibiting it without a usable alternative tends not to survive contact with clients.
Yes, and send it before anybody starts answering. Custodian questionnaires ask specific, verifiable things about multi-factor authentication, encryption, backups, and access controls, and an optimistic answer is a genuine risk because the whole point is that it can be checked. We work through it with you, mark what your environment already satisfies, and flag anything that needs work first. Small gaps often close quickly enough to answer accurately on this submission rather than the next one.
Most owners find out how thin their security was on the day it fails, and how slow their IT company is on the same day. You can find out now instead, on a call that costs nothing, from somebody who will say it plainly.
Call (702) 874-3767 today or fill out the form below to see firsthand what white-glove IT services look like.