A handshake across a meeting table

IT security for asset managers and financial firms

Requirements built for large institutions, a team of five, outsourced IT and full responsibility anyway. Where we start at Swiss financial firms.

A laptop and a coffee cup on a desk

Financial services

Book a conversation

The situation

Since the Financial Institutions Act, independent asset managers and trustees are supervised by FINMA as well. Most of them are micro-businesses with fewer than five full-time positions.

These firms have to meet expectations on operational risk and outsourcing that were written for institutions with their own staff functions. What is a department at a bank is an extra job for someone at an asset manager whose actual work is looking after clients.

Then there is a second reviewer many underestimate: custodian banks run their own due diligence on the asset managers they work with, with their own questionnaires and their own deadlines. Failing there risks the business relationship, not just a finding.

And the most expensive point of attack is not technical, it is procedural. Payment approvals run over mail and phone, often under time pressure. In the FBI IC3 2025 annual report, business email compromise was the second costliest fraud category overall, with around USD 3 billion in reported losses across 24,768 complaints.

What we find in this industry

  • Requirements built for large institutions, a team of fiveWhat is a staff function at a bank is an extra job for someone whose actual work is looking after clients. The requirement does not scale down with headcount, the team does.
  • The IT is outsourced, the responsibility is notAn external provider runs the systems. Towards the regulator, the custodian bank and your clients you are still the one answering. Outsourcing moves the work, not the accountability.
  • Payment approvals run over mail and phoneThat is exactly where payment fraud starts. A binding call-back rule to a pre-registered number is the single most effective measure in this business and costs no licence.
  • The custodian bank reviews you with its own questionnaireOn top of the regulator and the audit firm comes a third audience with its own deadlines. Without reusable evidence every request becomes a special project that blocks half the firm.
  • Compliance costs grow with nobody saying when it is enoughWithout a reference frame, every new requirement is answered with another tool or another mandate. A maturity picture ends that spiral because it shows what is already covered.
  • Discretion is the actual productAn incident that becomes public rarely costs systems, it costs mandates. So what counts here is not only defence but also a rehearsed process for the day it happens.

Typical trigger

The custodian bank or the auditor asks for evidence on IT security and outsourcing and there is nobody inside who can produce it. Or a payment fraud attempt was stopped only just in time.

The ODCUS difference

No selling of additional tools. The first step is always: what do you already have, what of it works, and what can we cut? Most mandates start by reducing cost and improving protection at the same time.

Why these services fit

ISMS & ISO 27001

Built once, it serves all three audiences

Regulator, custodian bank and clients ask essentially the same things in different formats. An ISMS delivers the evidence in a structured, reusable form, including an outsourcing and supplier register.

Every further request becomes routine instead of a special project. That is the real time saving, not the certificate.

Interim & Fractional CISO

Due care that is documented and provable

We take on the named security responsibility and deliver reporting in business language for the board, auditors and the regulator.

That includes the things small institutions most often fall down on: payment approval processes, vetting of IT providers, and an incident plan that actually exists.

Security Assessment with Implementation

Know where you stand before the next budget is signed

A fixed-price assessment shows where you sit against recognised frameworks and which measures actually have an effect.

That is the basis for capping compliance spend instead of rolling it forward every year.

Security Management & Operations

The provider is managed, not just contracted

We review the IT partner in a structured way, fix requirements contractually and check whether they are met.

That turns an outsourcing arrangement into a relationship you can steer and defend in an audit.

Who it is for

  • Independent asset managers and trustees under FINMA supervision
  • Small and mid-sized financial firms with outsourced IT
  • Institutions whose custodian bank asks for security evidence
  • Firms where payment approvals run over mail and phone

Related engagements

Anonymised looks at real engagements. Not all of them come from this industry, but the task is the same.

FAQ

Our IT is fully outsourced. Do we still need something of our own?

Yes. The provider runs the systems, but the duty to select, instruct and monitor stays with you. Auditors do not ask who operates the servers, they ask how you make sure the provider does what was agreed.

Do we need ISO 27001 for FINMA?

No, the regulator does not require any particular certificate. The value is that an ISMS orders the evidence once that regulator, custodian bank and clients would otherwise request separately.

How do we actually protect ourselves against payment fraud?

The most effective lever is a binding call-back rule to a pre-registered number, combined with a clear rule that urgency is never a reason to skip it. That is process work, not a software question.

There are five of us. Is a mandate even worth it?

Especially then. With five people there is no capacity to learn this on the side. A mandate of a few days a month is usually cheaper than the internal time spent on questionnaires and research.

Let us talk about your situation

Thirty minutes, free and without obligation. We tell you honestly whether and where we can help.