info@lookup.com.au 1300 553 559 Remote Assist
    Lookup Logo
    Financial Services Business Outcome

    Protecting Client and Financial Information in a Financial Services Business

    Financial services businesses depend on trust. Protecting client and financial information requires coordinated controls across identity, access, devices, Microsoft 365, specialist platforms, email, third parties, recovery and people — not a single security product.

    The two-minute answer

    How should a financial services business protect client and financial information? By building coordinated controls across the entire information environment rather than relying on a single product or perimeter.

    A practical approach covers multi-factor authentication, identity lifecycle management, least-privilege access, Microsoft 365 configuration, endpoint security, email protection, application access, secure sharing, information governance, verified backup and recovery, incident readiness, vendor access management and staff awareness.

    The objective is not simply to install security tools. It is to create an environment where sensitive client information is appropriately protected throughout its lifecycle, and where the business can demonstrate that protection to clients, insurers and regulators.

    Understand what information the business holds

    Financial services businesses hold a range of sensitive information. Understanding what you hold — and where it lives — is the first step toward effective protection.

    Identity information

    Client names, dates of birth, driver licences, passports and other identity verification records.

    Contact information

    Addresses, phone numbers, email addresses and emergency contacts.

    Financial information

    Bank account details, superannuation records, investment holdings, loan details and transaction histories.

    Client records

    Advice documents, statements of advice, risk profiles, client correspondence and service records.

    Application information

    Loan applications, insurance applications, credit assessments and supporting documentation.

    Advice and service records

    Advice recommendations, compliance files, review records and ongoing service documentation where relevant.

    Information sensitivity and legal obligations vary according to information type, business activities, applicable legislation, professional obligations, contractual requirements and client circumstances. This page does not provide legal classifications — businesses should obtain professional advice regarding their specific obligations.

    Financial Services Information Exposure Map

    Client information flows across multiple systems. Effective protection requires governance across all of them — not just the perimeter.

    Client & Financial Information
    Email
    Microsoft 365
    CRM
    Advice Systems
    Endpoints
    Client Portals
    Staff Accounts
    External Sharing

    Identity is the security perimeter

    Modern security starts with identity. If an attacker can access a user account, they can often access everything that user can access — including client records, financial information and practice systems.

    Multi-factor authentication

    Enforce MFA across user accounts, with any necessary technical exceptions formally assessed and appropriately controlled.

    Conditional access

    Use conditional access policies where appropriate to restrict access based on location, device, risk and context.

    User lifecycle

    Manage joiners, movers and leavers promptly. Dormant accounts create unnecessary access risk.

    Privileged identities

    Restrict administrative accounts to authorised personnel. Review privileged access regularly.

    Shared accounts

    Avoid shared accounts where practical. Each user should have a uniquely identifiable account.

    Role changes

    Review and adjust access when staff change roles, leave the business or take on new responsibilities.

    Access should follow actual business responsibility

    Financial services businesses should implement least-privilege access so that staff can only see client information relevant to their role. Broad, inherited permissions accumulated over time create unnecessary risk.

    Least privilege

    Each user has only the access they need for their role — no more.

    Role changes

    Review and adjust access when staff change roles or leave the business.

    Sensitive client information

    High-sensitivity client files may require additional access restrictions.

    External users

    Guest access and external sharing should be controlled, time-limited and reviewed.

    Microsoft 365 information security

    Microsoft 365 provides powerful collaboration tools, but permissions require active governance. Microsoft's official documentation details how SharePoint, Teams and OneDrive permissions work — and how they can be configured to reduce oversharing risk.

    SharePoint

    Review site-level permissions, library access and sharing defaults. Avoid broad inheritance where it exceeds business need.

    Teams

    Review Team membership, channel access and guest users. Remove inactive Teams and manage private channels.

    OneDrive

    Review external sharing settings and ensure OneDrive is not used as an uncontrolled document repository.

    Exchange

    Review mail forwarding rules, shared mailboxes and external forwarding to reduce information leakage risk.

    Guest access

    Track guest users, set expiry on guest accounts and review external collaboration regularly.

    Sharing links

    Configure appropriate sharing link defaults. Avoid anonymous links for sensitive information.

    Learn how LOOKUP helps financial services businesses optimise Microsoft 365 →

    Protect information across specialist platforms

    Microsoft 365 is not the only information environment in a financial services business. Specialist platforms — including CRM, advice and practice systems, document platforms, accounting, loan and credit systems, and client portals — also require governance.

    CRM systems

    Review user access, admin roles, API credentials and integration permissions.

    Advice and practice systems

    Review user lifecycle, MFA where supported, and data export controls.

    Document platforms

    Review permissions, sharing settings and retention policies.

    Client portals

    Review authentication, access controls and external sharing defaults.

    Loan and credit systems

    Review user access, audit logging and integration credentials where relevant.

    Other SaaS

    Assess each cloud application for user lifecycle, admin roles, MFA and vendor security.

    Email and impersonation risk

    Email is both a primary collaboration tool and a significant attack surface. Phishing and business email compromise remain among the most common threats facing professional services firms.

    Phishing protection

    Deploy email filtering, anti-phishing policies and staff awareness training.

    Business email compromise

    Implement verification processes for changes to payment details, banking information and client instructions.

    Misdirected email

    Implement delay-send rules or confirmation prompts for external recipients to reduce misdirected email risk.

    Sensitive attachments

    Avoid emailing sensitive attachments where secure sharing alternatives exist.

    Secure alternatives

    Use controlled SharePoint links or client portals instead of email attachments where practical.

    Payment verification

    Establish verification protocols for payment instruction changes received via email.

    Third-party access and supply chain

    Financial services businesses often rely on vendors, contractors, support providers and integrations. Each connection is a potential access point that requires governance.

    Vendors and contractors

    Track who has access, why, and for how long. Remove access when no longer required.

    Support providers

    Review support access, privileged accounts and time-limited access arrangements.

    Integrations

    Review API credentials, service accounts and integration permissions regularly.

    API and service accounts

    Review credentials, rotate where appropriate and remove unused integrations.

    External portals

    Review authentication, access controls and data handling practices.

    Vendor security

    Assess vendor security practices, data handling and contractual terms.

    Information lifecycle

    Information protection should span the entire lifecycle — from creation to disposal.

    Create

    Classify and label information at creation

    Receive

    Route external documents to governed locations

    Use

    Control access during review and processing

    Share

    Use secure, time-limited sharing methods

    Store

    File in governed, permission-controlled locations

    Retain

    Apply retention policies appropriate to the information

    Archive

    Archive completed records with appropriate access

    Dispose

    Dispose of information securely when retention expires

    Retention periods should reflect the firm's legal, regulatory and professional obligations. This page does not prescribe universal retention periods — businesses should obtain professional advice regarding their specific requirements.

    For guidance on structuring the client onboarding journey with secure information collection, see our improving client onboarding and service workflows Business Outcome. For a broader treatment of information architecture, permissions and document governance, see our guide to improving information and document governance in financial services.

    Privacy considerations

    The Office of the Australian Information Commissioner oversees the Privacy Act and the Notifiable Data Breaches scheme. Whether these obligations apply depends on the organisation, the information held and the business activities undertaken.

    Organisations covered by the Notifiable Data Breaches scheme must notify affected individuals and the OAIC when an eligible data breach meets the statutory threshold. Some smaller organisations may also fall within Privacy Act coverage depending on their activities or the information they handle.

    This page provides business technology and governance information and is not legal, privacy or regulatory advice. Businesses should obtain appropriate professional advice regarding their specific privacy obligations.

    APRA requirements: only where applicable

    Some financial-sector entities are APRA regulated — including banks, insurers and superannuation trustees. APRA's prudential standards, including CPS 234 on information security, apply to these specific entity types.

    CPS 234 does not apply to every financial adviser or financial-services business. Many financial advice practices, credit businesses and other professional financial-services firms are not APRA-regulated. Regulatory obligations depend on the entity type, licence held and the activities the business undertakes.

    Confirm your regulatory obligations with appropriate professional advisers. This page does not provide legal or regulatory advice.

    Recovery and incident readiness

    Backup exists does not mean recovery is verified. A business should be able to demonstrate that business-critical information can be recovered within its recovery objectives.

    Critical information

    Identify which information is business-critical and ensure it is included in backup and recovery planning.

    Restore testing

    Test recovery regularly. An untested backup is an assumption, not a capability.

    Separation

    Ensure appropriate separation between production and backup environments.

    Responsibilities

    Clarify responsibilities between cloud platforms and the organisation.

    SaaS considerations

    Assess whether Microsoft 365 and other SaaS platforms meet your recovery objectives.

    Recovery planning

    Document recovery objectives, priorities and procedures. Review after any significant change.

    How this maps to the LOOKUP Business Modernisation Framework™

    Protecting client information is not a one-off project. It follows the same structured approach as every LOOKUP engagement.

    Discover

    Map where sensitive client information lives, who has access and how it is shared.

    Secure

    Strengthen identity, MFA, access controls, endpoint security and recovery capability.

    Modernise

    Address legacy systems and unsupported technology that create security risk.

    Standardise

    Create consistent permissions, sharing policies and information governance practices.

    Optimise

    Improve Microsoft 365 configuration, email security and document workflows.

    Prepare

    Establish governance, policies and staff awareness for AI and future technology.

    Implement

    Deploy security controls, incident response plans and monitoring deliberately.

    Improve

    Review permissions, test recovery, exercise incident response and continuously improve.

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    What success looks like

    Strong information protection creates qualitative business outcomes — not just technical compliance.

    Stronger access control

    Staff can access what they need — and nothing more.

    Better information visibility

    Leadership understands where sensitive information lives and who can access it.

    Clearer ownership

    Security ownership is explicit, not assumed.

    More consistent sharing

    Client collaboration uses governed, secure methods rather than ad-hoc email attachments.

    Better recovery readiness

    Backup and recovery is tested, documented and aligned to business objectives.

    Reduced unnecessary access

    Broad, inherited permissions are reviewed and reduced.

    Stronger information governance

    The business can demonstrate protection to clients, insurers and regulators.

    Research and regulatory context

    The Australian Securities and Investments Commission (ASIC) provides guidance on cyber resilience for financial services licensees. The Australian Prudential Regulation Authority (APRA) publishes prudential standards on information security applicable to APRA-regulated entities.

    The Office of the Australian Information Commissioner oversees the Privacy Act and the Notifiable Data Breaches scheme. The Australian Cyber Security Centre provides the Essential Eight as a recommended baseline for reducing cyber risk.

    Microsoft's official documentation details Microsoft 365 security, compliance and information protection capabilities.

    See how information security connects to AI readiness for financial services businesses →

    For broader guidance on detection, response, recovery and operational resilience, see our guide to strengthening cyber and operational resilience in financial services.

    Illustrative business outcome

    Illustrative Scenario

    This is an illustrative scenario, not a LOOKUP client case study. It reflects common challenges financial services businesses may encounter and demonstrates how a structured technology approach could be applied.

    Business challenge

    A growing financial services practice has accumulated broad permissions across Microsoft 365 and several SaaS platforms. Former users still have access. External sharing is inconsistent. Recovery has not been recently tested. Multiple SaaS systems have unclear recovery responsibility. No clear security ownership exists.

    Structured approach

    Discover where information lives. Secure identity and MFA. Review and reduce permissions. Standardise sharing policies. Assess third-party access. Test recovery. Establish incident response. Assign clear ownership.

    Potential business outcomes

    • • Reduced unnecessary access to sensitive client information
    • • Improved recovery confidence through tested backup procedures
    • • More consistent, governed client collaboration
    • • Clearer security ownership and accountability
    • • Better foundations for responsible AI adoption
    • • Stronger evidence for insurer and regulatory discussions

    Frequently asked questions

    How should financial services businesses protect client information?

    Financial services businesses should protect client information through coordinated controls across identity, access, devices, Microsoft 365, specialist platforms, email, third-party access, backup and recovery, incident response and staff awareness. No single product achieves this — it requires a governed system of controls across the entire information environment.

    Do financial advisers need MFA?

    Multi-factor authentication is one of the most effective controls for reducing unauthorised access. LOOKUP recommends enforcing MFA across user accounts, with any necessary technical exceptions formally assessed and appropriately controlled. Administrative accounts, remote access and cloud services should all be covered.

    How should client files be shared securely?

    Client files should be shared through controlled methods such as governed SharePoint external links with appropriate expiry, authenticated guest access, or dedicated client portals. Anonymous public links should be avoided for sensitive information. Sharing methods should reflect the firm's risk profile, client requirements and information governance policies.

    Is Microsoft 365 secure enough for financial services?

    Microsoft 365 can support strong security when properly configured. Security depends on factors including identity configuration, conditional access, multi-factor authentication, information protection, external sharing settings, administrative roles and ongoing governance. Security is not automatic — it requires deliberate configuration and continuous management.

    Can SharePoint store financial-services information?

    SharePoint can store financial-services information when permissions, sharing settings, retention policies and information protection are properly configured. Firms should review access controls, external sharing defaults and sensitivity labels before storing sensitive client information. Poorly governed SharePoint can create oversharing risk.

    How should access permissions be managed?

    Permissions should follow least-privilege principles, meaning each user has only the access they need for their role. Firms should manage joiners, movers and leavers promptly, review permissions regularly, and reduce broad or inherited access that exceeds legitimate business need.

    What is least privilege?

    Least privilege means giving each user only the access they need to perform their role. For financial services businesses, this means advisers have access to their client files, administrative accounts are restricted to administrators, and broad access is regularly reviewed and reduced where it exceeds legitimate business need.

    How should former employee access be removed?

    Former employee access should be removed promptly through a documented joiner-mover-leaver process. This includes disabling accounts, revoking Microsoft 365 licences, removing SharePoint and Teams access, terminating third-party application access, and reviewing shared mailbox or delegated permissions.

    How should SaaS applications be secured?

    SaaS applications should be secured through individual user accounts (not shared accounts), MFA where supported, regular access reviews, review of administrative roles, assessment of API and integration credentials, and evaluation of vendor security and data handling practices.

    What is business email compromise?

    Business email compromise is a form of attack where cyber criminals impersonate a trusted party — often through compromised or spoofed email accounts — to manipulate payments, redirect funds or extract sensitive information. Verification processes for changes to payment details and client instructions are important controls.

    Do cloud systems need backup?

    Cloud platforms provide infrastructure resilience, but organisations remain responsible for their information. Firms should assess whether their recovery objectives require additional backup capabilities beyond what the cloud platform provides. Recovery should be tested — backup exists does not mean recovery is verified.

    What does CPS 234 apply to?

    CPS 234 is an APRA prudential standard that applies to APRA-regulated entities such as banks, insurers and superannuation trustees. It does not apply to every financial adviser or financial-services business. Regulatory obligations depend on entity type, licence and activities. Confirm your specific obligations with appropriate professional advisers.

    Does CPS 234 apply to every financial adviser?

    No. CPS 234 applies to APRA-regulated entities. Many financial advice practices, credit businesses and other professional financial-services firms are not APRA-regulated. Regulatory obligations depend on the entity type, licence held and the activities the business undertakes.

    How does information security affect AI?

    AI tools such as Microsoft 365 Copilot work within a user's existing permissions. If permissions are broader than intended, AI may make information that a user already has permission to access easier to discover. Reviewing permissions, sharing settings and information governance before AI deployment helps reduce oversharing risk.

    Where should a financial services business start?

    Start by understanding where sensitive client information lives, who has access to it, and how it is shared. Then review MFA coverage, privileged accounts, Microsoft 365 sharing settings, endpoint security and backup recovery. Prioritise the highest-risk gaps first and build a practical improvement roadmap.

    What business leaders should do next

    1.Identify where sensitive client information resides.
    2.Review identity and MFA coverage.
    3.Review administrative privileges and dormant accounts.
    4.Review Microsoft 365 permissions and external sharing.
    5.Review access across specialist platforms and SaaS applications.
    6.Assess backup and recovery — and test it.
    7.Review email security and phishing protection.
    8.Review third-party access and vendor security.
    9.Establish incident response responsibilities.
    10.Review AI usage and information governance.
    11.Create a technology and security improvement roadmap.

    To bring information protection into a coordinated technology strategy, see our guide to building a technology roadmap for a financial services business.

    How LOOKUP can help

    LOOKUP helps financial services businesses strengthen cyber security, improve Microsoft 365 governance and build safer foundations for AI — through practical, business-first technology leadership.

    Sources & Further Reading

    Australian Securities and Investments Commission

    Cyber Security Guidance

    ASIC guidance on cyber resilience and information security for financial services licensees.

    View Source

    Australian Prudential Regulation Authority

    Information Security — CPS 234

    APRA prudential standard on information security applicable to APRA-regulated entities — not universal for all financial services businesses.

    View Source

    Office of the Australian Information Commissioner

    Australian Privacy Principles Guidelines

    Guidance on privacy obligations relevant to client information handling in financial services.

    View Source

    Australian Cyber Security Centre

    Essential Eight Explained

    Recommended baseline of mitigation strategies for reducing cyber risk.

    View Source

    Microsoft

    Microsoft 365 Security Documentation

    Official documentation on Microsoft 365 security, compliance and information protection capabilities.

    View Source

    Office of the Australian Information Commissioner

    Notifiable Data Breaches Scheme

    Guidance on privacy obligations and eligible data breach notification.

    View Source

    Evidence Standard: LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.

    This page provides business technology and governance information and is not legal, privacy, financial, regulatory or compliance advice. Organisations should obtain appropriate professional advice regarding their specific obligations.

    Protecting Client Information Starts with Better Technology Governance

    LOOKUP helps financial services businesses strengthen cyber security, improve Microsoft 365 governance and build safer foundations for AI through practical, business-first technology leadership.

    Avatar
    Hi there! Have a question? Chat with us here.