Industries

IT built for the audit, not around it.

Managed IT and security for UK financial services firms: IFAs, wealth managers, accountants, payment businesses and fintechs. FCA and ICO requirements treated as the baseline, not the aspiration.

Why financial services?

Because an ordinary MSP will not pass your audit.

Generic managed IT is good enough for most UK SMBs. It is not good enough when your client agreement has an ICO clause, your PI insurer wants a Cyber Essentials Plus certificate, and the FCA can walk in next quarter.

We run the stack every regulated firm eventually lands on. MFA enforced, conditional access, endpoint EDR, email DMARC to reject, DLP on client data, and monitored 24/7 by a real SOC. Then we keep the evidence pack current so audit day is boring.

CEWe hold it. Yearly.
24/7Huntress MDR cover
0Audit findings for our clients
72 hrCritical patch SLA
Audit, ready

Controls your regulator will recognise on sight.

The FCA, PRA and your auditor all want the same things: evidence, segregation, recovery. We bake those controls in from day one and keep the paper trail current.

For Operations
  • Conditional access on every identity
  • Privileged access reviewed quarterly
  • Immutable backups, tested recovery
  • Patching inside 72 hours for criticals
For the Audit
  • Control evidence exported on demand
  • Change logs, access reviews, incident records
  • Board-ready risk and posture reports
  • Mapped to CE+, ISO 27001 and FCA guidance
Request a sample evidence pack

Audit export complete 10:21

Q1 access review, backup verification and change log exported. 0 findings.

Controls in place, continuously enforced
147
Our baseline

What every financial services client runs, by default.

The controls you need, without the business-case debate. Included in the service.

FCA and ICO Ready

MFA, audit logging, endpoint EDR, email DMARC, and DLP configured to the expectations of the FCA SYSC handbook and the ICO accountability principle.

  • MFA and conditional access everywhere
  • Audit logging retained to policy
  • DMARC enforced on your domain
SYSC mapped, not claimed

Data Classification and DLP

Included on the Premium plan. Microsoft Purview sensitivity labels, DLP policies on client data and payment information, automated retention and disposal.

  • Client data labelled at rest and in flight
  • DLP policies matched to your file types
  • Exfiltration blocked, not just logged
Purview labels applied

24/7 Monitored Tenants

Huntress MDR on every endpoint, Microsoft 365 sign-in and mailbox watch, and written incident reports when anything trips the wire.

  • Sign-in and mail flow watched
  • Alerts followed by human analysts
  • Suspicious sessions killed live
24/7 Huntress MDR

Evidence for Audit

Quarterly control evidence packs for ISO 27001, SOC 2, ICO assessments and insurer questionnaires. Zero scramble on audit day.

  • Mapped to ISO 27001 and SOC 2
  • Ready before the auditor asks
  • Written, not reconstructed later
Quarterly evidence packs

Joiner, Mover, Leaver Controls

HR-integrated provisioning. New hires have accounts, laptops and MFA on day one. Leavers are offboarded and audited within the hour.

  • HR-integrated provisioning
  • Accounts and laptops ready on day one
  • Access removed the hour they leave
Same day deprovisioning

Regulated Workstations

Intune-managed laptops with drive encryption, USB control, BitLocker recovery held, and automated patch within 72 hours of release.

  • Intune-managed with BitLocker
  • Removable media locked down
  • Compliance state reported monthly
Encrypted and USB controlled
Client quote

"They passed our insurer questionnaire, our FCA inspection and our SOC 2 audit without a single finding in IT. First time in four years."

Head of Operations, Midlands-based IFA

The checklist

What an FCA-regulated firm has to be able to show.

The controls an auditor, an insurer or the regulator will ask for, and how each one is met on the service.

  • Operational resilience (PS21/3). Important business services mapped, impact tolerances set, and a tested recovery plan behind each. We run the technical side: documented runbooks, rehearsed restores and a recovery time you can put in the self-assessment.
  • Access control and joiners, movers, leavers. Named accounts only, MFA everywhere, conditional access by role, and leavers removed within the hour with an audit trail. The evidence is the log, not a promise.
  • Data retention and legal hold. Retention periods set per system in Microsoft Purview, mailboxes on hold where SMCR or complaints handling requires it, and a defensible deletion schedule for everything else.
  • Third-party and outsourcing oversight (SYSC 8). A written service description, SLA and exit terms, plus the reporting you need to evidence oversight of us as an outsourced provider.
  • Incident response and reporting. A 24/7 SOC, a written incident report in plain English, and the timeline you need for a notification to the FCA or the ICO if one is required.
  • Cyber Essentials Plus. Held by us, and the practical route to it for you: patching within 14 days, supported operating systems only, and every device enrolled and encrypted.
Alignment

Mapped to the frameworks auditors actually check.

FCA SYSCUK GDPR and ICOPCI DSS (if taking card)Cyber Essentials PlusISO 27001 alignment
Free · no slide deck

Audit coming up? Let us walk the controls with you.

30 minutes with our engineer and compliance lead. We will look at your current state against the regulatory baseline and give you a written list of the three things to fix before the inspector arrives.