What the SFC's cybersecurity review found — and where small firms fall short
The SFC's thematic review of cybersecurity across licensed corporations produced an uncomfortable headline: roughly half of the firms reviewed were running end-of-life systems, alongside widespread weaknesses in cloud security. For a smaller fund manager or advisory firm without a dedicated IT department, the findings read less like a scandal and more like a mirror. Here is what the review surfaced, and the gaps we most often find when we assess firms of this size.
What the regulator is now asking for
Circular 25EC7, in effect since February 2025, advises licensed corporations to carry out a comprehensive technical review — including penetration testing — at least annually, and to maintain controls across patching, access, monitoring, third-party risk and incident response. A further circular in June 2026 turned attention to AI-enabled threats, reflecting how quickly phishing and social-engineering attacks are becoming more convincing. The direction of travel is clear: cybersecurity is a standing obligation, reviewed on a cycle, not a one-off box to tick at licensing.
The five gaps we see most often
1. End-of-life systems still in daily use
An old server running an unsupported operating system, or a handful of machines left on a retired version of Windows, is the most common — and most avoidable — finding. Once support ends, security patches stop, and the system becomes a standing invitation. The fix is lifecycle tracking and a planned upgrade before support lapses, not after.
2. Microsoft 365 left on its defaults
Most small firms run Microsoft 365, and most run it exactly as it arrived. Default settings are not the same as secured settings: conditional access, least-privilege admin roles and data-loss prevention all have to be switched on and configured. And Microsoft does not back up your tenant — that is your responsibility.
3. MFA that is "mostly" on
Multi-factor authentication enforced on staff email but not on the administrator accounts, or not on remote access, leaves the highest-value doors unlocked. It needs to be universal — email, remote access and every admin — with periodic access reviews.
4. Backups that have never been tested
A backup you have never restored is a hope, not a control. Ransomware planning assumes you can recover; the only way to know is to test-restore on a schedule and document it.
5. No incident-response plan
When something goes wrong, the difference between a contained incident and an expensive week is whether there is a written plan — who is called, what is isolated, what is reported and when. Most firms discover they don't have one at the worst possible moment.
What "good" looks like for a firm your size
Good does not mean a security operations centre and a six-figure budget. For a 10–50-person financial firm it means: a live asset inventory, no end-of-life systems, patching on an SLA, universal MFA, a hardened and backed-up Microsoft 365 tenant, tested restores, a vendor due-diligence pack, and an incident-response plan that has been rehearsed once. That is an achievable baseline — and it maps directly to what the SFC examines. If you would like to see where you stand today, our two-minute self-check runs through the same ten areas.