Financial services businesses face a unique challenge when it comes to cyber security.
Clients trust them with highly sensitive personal and financial information, regulators expect robust governance and compliance, and employees need to access that information quickly to provide an excellent service. Finding the right balance between security and usability isn’t always straightforward.
When Peartree Wealth Management approached us, they weren’t looking for technology for technology’s sake. They wanted to strengthen their cyber security, support hybrid working and give both clients and regulators confidence that sensitive information was being protected appropriately.
Rather than recommending additional products or unnecessary complexity, we looked at how their people worked, where sensitive information lived and how Microsoft 365 could be used more effectively to deliver stronger protection without creating unnecessary barriers.
This project is a great example of how the right cyber security strategy isn’t always about adding more tools. Sometimes it’s about making better use of the technology you already have.
As a regulated financial services business, Peartree handled highly confidential client information every day.
Protecting that information wasn’t simply good practice; it was fundamental to maintaining client trust and meeting regulatory obligations.
The business wanted to:
Like many growing businesses, they also wanted to avoid making life harder for their team. Security measures needed to enhance protection while still allowing advisers and support staff to work efficiently.
That’s often where businesses find themselves stuck.
Many assume stronger cyber security means introducing more restrictions or buying additional software.
In reality, the best security strategies are the ones that protect information while allowing people to continue doing their jobs effectively.
One thing I often tell clients is that good cyber security starts with understanding the business, not the software.
Before recommending any changes, we spent time understanding how Peartree’s team worked, where sensitive information was stored, how it was shared and which risks were most significant.
Only then did we begin designing a solution.
Rather than introducing multiple standalone security products, we built on the Microsoft 365 Business Premium platform they already had in place.
It’s an approach we take with many clients.
If your existing technology can achieve the right outcome, we’ll always recommend making the most of it before suggesting additional investment.
Working closely with Peartree, we implemented a Microsoft 365-based information protection and data classification framework tailored to the way their business operated.
Information was classified according to its sensitivity, allowing different levels of protection to be applied automatically.
Lower-risk operational information remained readily available for day-to-day work, while confidential client and financial information was automatically protected through policy-based controls governing:
The project also introduced a Zero Trust-style approach using Microsoft 365’s built-in security capabilities, including:
We also restricted the use of unapproved file-sharing platforms such as Dropbox and WeTransfer, ensuring sensitive information remained within approved and governed systems.
By making full use of Microsoft 365’s native security capabilities, we were able to significantly strengthen protection without introducing unnecessary complexity or additional software.
Cyber security projects aren’t just technical exercises.
They’re also about helping people adapt to new ways of working.
One area we paid particular attention to was the rollout of mobile device management.
Rather than introducing changes overnight, we worked closely with Peartree to explain why the changes were being made, what staff could expect and how any temporary disruption would be kept to a minimum.
Taking the time to communicate clearly helped ensure the project was adopted smoothly while allowing employees to continue supporting clients throughout the rollout.
For us, successful cyber security is as much about people as it is technology.
The completed project delivered far more than stronger technical controls.
By introducing consistent data classification and automated policy enforcement, Peartree reduced its reliance on individual users making manual security decisions.
The organisation also gained significantly better visibility over how sensitive information was being accessed, shared and protected.
The result was:
Perhaps most importantly, the solution gave Peartree confidence that security controls were working quietly in the background, allowing employees to focus on delivering excellent service to their clients.
✔ Microsoft 365 security framework tailored to a regulated financial services business.
✔ Improved governance of sensitive client information.
✔ Automated information protection using Microsoft 365 Business Premium.
✔ Enhanced support for FCA compliance.
✔ Helped meet Cyber Essentials Plus requirements.
✔ Secure hybrid working.
✔ Reduced reliance on manual security processes.
✔ Practical implementation with minimal disruption.
Financial services organisations are under increasing pressure to demonstrate strong cyber security while maintaining excellent client service.
Finding the right balance isn’t always easy.
Security that is too restrictive can frustrate employees and reduce productivity.
Security that is too relaxed increases business risk.
The right solution sits somewhere in the middle.
That’s why we believe every cyber security project should begin with understanding how a business operates before recommending technology.
For Peartree, that meant creating a practical, proportionate security framework that reflected the way the business worked, protected sensitive client information and supported long-term compliance objectives.
Every organisation is different.
What worked for Peartree may not be exactly what your business needs.
That’s why we always start by understanding your people, your processes and your goals before recommending a solution.
If you’d like to strengthen your cyber security without creating unnecessary complexity, we’d be happy to have a conversation.
Take a look at our Cyber Security Services to see how we help businesses protect what matters most, or complete our Cyber Security SPACE Assessment for a practical view of your current cyber security maturity and a tailored 90-day improvement plan.
Adam, Managing Director of TechWyse