Protecting Client and Financial Information in a Financial Services Business
Financial services businesses depend on trust. Protecting client and financial information requires coordinated controls across identity, access, devices, Microsoft 365, specialist platforms, email, third parties, recovery and people — not a single security product.
The two-minute answer
How should a financial services business protect client and financial information? By building coordinated controls across the entire information environment rather than relying on a single product or perimeter.
A practical approach covers multi-factor authentication, identity lifecycle management, least-privilege access, Microsoft 365 configuration, endpoint security, email protection, application access, secure sharing, information governance, verified backup and recovery, incident readiness, vendor access management and staff awareness.
The objective is not simply to install security tools. It is to create an environment where sensitive client information is appropriately protected throughout its lifecycle, and where the business can demonstrate that protection to clients, insurers and regulators.
Understand what information the business holds
Financial services businesses hold a range of sensitive information. Understanding what you hold — and where it lives — is the first step toward effective protection.
Identity information
Client names, dates of birth, driver licences, passports and other identity verification records.
Contact information
Addresses, phone numbers, email addresses and emergency contacts.
Financial information
Bank account details, superannuation records, investment holdings, loan details and transaction histories.
Client records
Advice documents, statements of advice, risk profiles, client correspondence and service records.
Application information
Loan applications, insurance applications, credit assessments and supporting documentation.
Advice and service records
Advice recommendations, compliance files, review records and ongoing service documentation where relevant.
Information sensitivity and legal obligations vary according to information type, business activities, applicable legislation, professional obligations, contractual requirements and client circumstances. This page does not provide legal classifications — businesses should obtain professional advice regarding their specific obligations.
Client information flows across multiple systems. Effective protection requires governance across all of them — not just the perimeter.
Identity is the security perimeter
Modern security starts with identity. If an attacker can access a user account, they can often access everything that user can access — including client records, financial information and practice systems.
Multi-factor authentication
Enforce MFA across user accounts, with any necessary technical exceptions formally assessed and appropriately controlled.
Conditional access
Use conditional access policies where appropriate to restrict access based on location, device, risk and context.
User lifecycle
Manage joiners, movers and leavers promptly. Dormant accounts create unnecessary access risk.
Privileged identities
Restrict administrative accounts to authorised personnel. Review privileged access regularly.
Shared accounts
Avoid shared accounts where practical. Each user should have a uniquely identifiable account.
Role changes
Review and adjust access when staff change roles, leave the business or take on new responsibilities.
Access should follow actual business responsibility
Financial services businesses should implement least-privilege access so that staff can only see client information relevant to their role. Broad, inherited permissions accumulated over time create unnecessary risk.
Least privilege
Each user has only the access they need for their role — no more.
Role changes
Review and adjust access when staff change roles or leave the business.
Sensitive client information
High-sensitivity client files may require additional access restrictions.
External users
Guest access and external sharing should be controlled, time-limited and reviewed.
Microsoft 365 information security
Microsoft 365 provides powerful collaboration tools, but permissions require active governance. Microsoft's official documentation details how SharePoint, Teams and OneDrive permissions work — and how they can be configured to reduce oversharing risk.
SharePoint
Review site-level permissions, library access and sharing defaults. Avoid broad inheritance where it exceeds business need.
Teams
Review Team membership, channel access and guest users. Remove inactive Teams and manage private channels.
OneDrive
Review external sharing settings and ensure OneDrive is not used as an uncontrolled document repository.
Exchange
Review mail forwarding rules, shared mailboxes and external forwarding to reduce information leakage risk.
Guest access
Track guest users, set expiry on guest accounts and review external collaboration regularly.
Sharing links
Configure appropriate sharing link defaults. Avoid anonymous links for sensitive information.
Learn how LOOKUP helps financial services businesses optimise Microsoft 365 →
Protect information across specialist platforms
Microsoft 365 is not the only information environment in a financial services business. Specialist platforms — including CRM, advice and practice systems, document platforms, accounting, loan and credit systems, and client portals — also require governance.
CRM systems
Review user access, admin roles, API credentials and integration permissions.
Advice and practice systems
Review user lifecycle, MFA where supported, and data export controls.
Document platforms
Review permissions, sharing settings and retention policies.
Client portals
Review authentication, access controls and external sharing defaults.
Loan and credit systems
Review user access, audit logging and integration credentials where relevant.
Other SaaS
Assess each cloud application for user lifecycle, admin roles, MFA and vendor security.
Email and impersonation risk
Email is both a primary collaboration tool and a significant attack surface. Phishing and business email compromise remain among the most common threats facing professional services firms.
Phishing protection
Deploy email filtering, anti-phishing policies and staff awareness training.
Business email compromise
Implement verification processes for changes to payment details, banking information and client instructions.
Misdirected email
Implement delay-send rules or confirmation prompts for external recipients to reduce misdirected email risk.
Sensitive attachments
Avoid emailing sensitive attachments where secure sharing alternatives exist.
Secure alternatives
Use controlled SharePoint links or client portals instead of email attachments where practical.
Payment verification
Establish verification protocols for payment instruction changes received via email.
Third-party access and supply chain
Financial services businesses often rely on vendors, contractors, support providers and integrations. Each connection is a potential access point that requires governance.
Vendors and contractors
Track who has access, why, and for how long. Remove access when no longer required.
Support providers
Review support access, privileged accounts and time-limited access arrangements.
Integrations
Review API credentials, service accounts and integration permissions regularly.
API and service accounts
Review credentials, rotate where appropriate and remove unused integrations.
External portals
Review authentication, access controls and data handling practices.
Vendor security
Assess vendor security practices, data handling and contractual terms.
Information lifecycle
Information protection should span the entire lifecycle — from creation to disposal.
Create
Classify and label information at creation
Receive
Route external documents to governed locations
Use
Control access during review and processing
Share
Use secure, time-limited sharing methods
Store
File in governed, permission-controlled locations
Retain
Apply retention policies appropriate to the information
Archive
Archive completed records with appropriate access
Dispose
Dispose of information securely when retention expires
Retention periods should reflect the firm's legal, regulatory and professional obligations. This page does not prescribe universal retention periods — businesses should obtain professional advice regarding their specific requirements.
For guidance on structuring the client onboarding journey with secure information collection, see our improving client onboarding and service workflows Business Outcome. For a broader treatment of information architecture, permissions and document governance, see our guide to improving information and document governance in financial services.
Privacy considerations
The Office of the Australian Information Commissioner oversees the Privacy Act and the Notifiable Data Breaches scheme. Whether these obligations apply depends on the organisation, the information held and the business activities undertaken.
Organisations covered by the Notifiable Data Breaches scheme must notify affected individuals and the OAIC when an eligible data breach meets the statutory threshold. Some smaller organisations may also fall within Privacy Act coverage depending on their activities or the information they handle.
This page provides business technology and governance information and is not legal, privacy or regulatory advice. Businesses should obtain appropriate professional advice regarding their specific privacy obligations.
APRA requirements: only where applicable
Some financial-sector entities are APRA regulated — including banks, insurers and superannuation trustees. APRA's prudential standards, including CPS 234 on information security, apply to these specific entity types.
CPS 234 does not apply to every financial adviser or financial-services business. Many financial advice practices, credit businesses and other professional financial-services firms are not APRA-regulated. Regulatory obligations depend on the entity type, licence held and the activities the business undertakes.
Confirm your regulatory obligations with appropriate professional advisers. This page does not provide legal or regulatory advice.
Recovery and incident readiness
Backup exists does not mean recovery is verified. A business should be able to demonstrate that business-critical information can be recovered within its recovery objectives.
Critical information
Identify which information is business-critical and ensure it is included in backup and recovery planning.
Restore testing
Test recovery regularly. An untested backup is an assumption, not a capability.
Separation
Ensure appropriate separation between production and backup environments.
Responsibilities
Clarify responsibilities between cloud platforms and the organisation.
SaaS considerations
Assess whether Microsoft 365 and other SaaS platforms meet your recovery objectives.
Recovery planning
Document recovery objectives, priorities and procedures. Review after any significant change.
How this maps to the LOOKUP Business Modernisation Framework™
Protecting client information is not a one-off project. It follows the same structured approach as every LOOKUP engagement.
Discover
Map where sensitive client information lives, who has access and how it is shared.
Secure
Strengthen identity, MFA, access controls, endpoint security and recovery capability.
Modernise
Address legacy systems and unsupported technology that create security risk.
Standardise
Create consistent permissions, sharing policies and information governance practices.
Optimise
Improve Microsoft 365 configuration, email security and document workflows.
Prepare
Establish governance, policies and staff awareness for AI and future technology.
Implement
Deploy security controls, incident response plans and monitoring deliberately.
Improve
Review permissions, test recovery, exercise incident response and continuously improve.
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
What success looks like
Strong information protection creates qualitative business outcomes — not just technical compliance.
Stronger access control
Staff can access what they need — and nothing more.
Better information visibility
Leadership understands where sensitive information lives and who can access it.
Clearer ownership
Security ownership is explicit, not assumed.
More consistent sharing
Client collaboration uses governed, secure methods rather than ad-hoc email attachments.
Better recovery readiness
Backup and recovery is tested, documented and aligned to business objectives.
Reduced unnecessary access
Broad, inherited permissions are reviewed and reduced.
Stronger information governance
The business can demonstrate protection to clients, insurers and regulators.
Research and regulatory context
The Australian Securities and Investments Commission (ASIC) provides guidance on cyber resilience for financial services licensees. The Australian Prudential Regulation Authority (APRA) publishes prudential standards on information security applicable to APRA-regulated entities.
The Office of the Australian Information Commissioner oversees the Privacy Act and the Notifiable Data Breaches scheme. The Australian Cyber Security Centre provides the Essential Eight as a recommended baseline for reducing cyber risk.
Microsoft's official documentation details Microsoft 365 security, compliance and information protection capabilities.
See how information security connects to AI readiness for financial services businesses →
For broader guidance on detection, response, recovery and operational resilience, see our guide to strengthening cyber and operational resilience in financial services.
Illustrative business outcome
This is an illustrative scenario, not a LOOKUP client case study. It reflects common challenges financial services businesses may encounter and demonstrates how a structured technology approach could be applied.
Business challenge
A growing financial services practice has accumulated broad permissions across Microsoft 365 and several SaaS platforms. Former users still have access. External sharing is inconsistent. Recovery has not been recently tested. Multiple SaaS systems have unclear recovery responsibility. No clear security ownership exists.
Structured approach
Discover where information lives. Secure identity and MFA. Review and reduce permissions. Standardise sharing policies. Assess third-party access. Test recovery. Establish incident response. Assign clear ownership.
Potential business outcomes
- • Reduced unnecessary access to sensitive client information
- • Improved recovery confidence through tested backup procedures
- • More consistent, governed client collaboration
- • Clearer security ownership and accountability
- • Better foundations for responsible AI adoption
- • Stronger evidence for insurer and regulatory discussions
Frequently asked questions
How should financial services businesses protect client information?
Financial services businesses should protect client information through coordinated controls across identity, access, devices, Microsoft 365, specialist platforms, email, third-party access, backup and recovery, incident response and staff awareness. No single product achieves this — it requires a governed system of controls across the entire information environment.
Do financial advisers need MFA?
Multi-factor authentication is one of the most effective controls for reducing unauthorised access. LOOKUP recommends enforcing MFA across user accounts, with any necessary technical exceptions formally assessed and appropriately controlled. Administrative accounts, remote access and cloud services should all be covered.
How should client files be shared securely?
Client files should be shared through controlled methods such as governed SharePoint external links with appropriate expiry, authenticated guest access, or dedicated client portals. Anonymous public links should be avoided for sensitive information. Sharing methods should reflect the firm's risk profile, client requirements and information governance policies.
Is Microsoft 365 secure enough for financial services?
Microsoft 365 can support strong security when properly configured. Security depends on factors including identity configuration, conditional access, multi-factor authentication, information protection, external sharing settings, administrative roles and ongoing governance. Security is not automatic — it requires deliberate configuration and continuous management.
Can SharePoint store financial-services information?
SharePoint can store financial-services information when permissions, sharing settings, retention policies and information protection are properly configured. Firms should review access controls, external sharing defaults and sensitivity labels before storing sensitive client information. Poorly governed SharePoint can create oversharing risk.
How should access permissions be managed?
Permissions should follow least-privilege principles, meaning each user has only the access they need for their role. Firms should manage joiners, movers and leavers promptly, review permissions regularly, and reduce broad or inherited access that exceeds legitimate business need.
What is least privilege?
Least privilege means giving each user only the access they need to perform their role. For financial services businesses, this means advisers have access to their client files, administrative accounts are restricted to administrators, and broad access is regularly reviewed and reduced where it exceeds legitimate business need.
How should former employee access be removed?
Former employee access should be removed promptly through a documented joiner-mover-leaver process. This includes disabling accounts, revoking Microsoft 365 licences, removing SharePoint and Teams access, terminating third-party application access, and reviewing shared mailbox or delegated permissions.
How should SaaS applications be secured?
SaaS applications should be secured through individual user accounts (not shared accounts), MFA where supported, regular access reviews, review of administrative roles, assessment of API and integration credentials, and evaluation of vendor security and data handling practices.
What is business email compromise?
Business email compromise is a form of attack where cyber criminals impersonate a trusted party — often through compromised or spoofed email accounts — to manipulate payments, redirect funds or extract sensitive information. Verification processes for changes to payment details and client instructions are important controls.
Do cloud systems need backup?
Cloud platforms provide infrastructure resilience, but organisations remain responsible for their information. Firms should assess whether their recovery objectives require additional backup capabilities beyond what the cloud platform provides. Recovery should be tested — backup exists does not mean recovery is verified.
What does CPS 234 apply to?
CPS 234 is an APRA prudential standard that applies to APRA-regulated entities such as banks, insurers and superannuation trustees. It does not apply to every financial adviser or financial-services business. Regulatory obligations depend on entity type, licence and activities. Confirm your specific obligations with appropriate professional advisers.
Does CPS 234 apply to every financial adviser?
No. CPS 234 applies to APRA-regulated entities. Many financial advice practices, credit businesses and other professional financial-services firms are not APRA-regulated. Regulatory obligations depend on the entity type, licence held and the activities the business undertakes.
How does information security affect AI?
AI tools such as Microsoft 365 Copilot work within a user's existing permissions. If permissions are broader than intended, AI may make information that a user already has permission to access easier to discover. Reviewing permissions, sharing settings and information governance before AI deployment helps reduce oversharing risk.
Where should a financial services business start?
Start by understanding where sensitive client information lives, who has access to it, and how it is shared. Then review MFA coverage, privileged accounts, Microsoft 365 sharing settings, endpoint security and backup recovery. Prioritise the highest-risk gaps first and build a practical improvement roadmap.
What business leaders should do next
To bring information protection into a coordinated technology strategy, see our guide to building a technology roadmap for a financial services business.
Executive guides
Business Modernisation Framework™
The eight-stage methodology guiding every LOOKUP engagement.
Business Technology Roadmap
Build a practical technology roadmap aligned with long-term business goals.
AI Governance
Practical guidance for responsible AI adoption, policies and oversight.
Cyber Insurance Readiness
Strengthen cyber maturity before insurance renewal discussions.
Preparing for AI
Governance, information and security foundations for AI adoption.
Financial Services Industry Page
Technology services designed for financial services businesses.
How LOOKUP can help
LOOKUP helps financial services businesses strengthen cyber security, improve Microsoft 365 governance and build safer foundations for AI — through practical, business-first technology leadership.
Sources & Further Reading
Australian Securities and Investments Commission
Cyber Security Guidance
ASIC guidance on cyber resilience and information security for financial services licensees.
View SourceAustralian Prudential Regulation Authority
Information Security — CPS 234
APRA prudential standard on information security applicable to APRA-regulated entities — not universal for all financial services businesses.
View SourceOffice of the Australian Information Commissioner
Australian Privacy Principles Guidelines
Guidance on privacy obligations relevant to client information handling in financial services.
View SourceAustralian Cyber Security Centre
Essential Eight Explained
Recommended baseline of mitigation strategies for reducing cyber risk.
View SourceMicrosoft
Microsoft 365 Security Documentation
Official documentation on Microsoft 365 security, compliance and information protection capabilities.
View SourceOffice of the Australian Information Commissioner
Notifiable Data Breaches Scheme
Guidance on privacy obligations and eligible data breach notification.
View SourceEvidence Standard: LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.
This page provides business technology and governance information and is not legal, privacy, financial, regulatory or compliance advice. Organisations should obtain appropriate professional advice regarding their specific obligations.
Protecting Client Information Starts with Better Technology Governance
LOOKUP helps financial services businesses strengthen cyber security, improve Microsoft 365 governance and build safer foundations for AI through practical, business-first technology leadership.