Quick Answer: The 12 Cybersecurity Controls Financial Firms Should Prioritize
A financial firm should implement at least 12 foundational cybersecurity controls: multi-factor authentication, privileged-account protection, endpoint detection and response, 24/7 threat monitoring, advanced email security, vulnerability and patch management, encryption, secure Microsoft 365 configuration, tested backups, incident-response planning, employee security training, and vendor-risk management.
These controls help protect confidential client information and support obligations associated with SEC, FINRA, GLBA, IRS, PCI DSS, cyber insurance, and other applicable requirements. However, no individual product or checklist automatically makes a firm compliant. Effective compliance also requires written policies, assigned responsibilities, recurring risk assessments, documentation, testing, and management oversight.
Financial organizations can strengthen these areas through a coordinated combination of cybersecurity services, managed IT support, business continuity planning, and industry-specific guidance for CPAs and financial firms.
The 12-Control Financial Firm Cybersecurity Framework
| Control | Primary purpose | Recommended review frequency |
|---|---|---|
| 1. Multi-factor authentication | Reduce unauthorized access when passwords are stolen | Quarterly |
| 2. Privileged-account protection | Limit and monitor powerful administrator access | Quarterly |
| 3. Endpoint detection and response | Detect and contain malicious activity on computers and servers | Continuous |
| 4. 24/7 threat monitoring | Identify and escalate suspicious activity outside business hours | Continuous |
| 5. Advanced email security | Reduce phishing, impersonation, malware, and payment fraud | Continuous |
| 6. Vulnerability and patch management | Identify and correct known security weaknesses | Monthly or more often |
| 7. Encryption | Protect sensitive information at rest and in transit | Annually and after major changes |
| 8. Secure Microsoft 365 configuration | Protect cloud identities, email, documents, and collaboration tools | Quarterly |
| 9. Tested backups | Restore data and systems after ransomware, deletion, or failure | Quarterly restore testing |
| 10. Incident-response planning | Define actions, ownership, escalation, and recovery procedures | At least annually |
| 11. Security awareness training | Reduce human error and improve threat reporting | At onboarding and throughout the year |
| 12. Vendor-risk management | Evaluate third parties that access systems or sensitive information | Annually and before onboarding |
The exact controls, technologies, and review schedule should reflect the firm’s size, data, systems, services, risk profile, contractual obligations, and applicable regulations.
1. Require Multi-Factor Authentication Across Critical Systems
Multi-factor authentication adds a second verification step when an employee signs in. That second factor can help prevent an attacker from accessing an account with a stolen password.
Financial firms should prioritize MFA for:
- Microsoft 365 and business email
- Remote-access systems
- Accounting, tax, payroll, and financial applications
- Cloud storage and document-management systems
- Administrator accounts
- Banking and payment portals
- Backup-management systems
- Cybersecurity tools
MFA should be enforced rather than left optional. The firm should also review whether older authentication methods or unsupported applications can bypass the requirement.
Questions to ask your IT provider
- Which systems currently require MFA?
- Are any users or applications exempt?
- Can older sign-in methods bypass MFA?
- Are administrator accounts subject to stronger controls?
- How are lost or replaced authentication devices handled?
2. Protect Privileged and Administrator Accounts
Administrator accounts can create users, change settings, access data, disable security tools, and alter systems. Because these accounts have elevated capabilities, they should not be used for routine email, web browsing, or daily office work.
A strong privileged-access process should include:
- Separate standard and administrator accounts
- MFA for every privileged account
- Unique credentials for each administrator
- No shared administrator passwords
- Limited access based on job responsibilities
- Logging and review of administrative activity
- Immediate removal of access when roles change
- Emergency access procedures
Quarterly access reviews can help identify former employees, unused accounts, excessive permissions, and access that is no longer necessary.
3. Deploy Endpoint Detection and Response
Traditional antivirus software looks primarily for known malicious files. Endpoint detection and response provides broader visibility into suspicious behavior occurring on workstations, laptops, and servers.
An EDR platform may detect:
- Ransomware behavior
- Malicious scripts
- Unusual account activity
- Unauthorized software
- Credential theft attempts
- Suspicious connections
- Security tools being disabled
The technology is only one part of the control. Alerts must also be reviewed, investigated, escalated, and resolved by qualified personnel.
Questions to ask
- Does every supported device have EDR installed?
- Who monitors alerts?
- What happens after a high-risk alert is generated?
- Can compromised devices be isolated remotely?
- How are missed installations and inactive agents identified?
4. Monitor Threats 24/7
Cyberattacks do not follow normal office hours. A compromised account, malicious email, or ransomware event may begin overnight, during a weekend, or while key employees are unavailable.
Continuous monitoring should cover the systems most relevant to the firm, which may include:
- Endpoints and servers
- Microsoft 365 identities
- Firewalls and networks
- Email security systems
- Cloud applications
- Backup platforms
- Security logs
911 IT’s managed cybersecurity services include round-the-clock threat monitoring and incident response designed to detect and contain suspicious activity before it causes wider damage.
Define escalation before an emergency
The firm and its provider should document:
- Who receives urgent alerts
- Which events qualify as critical
- When accounts or devices may be disabled
- Who can authorize major containment actions
- How legal counsel, insurance carriers, and leadership are contacted
- How incident activity and decisions are documented
5. Strengthen Email Security
Email is a common entry point for phishing, credential theft, ransomware, invoice fraud, and executive impersonation. Financial firms are especially vulnerable because employees regularly exchange sensitive documents, payment instructions, tax information, and client requests.
A layered email-security program should include:
- Phishing and malware filtering
- Impersonation and spoofing protection
- Suspicious-link analysis
- Attachment scanning
- External-sender warnings
- Domain-protection settings
- MFA
- Secure message encryption where appropriate
- A simple method for employees to report suspicious messages
Technology should be reinforced by business procedures. Employees should verify unexpected payment, banking, payroll, password-reset, and document-sharing requests through a separate trusted communication channel.
6. Maintain a Formal Vulnerability and Patch-Management Process
Software vendors regularly release updates that correct known security weaknesses. Attackers often target organizations that delay those updates or continue using unsupported systems.
A structured patch-management process should cover:
- Operating systems
- Web browsers
- Microsoft 365 applications
- Accounting and financial software
- PDF and document tools
- Servers
- Firewalls and network devices
- Remote-access software
- Third-party applications
The process should define how quickly critical, high, medium, and low-risk vulnerabilities are addressed. Emergency vulnerabilities may need remediation much faster than the normal maintenance schedule.
Useful management metrics
- Percentage of devices fully patched
- Number of unresolved critical vulnerabilities
- Average time to remediate high-risk findings
- Number of unsupported devices or applications
- Number of devices missing security agents
7. Encrypt Sensitive Information
Encryption makes protected information unreadable without the appropriate key or authorization. It can reduce exposure when a laptop is lost, a device is stolen, data is intercepted, or a storage system is accessed improperly.
Financial firms should evaluate encryption for:
- Laptop and workstation drives
- Servers and storage systems
- Backups
- Email containing sensitive information
- File transfers
- Mobile devices
- Cloud storage
- Remote connections
Encryption must be managed carefully. Recovery keys, certificates, administrator access, and decryption procedures should be documented and protected.
“My computer is now protected. If anyone steals my computer, the important info will be useless to them.”
8. Secure Microsoft 365 Beyond the Default Configuration
Microsoft 365 may contain some of the firm’s most sensitive information, including email, attachments, contracts, tax records, internal discussions, and client documents. Default settings do not necessarily reflect the organization’s security needs.
A secure Microsoft 365 baseline should address:
- Mandatory MFA
- Conditional Access
- Administrator-role restrictions
- Sign-in risk monitoring
- Email threat protection
- External file sharing
- Mobile-device access
- Employee onboarding and offboarding
- Data retention
- Audit logging
- Inactive and guest accounts
- Cloud backup and recovery needs
911 IT’s cloud services include Microsoft 365 management, secure remote access, cloud storage, and related support.
Review access when employees change roles
Employee departures and role changes create risk when accounts, shared mailboxes, cloud files, mobile devices, and application access are not updated promptly. A documented onboarding and offboarding checklist should assign responsibility for each action.
9. Maintain Protected Backups and Test Recovery
Backups are a critical defense against ransomware, accidental deletion, hardware failure, and other disruptions. However, a successful backup notification does not prove that the organization can recover.
A complete backup strategy should define:
- Which data and systems are protected
- How often backups occur
- Where backup copies are stored
- How copies are protected from alteration or deletion
- How long data is retained
- How quickly important systems must be restored
- Who approves recovery priorities
- How often restore testing is performed
For critical systems, conduct documented recovery tests at least quarterly or according to the firm’s risk and operational requirements.
| Backup question | Why it matters |
|---|---|
| What is backed up? | Unprotected cloud data or business applications may be overlooked |
| How frequently? | The interval determines how much recent work could be lost |
| Is a copy isolated? | Ransomware may attempt to encrypt or delete connected backups |
| When was recovery tested? | Testing proves that data can be restored |
| How long will recovery take? | Leadership needs realistic expectations for downtime |
Learn more about secure backups and recovery through 911 IT’s business continuity services.
10. Create and Test an Incident-Response Plan
An incident-response plan explains what the organization will do when a security event occurs. It should be written before the emergency and tested with the people who will use it.
The plan should cover at least six phases:
- Preparation: Define responsibilities, contact information, tools, vendors, and decision authority.
- Detection: Identify suspicious events and determine whether an incident has occurred.
- Containment: Limit access, isolate affected systems, and prevent further damage.
- Investigation: Determine what happened, what was affected, and what evidence should be preserved.
- Recovery: Restore systems safely, reset access, monitor for recurrence, and resume operations.
- Post-incident review: Document lessons learned and improve safeguards, training, and procedures.
Include contact information for leadership, IT support, cybersecurity specialists, legal counsel, insurance carriers, compliance personnel, law enforcement, and other relevant parties.
Conduct a tabletop exercise
At least annually, walk through a realistic scenario such as:
- A compromised Microsoft 365 account
- A fraudulent wire-transfer request
- Ransomware on a server
- A lost laptop containing sensitive information
- A third-party vendor breach
The exercise should identify unclear responsibilities, missing contact information, unavailable backups, communication gaps, and decisions that have not been assigned in advance.
11. Train Employees Throughout the Year
Employees routinely make decisions that affect cybersecurity. They open attachments, approve payments, share files, create passwords, use mobile devices, and communicate with clients and vendors.
An effective awareness program should include:
- Training during onboarding
- Short recurring lessons throughout the year
- Phishing simulations
- Guidance for reporting suspicious messages
- Education about payment and executive impersonation
- Password and MFA guidance
- Remote-work and mobile-device practices
- Secure handling of client information
- Targeted follow-up for higher-risk users
Track completion and improvement rather than treating training as a checkbox. Useful measures include the percentage of employees completing training, phishing-reporting rates, simulation results, and the time required to report suspicious activity.
12. Manage Third-Party and Vendor Risk
Financial firms often rely on software vendors, cloud platforms, payment processors, document services, consultants, and outsourced providers. A weakness at one of those organizations can create risk for the firm.
Before providing a vendor with access to systems or sensitive data, review:
- The information the vendor will access
- The systems the vendor can connect to
- Security controls and MFA requirements
- Encryption practices
- Incident-notification obligations
- Data retention and deletion
- Use of subcontractors
- Backup and recovery capabilities
- Insurance and contractual protections
- Procedures for removing access when the relationship ends
Maintain an inventory of critical vendors and reassess them at least annually or whenever their services, ownership, access, or security posture changes.
How These Controls Support SEC, FINRA, and GLBA Expectations
Although specific obligations vary, financial-sector security requirements commonly emphasize several recurring principles:
| Common expectation | Controls that help support it |
|---|---|
| Protect customer and client information | Access controls, MFA, encryption, endpoint security, email security, and secure cloud configuration |
| Identify and manage risk | Risk assessments, vulnerability management, vendor reviews, and strategic planning |
| Detect suspicious activity | EDR, centralized monitoring, logging, and alert escalation |
| Respond to security incidents | Incident-response plans, containment procedures, contact lists, and tabletop exercises |
| Maintain business continuity | Protected backups, restore testing, recovery objectives, and disaster-recovery planning |
| Train employees | Security awareness, phishing simulations, and documented completion |
| Oversee service providers | Vendor inventories, due diligence, contracts, access reviews, and recurring reassessment |
| Demonstrate oversight | Policies, reports, meeting records, risk registers, test results, and remediation tracking |
Your firm should work with qualified legal and compliance professionals to interpret its specific obligations. An IT provider can help implement technical safeguards and organize supporting evidence, but it should not replace legal advice.
Do You Need a Written Information Security Plan?
A written information security plan, often called a WISP, documents how the organization protects sensitive information and manages security responsibilities.
A practical WISP may include:
- The types of sensitive information the firm handles
- Assigned security roles and responsibilities
- Risk-assessment procedures
- Access-control requirements
- Employee training expectations
- Incident-response procedures
- Backup and recovery requirements
- Vendor-management procedures
- Physical safeguards
- Review and update schedules
Review 911 IT’s overview of what a written information security plan is and how it supports a structured security program.
Common Cybersecurity Gaps Found in Financial Firms
- MFA is not enforced for every user. Optional enrollment leaves unprotected accounts.
- Administrator accounts are shared. Shared credentials reduce accountability and increase risk.
- Former employees retain access. Incomplete offboarding can leave accounts, files, and applications exposed.
- Microsoft 365 uses default settings. Important identity, email, and sharing protections may not be configured.
- Backups have never been restored. The firm knows backup jobs ran but cannot confirm recovery.
- Employees receive training only once a year. Long gaps reduce awareness of current threats.
- Critical vulnerabilities remain unresolved. Delayed patching creates avoidable exposure.
- The incident-response plan is outdated or missing. Employees do not know who to contact or what actions to take.
- Vendor access is not reviewed. Third parties may retain unnecessary permissions.
- Security reports are not reviewed by leadership. Technical findings remain disconnected from business decisions.
A 90-Day Cybersecurity Improvement Roadmap
Days 1–30: Assess and Prioritize
- Inventory users, devices, systems, applications, and vendors
- Review Microsoft 365 security settings
- Identify missing MFA and excessive access
- Evaluate endpoint and email protection
- Review patch and vulnerability status
- Confirm what is backed up
- Examine existing policies and incident procedures
- Create a prioritized risk register
Days 31–60: Correct High-Risk Gaps
- Enforce MFA
- Separate administrator accounts
- Deploy or validate EDR
- Strengthen email security
- Correct critical vulnerabilities
- Remove unused accounts and access
- Protect backup systems
- Update employee onboarding and offboarding procedures
Days 61–90: Test and Document
- Conduct a backup restore test
- Run a phishing simulation
- Complete an incident-response tabletop exercise
- Document security roles and escalation contacts
- Update the WISP and related procedures
- Review critical vendors
- Present progress and remaining risks to leadership
- Set quarterly review dates
Seven Metrics Leadership Should Review
| Metric | Suggested objective |
|---|---|
| MFA coverage | 100% of applicable accounts |
| Critical vulnerability remediation | Within the firm’s documented risk-based deadline |
| Security-agent coverage | 100% of supported endpoints |
| Backup restore success | Successful documented tests according to schedule |
| Training completion | 100% of active employees |
| Phishing reporting | Increasing employee reporting and decreasing risky behavior |
| Incident response readiness | Current plan, contact list, and completed annual exercise |
Metrics should help leadership understand risk and progress. They should not become superficial targets that encourage teams to hide unresolved problems.
What Financial Clients Say About 911 IT
“They’ve helped us implement and maintain backend network protocols and compliance measures that are far beyond our technical understanding.”
“It’s clear they understand our industry and the security standards required to keep client data safe.”
Other financial-industry clients describe 911 IT as responsive, proactive, knowledgeable, and willing to follow through until problems are fully resolved. One client specifically reported that a security audit helped identify and correct security weaknesses and said the information was worth significantly more than the cost of the assessment.
Why Financial Firms Work With 911 IT
911 IT helps financial organizations improve security through:
- 24/7 access to cybersecurity and IT expertise
- Continuous threat monitoring and incident response
- Endpoint, email, firewall, and network security
- Microsoft 365 and cloud management
- Encryption and secure backup solutions
- Business continuity and disaster-recovery planning
- Employee security awareness training
- Compliance-focused technical safeguards
- Written information security planning
- Proactive monitoring, maintenance, and strategic reviews
Explore 911 IT’s cybersecurity services, business continuity services, and specialized IT support for CPAs and financial firms.
Take One Action This Week
Ask your IT provider for a one-page report showing:
- The percentage of users protected by MFA
- The percentage of devices covered by endpoint security
- The number of unresolved critical vulnerabilities
- The date and result of the most recent backup restore test
- The date of the most recent incident-response exercise
If the provider cannot produce this information, your firm may not have enough visibility to evaluate whether its safeguards are operating effectively.
Schedule a Cybersecurity Assessment for Your Financial Firm
A useful cybersecurity assessment should identify your current safeguards, reveal important gaps, prioritize remediation, and create a practical improvement roadmap. It should not rely on fear, vague compliance claims, or a one-size-fits-all product bundle.
Schedule a discovery call with 911 IT to discuss your firm’s users, systems, Microsoft 365 environment, sensitive information, regulatory concerns, backup strategy, and current security controls.
