Back to all resources
guide

IT Support for Financial Services Firms: A Security and Compliance Checklist for Ontario Advisors, Dealers and Brokers

October 9, 2026
9 min read
IT Rapid Support Team
IT Support for Financial Services Firms: A Security and Compliance Checklist for Ontario Advisors, Dealers and Brokers

IT support for financial services firms has to do two jobs at once: keep advisors, planners and administrators working every hour the markets and clients need them, and protect client financial data well enough that you can prove it to a regulator, a dealer, a carrier or an insurer. In practice that means a helpdesk that knows your planning, CRM and custodian tools, multi-factor authentication on every account, encrypted and managed devices, an enforcing DMARC policy and a call-back rule against wire fraud, records kept for as long as your obligations require, tested backups, and written evidence of all of it. The checklist below covers each of those, in the order most firms should tackle them.

It is written for principals, branch and operations managers, chief compliance officers and the person who ends up owning technology at independent advisory and wealth practices, mutual fund and investment dealer branches, insurance agencies, mortgage brokerages and small lenders in Ontario. It is written by IT Rapid Support, a managed IT and cybersecurity provider at 7810 Keele St in Vaughan, so read it with that in mind; the checklist applies whoever runs your IT. It is not legal or compliance advice, and your compliance officer has the final word on what your firm must do.

Who Sets the Rules for Your Firm

The security expectations a financial firm answers to depend on what kind of firm it is. In plain terms:

  • Investment dealers and mutual fund dealers are members of CIRO, the Canadian Investment Regulatory Organization, whose rules include cybersecurity expectations and the reporting of cybersecurity incidents.
  • Portfolio managers, exempt market dealers and investment fund managers are registered with the Ontario Securities Commission, and the Canadian Securities Administrators have published staff guidance on cybersecurity for registrants.
  • Mortgage brokerages, insurance agents and credit unions in Ontario are licensed or regulated by FSRA, the Financial Services Regulatory Authority of Ontario.
  • Banks, federally regulated insurers and trust and loan companies fall under OSFI, whose Guideline B-13 on technology and cyber risk sets detailed expectations. Smaller firms are not bound by it directly, but security questionnaires from the institutions you work with are often shaped by it.
  • Reporting entities under Canada's anti-money-laundering law, which include securities dealers, life insurance agents and mortgage brokers, have record-keeping obligations with FINTRAC, generally for at least five years.
  • Almost every private-sector firm handles client personal information under PIPEDA, which requires safeguards suited to the sensitivity of the data, breach reporting to the Privacy Commissioner of Canada when there is a real risk of significant harm, and a record of every breach kept for 24 months.

Which of these applies, and exactly how, is a question for your compliance officer and counsel. The job of IT support is the technology underneath: controls that are actually switched on, records that are actually kept, and evidence you can produce on request.

1. Accounts and Multi-Factor Authentication

  • Every person has their own account. No shared logins for the front desk, the assistant or the branch, including on custodian, carrier and lender portals.
  • Multi-factor authentication is enforced, not just offered, on email, Microsoft 365 or Google Workspace, the CRM, planning software, custodian and carrier portals, banking, the VPN and every admin account. Prefer an authenticator app or a security key over text messages for administrators.
  • Admin rights are held by as few people as possible, in separate admin accounts that are not used for everyday email.
  • Access follows the role. An assistant who books meetings does not need trading or money-movement permissions, and a licensed representative sees the client files they serve.
  • Leavers lose access on their last day: mailbox, CRM, portals, phones and any device that holds client data. Advisor departures to a competing firm are exactly when client lists walk out the door.

2. Email, Impersonation and Wire Fraud

The incident that costs financial firms the most is usually not malware. It is an email, inside a real thread or from a lookalike domain, asking for a redemption to a new account, a change of banking details or an urgent transfer. Controls work in layers:

  • Publish SPF and DKIM for every service that sends as your domain, and move DMARC to an enforcing policy so criminals cannot send as you to your clients. Our SPF, DKIM and DMARC guide explains the setup, and the free email spoofing check shows where your domain stands.
  • Alert on new mailbox forwarding and inbox rules, which are the first thing an attacker sets up after taking over a mailbox.
  • Tag external senders and tune impersonation filtering for the names of your principals and advisors.
  • Write down a call-back rule: any instruction to move money or change payment or banking details is confirmed by calling a number already on file, never one supplied in the email or text. Make it routine for every staff member, and tell clients you will never change your own banking details by email.
  • Use a secure client portal or encrypted email for statements, tax slips and account documents rather than plain attachments.

3. Devices and Remote Work

  • Full-disk encryption on every laptop (BitLocker or FileVault) and enforced screen locks and encryption on phones that receive client email.
  • Endpoint detection and response on every computer, monitored by someone who will act on an alert at night and on weekends.
  • Operating systems, browsers and line-of-business software patched on a schedule, with exceptions recorded. Unsupported systems such as Windows 10 need a replacement plan, not a shrug.
  • Devices enrolled in management (for example Microsoft Intune) so a lost or stolen laptop or phone can be wiped remotely.
  • A clear rule on personal devices: either they are enrolled with a work profile, or they do not get client data.
  • Home and branch connections: no client work over public Wi-Fi without a VPN, and the office network separated from guest Wi-Fi.

4. Records, Retention and Logging

  • Decide, with your compliance officer, how long each type of record is kept: client communications, account documents, KYC and identification records, trade and transaction records. Then configure Microsoft 365 or Google Workspace retention to match, so mail and files cannot be quietly deleted before the end of the retention period.
  • If you keep records for FINTRAC, a dealer or a carrier, make sure they can be found and produced within the time you would be given, not only that they exist somewhere.
  • Keep audit logs for sign-ins, admin changes and mailbox access long enough to investigate an incident months after it started. Default log retention on smaller licences is often shorter than firms assume.
  • Text messages and messaging apps are records too if business is done over them. Decide which channels are allowed and how they are captured.

5. Backups and Recovery

  • Back up Microsoft 365 or Google Workspace mail and files with a separate service, because the platform's own recycle bins and version history are not a backup.
  • Keep at least one backup copy that cannot be changed or deleted from your normal admin accounts, so ransomware that reaches an admin account cannot reach the backups.
  • Test a restore at least quarterly and write down how long it took. An untested backup is a hope, not a control.
  • Know how the firm would keep serving clients if the office, the internet connection or a key application were unavailable for a day. Our disaster recovery plan guide walks through the plan itself.

6. Incident Response

  • Keep a one-page plan: who decides, who calls the insurer's breach line, who contacts your regulator or dealer, who notifies clients, and who your IT provider escalates to after hours.
  • Know your reporting clocks before you need them. Regulatory and contractual reporting deadlines for cyber incidents can be short, and the insurer usually wants to be called before you hire anyone.
  • Preserve evidence: do not wipe a compromised laptop or delete a malicious inbox rule before logs are captured. Our IT emergency response checklist covers the first hour.

7. Vendors, Insurers and Evidence

  • List every vendor that holds client data, including the CRM, planning software, document storage, e-signature, phone system and your IT provider, and check how each one secures and locates that data.
  • Expect questionnaires from dealers, carriers, custodians and cyber insurers asking about MFA, backups, endpoint protection and incident response. Answer them from documented controls, not memory. Our cyber insurance readiness checklist lists the controls behind the usual questions.
  • Produce a short quarterly report for principals or the board: MFA coverage, admin accounts, leavers removed, patch status, backup test results, phishing training completed and any incidents.
  • Train staff at least once a year on phishing and payment fraud, with short refreshers when a new scam is going around.

What to Ask an IT Provider

  • Have you supported advisory, dealer, insurance or mortgage firms, and do you understand that our compliance officer, not you, decides what our obligations are?
  • Will you work with our custodian, carrier, CRM and planning software vendors rather than around them?
  • Who watches our security alerts at night and on weekends, and what happens when one fires?
  • Can you produce written evidence of our controls for an examiner, dealer or insurer questionnaire?
  • Is the agreement clear about what is included, and is project work scoped and quoted in writing before it starts? Our guide on how to compare managed IT quotes lists what to look for.

How IT Rapid Support Works With Financial Services Firms

IT Rapid Support provides managed IT, Microsoft 365 administration and cybersecurity for financial advisors, wealth managers, insurance agencies, mortgage brokerages and other financial firms across the Greater Toronto Area from our office at 7810 Keele St in Vaughan. Our helpdesk is available 24/7, we work alongside your compliance officer and your software vendors, and on-site work is dispatched across the GTA. Smaller practices can buy support billed by the hour; ongoing managed agreements and projects are scoped and quoted in writing. The service details are on our page for managed IT for financial services firms. To review your firm against this checklist, call (289) 582-9930 or contact us.

Frequently Asked Questions

What does IT support for financial services firms include?

A helpdesk for advisors and staff, Microsoft 365 or Google Workspace administration, management of laptops, phones and the office network, monitored and tested backups, and the security controls client financial data needs: enforced MFA, endpoint detection and response, email authentication and fraud controls, retention and logging, access reviews, and documentation you can hand to a regulator, dealer or insurer.

Do OSFI guidelines like B-13 apply to a small advisory firm or mortgage brokerage?

Not directly. OSFI guidelines apply to federally regulated financial institutions such as banks and federally regulated insurers. Independent advisory practices, dealers and brokerages answer to their own regulators, such as CIRO, the OSC or FSRA, and to privacy law, though questionnaires from the institutions they work with are often shaped by B-13. Confirm your obligations with your compliance officer.

How do financial firms stop wire and payment fraud by email?

With layers: SPF, DKIM and an enforcing DMARC policy so your domain cannot be spoofed to clients, MFA on every mailbox, alerts on new forwarding and inbox rules, impersonation filtering, and a written call-back rule that confirms any money movement or banking change on a phone number already on file.

How long should a financial firm keep client emails and records?

As long as your regulator, FINTRAC, your dealer or carrier agreements and your own policies require, which for many records is at least five years. Your compliance officer sets the periods; IT support configures retention in Microsoft 365 or Google Workspace so records cannot be deleted early and can be found when they are requested.

What has to happen if client data is breached?

Under PIPEDA, a breach of security safeguards that creates a real risk of significant harm must be reported to the Privacy Commissioner of Canada and the affected individuals notified as soon as feasible, and every breach must be recorded and the record kept for 24 months. Your regulator, dealer or insurer may have their own reporting requirements and deadlines, so the incident plan should list all of them.

Can a small practice use hourly IT support instead of a managed plan?

Yes. A sole advisor or small practice with most systems in the cloud can reasonably use support billed by the hour, scoped in writing for each piece of work. A managed agreement makes more sense once the firm needs proactive patching, monitoring, backup testing and access reviews done on a schedule, and evidence that they were done.

Share this resource

IT Rapid Support Team

IT Rapid Support Team

Managed IT & Cybersecurity, GTA

IT Rapid Support Team is a security expert with extensive experience in creating security guidelines.

More from this author

Related Resources

All Resources
IT Support for Logistics Companies: Mississauga Warehouses and 3PLs
guide
•
September 5, 2026

IT Support for Logistics Companies: Mississauga Warehouses and 3PLs

IT support for Mississauga logistics and warehousing firms: WMS uptime, warehouse Wi-Fi and scanners, EDI and carrier portals, 24/7 shifts, ransomware.

Read more: IT Support for Logistics Companies: Mississauga Warehouses and 3PLs
IT for Medical and Dental Offices in Mississauga
guide
•
September 5, 2026

IT for Medical and Dental Offices in Mississauga

What PHIPA expects of a Mississauga medical or dental office's IT: breach reporting, EMR vendors, backups, MFA, phishing and patient Wi-Fi separation.

Read more: IT for Medical and Dental Offices in Mississauga
LSO Technology Competence: What Ontario Law Firms Need
guide
•
September 23, 2026

LSO Technology Competence: What Ontario Law Firms Need

What LSO rule 3.1-2 technology competence requires of Ontario law firms, with a checklist by firm size, common gaps and how to document compliance.

Read more: LSO Technology Competence: What Ontario Law Firms Need

Need Expert Security Advice?

Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.

Get in Touch