IT support for financial services firms is not ordinary business IT with a compliance sticker on the front. It is a regulated function in everything but name: the Financial Conduct Authority does not license your helpdesk, but it does write rules about how quickly you report an outage, how long you keep a recorded call, which of your suppliers you must register, and who personally carries the can when a system fails. Get the technology right and none of that is visible. Get it wrong and it arrives as a Section 166, a supervisory letter, or a headline.
This guide is built for the firms that sit between the two extremes — bigger than a sole trader, smaller than a bank. It draws on the Companies House free company data snapshot of 1 August 2026, which we downloaded and counted ourselves to establish how big the average UK financial services company actually is.
It maps that count against the FCA rules that landed in 2026: PS26/2 on operational incident and third party reporting, and the designation of four cloud providers as Critical Third Parties on 13 July 2026. It also costs the Microsoft 365 estate at published UK list prices rather than guesswork. If you run an advice firm, a broker, a lender or a fund manager, the same disciplines apply to you as to IT support for charities, to IT support for schools and to accountancy practices — only the clock speeds are different.
Nothing here is a marketing checklist for IT support for financial services. Every percentage in the tables and charts comes either from a public source in the references at the end, or from arithmetic on figures this article has already stated. Where the number cannot be sourced, it is not here.
Table of contents
- What IT Support for Financial Services Firms Actually Has to Deliver
- The Shape of the UK Financial Services Market: What We Counted
- How Small the Average Regulated Firm Really Is
- Where the Firms Are, and Why Location Still Decides Your Support Model
- The FCA Rulebook Your IT Support for Financial Services Has to Satisfy
- Operational Resilience: SYSC 15A in Practice
- PS26/2: The Incident Reporting Clock That Starts in March 2027
- Material Third Party Reporting and the Register You Do Not Have Yet
- Critical Third Parties: What the July 2026 Designations Change
- Record Keeping: The Retention Clocks IT Support for Financial Services Must Run
- Microsoft 365 for Financial Services Firms: Which Licence, and Why
- The Security Controls That Actually Matter, in the Order to Do Them In
- Identity, Conditional Access and the Privileged Account Problem
- Email, Payment Fraud and the Adviser’s Inbox
- Recording Calls and Electronic Communications Without Breaking the Budget
- Backup, Restore and the Difference Between Backup and Resilience
- Third Party and Supplier Assurance: What IT Support for Financial Services Owes You
- Cyber Essentials, ISO 27001 and What Clients Actually Ask For
- What the Cyber Security Breaches Survey Says About Finance
- Where IT Support for Financial Services Firms Goes Wrong
- What a Regulated Firm Should Expect From an IT Partner Day to Day
- IT Support for Financial Services Pricing: What UK Firms Pay
- A Worked Example: A 40-Seat Advice and Broking Firm
- Choosing a Provider: Twelve Questions and the Answers That Should Worry You
- The 100-Point IT Support for Financial Services Scorecard
- A 90-Day Plan to Get From Where You Are to Defensible
- Frequently Asked Questions About IT Support for Financial Services
- References and Further Reading
What IT Support for Financial Services Firms Actually Has to Deliver
IT support for an insurance broker with eleven staff looks nothing like a corporate service desk, and that mismatch is where most buyers of IT support for financial services come unstuck. The provider is often chosen on price and response time, then discovers eighteen months later that nobody has ever produced an impact tolerance, a supplier register, or an evidence pack that survives a supervisory question. The work is not harder than ordinary managed IT. It is differently shaped.
The regulator judges outcomes, and IT support for financial services supplies them
The FCA’s approach is outcomes-based. There is no rule that says “buy this endpoint product”. There are rules that say a firm must identify its important business services, must remain within an impact tolerance during a severe but plausible disruption, must report certain incidents within a stated time, and must keep certain records for a stated number of years. Every one of those is a technology deliverable dressed as a governance one. IT support for financial services is the function that has to turn each of them into a configuration, a runbook and a piece of retrievable evidence.
Four deliverables that separate IT support for financial services from ordinary IT
Strip away the noise and a regulated firm needs four things from IT support for financial services that an unregulated business does not. First, evidence on demand: a named artefact for every control, retrievable in minutes rather than weeks. Second, time-bounded recovery: an agreed restoration target per service, tested and documented. Third, retention with teeth: records that cannot be deleted early by a departing employee. Fourth, supplier transparency: a live list of who processes what, where, and under whose contract.
Why firms buy IT support for financial services too late
Most firms procure IT support for financial services after an event — a failed audit, a near-miss payment fraud, an adviser leaving with a mailbox full of client data. By then the firm is buying remediation at remediation prices. The cheapest moment to fix identity, retention and supplier assurance is before anyone has asked to see them, because the same work costs two to three times as much when it has to be done under a deadline set by somebody else.
Accountability for IT support for financial services is personal
Under the Senior Managers and Certification Regime, the chief operations function (SMF24) covers a firm’s internal operations and technology. That is a named human being, approved by the regulator, whose personal conduct is in scope if the systems underneath them fail. No outsourcing contract transfers that. A provider who understands IT support for financial services will write reports that an SMF24 can put in front of a board without translation; a provider who does not will send ticket-volume dashboards.
The Shape of the UK Financial Services Market: What We Counted
Before deciding what IT support for financial services should cost or contain, it is worth establishing who is actually buying it. The trade press describes a sector of banks and asset managers. The register describes something very different, and the difference is the whole argument.
The dataset behind our view of IT support for financial services
To size the market for IT support for financial services properly, we downloaded the Companies House free company data product — the single-file snapshot BasicCompanyDataAsOneFile-2026-08-01.zip, roughly 470 MB compressed — on 22 August 2026 and parsed it in full. It contains 5,695,465 rows, of which 5,190,464 are companies with a status of Active. Every count below is ours, recomputed from that file, and any reader with the same download can reproduce it exactly.
The universe: 217,248 active companies in financial and insurance activities
Filtering active companies whose first declared SIC code sits in divisions 64, 65 or 66 — financial and insurance activities — gives 217,248 companies, which is 4.19% of all active UK companies. Division 64 supplies 187,526 of them, division 66 supplies 23,752 and division 65 supplies 5,970. Taken at face value, that suggests a sector of a quarter of a million businesses. Taken at face value, it is wrong, and it distorts every estimate of what IT support for financial services should cost.
More than half the sector is a holding company, not a business
A single SIC code, 64209 — activities of other holding companies not elsewhere classified — accounts for 113,704 of those 217,248 companies, which is 52.34% of the sector on paper. These are holding vehicles, special purpose entities and group shells. They have no staff, no customers and no laptops. Anyone sizing the market for IT support for financial services from the raw SIC filter is counting more shells than firms.
Stripping out shells and dormant filers leaves 64,708 operating firms
Removing every holding-company and fund or trust SIC code, plus the dormant-company code, leaves 73,211 companies. Removing those that filed dormant accounts — 8,503 of them — leaves 64,708 active, operating, non-dormant UK companies whose primary declared activity is financial services. That is 29.79% of the naive figure. Sixty-four thousand buyers of IT support for financial services is still a large market, but it is a market of small firms, and the next section quantifies exactly how small.
Why this matters before anyone quotes for IT support for financial services
A provider pitching enterprise tooling at a sector it believes is dominated by banks will price and design accordingly. The register says otherwise. The correct design brief for IT support for financial services is a small, heavily regulated, evidence-hungry organisation with no in-house technology team — which is a genuinely different product from either consumer-grade managed IT or bank-grade infrastructure.
How Small the Average Regulated Firm Really Is
Company size is not published directly, but the accounts category a company files is an excellent proxy for it, because the thresholds are statutory, and it is the best guide we have to the scale of IT support for financial services. A micro-entity has turnover under £632,000 and fewer than ten employees. A company filing full accounts is materially larger. Counting the 64,708 operating financial services companies by accounts category produces the single most useful number in this article.
86.53% file as small companies; 11.31% file full or group accounts
Of the 64,708, 20,546 (31.75%) file micro-entity accounts, 19,567 (30.24%) file total exemption full accounts, 11,709 (18.10%) have filed no accounts yet, 2,154 (3.33%) file unaudited abridged accounts, 1,997 (3.09%) file small-company accounts and 19 file total exemption small. Together that is 55,992 companies, or 86.53%, at the small end of the filing regime. Against them sit 6,471 filing full accounts, 715 filing group accounts, 116 filing medium and 18 audited abridged — 7,320 companies, 11.31%. The ratio of small filers to full-accounts filers across the market for IT support for financial services is 7.65 to 1.
What that means for IT support for financial services in a firm with no IT department
A firm filing micro-entity accounts does not have a technology team. It has a director who is also the compliance officer, an office manager who resets passwords, and a laptop supplier who once set up the router. That is the modal buyer of IT support for financial services in the United Kingdom, and it is why the sector’s most common failure is not an exotic attack — it is an unowned control that nobody was ever assigned.
The sub-sector table that shows who buys IT support for financial services
Breaking the same population down by declared activity shows the pattern is not uniform. Advice and broking are overwhelmingly small; insurance underwriting and banking are not. The table below is our count, and it is the sharpest single view of who buys IT support for financial services and at what scale.
| Declared primary activity (SIC) | Companies | Small filers | Micro-entity | Full/group |
|---|---|---|---|---|
| Financial service activities n.e.c. (64999) | 25,911 | 87.34% | 33.48% | 10.79% |
| Auxiliary to financial services, incl. advisers and brokers (66190) | 6,707 | 94.11% | 36.45% | 4.41% |
| Insurance agents and brokers (66220) | 5,412 | 89.67% | 32.95% | 5.45% |
| Mortgage finance companies (64922) | 4,700 | 96.13% | 42.43% | 3.36% |
| Factoring (64991) | 4,059 | 98.52% | 29.86% | 1.40% |
| Fund management activities (66300) | 3,458 | 76.81% | 19.06% | 21.72% |
| Non-life insurance (65120) | 3,015 | 55.16% | 15.32% | 37.35% |
| Auxiliary to insurance and pension funding (66290) | 2,252 | 86.15% | 36.23% | 10.44% |
| Life insurance (65110) | 1,608 | 61.69% | 22.89% | 36.75% |
| Other credit granting (64929) | 1,572 | 90.46% | 25.32% | 7.70% |
| Securities and commodity contracts dealing (66120) | 1,324 | 84.82% | 29.38% | 14.73% |
| Administration of financial markets (66110) | 923 | 92.85% | 34.13% | 6.83% |
| Risk and damage evaluation (66210) | 759 | 95.52% | 39.26% | 1.84% |
| Banks (64191) | 412 | 57.77% | 32.52% | 41.02% |
Advisers and brokers are the smallest, and the most exposed
The two sub-sectors that hold the most client data per head — advisers and brokers — are also the smallest buyers of IT support for financial services by filing category. Firms auxiliary to financial services file as small companies 94.11% of the time; insurance agents and brokers 89.67%; mortgage finance companies 96.13%; risk and damage evaluators 95.52%. Banks, by contrast, file full or group accounts 41.02% of the time. The gap between the adviser figure and the bank figure is 36.34 percentage points, and it is the reason a bank’s security model cannot simply be scaled down.
Age and churn: 11.36% of the sector is under a year old
The median operating financial services company in the file is 8.56 years old and the mean is 11.90 years, but 7,350 companies — 11.36% — were incorporated within the twelve months to 1 August 2026. More than one in nine of the firms in this market is a startup, which is precisely the cohort that buys its first laptop, its first mailbox and its first authorisation in the same quarter. Getting IT support for financial services right at that moment costs almost nothing; retrofitting it at year three costs a great deal.
Multiple permissions, one estate, one IT support for financial services contract
11,742 companies — 18.15% declare more than one SIC code. That matters because a firm doing both advice and broking, or both lending and insurance mediation, inherits both sets of record-keeping obligations on the same mailboxes and the same file store. IT support for financial services has to design retention for the union of the firm’s activities, not the one on the letterhead.
Where the Firms Are, and Why Location Still Decides Your Support Model
Remote delivery has made geography less important to IT support for financial services than it was, but not irrelevant. The distribution of registered offices tells you where onsite attendance is cheap, where it is expensive, and where a provider promising a four-hour engineer is quietly promising something they cannot deliver.
London holds 39.26% of the sector, and EC alone holds 10.92%
Of the 64,708 operating firms, 25,405 (39.26%) have a registered office in a London postcode area, and 19,918 (30.78%) are in the eight core London areas. The EC postcode area alone accounts for 7,069 companies, or 10.92% of the entire UK sector — a single square mile holding more than a tenth of the demand for IT support for financial services. Outside the core, 5,487 firms (8.48%) sit in outer London areas, and 39,303 (60.74%) are in the rest of the United Kingdom.
Outside London is where onsite IT support for financial services promises break
Because 60.74% of the sector is outside London, a provider’s coverage map matters more than its brochure. Birmingham (1,414), Manchester (1,213), Leeds (1,009), Chelmsford (973), Leicester (896), Belfast and Northern Ireland (869) and Edinburgh (851) all carry meaningful clusters. IT support for financial services in those cities is perfectly deliverable, but it needs an engineer within a sensible drive, not a promise routed through a call centre.
A registered office is not an office, and IT support for financial services must know the difference
One caveat we can measure: registered-office addresses cluster heavily on formation-agent addresses, and the concentration is visible in the raw file. Treat the geography as a guide to where demand for IT support for financial services concentrates, not as a site survey. For a firm choosing a provider, the practical test is simpler — ask which of the provider’s engineers has physically visited a client within twenty miles of your actual working office in the last month.
The FCA Rulebook Your IT Support for Financial Services Has to Satisfy
There is no single “FCA IT rule”. There is a set of obligations scattered across the Handbook, each of which lands on technology. Mapping them once, in a table a board can read, is the highest-value hour any buyer of IT support for financial services will ever spend a regulated firm will ever spend with its provider.
The map from FCA rule to IT support for financial services deliverable
| Obligation | Where it lives | What the technology has to produce |
|---|---|---|
| Identify important business services | SYSC 15A.2.1R | A named service list mapped to systems, suppliers and data |
| Set and stay within an impact tolerance | SYSC 15A.2.5R, 15A.2.9R | A tested recovery time per service, with evidence of the test |
| Map people, processes, technology, facilities, information | SYSC 15A.4.1R | A current dependency map, not a diagram from the last audit |
| Scenario testing including data corruption and third party loss | SYSC 15A.5 | Restore tests, failover tests, and a lessons-learned record |
| Written self-assessment, kept for at least six years | SYSC 15A.6 | A retained, versioned document with retention applied |
| Report qualifying operational incidents | SUP 15.18 (from 18 March 2027) | Detection, triage and a submission inside 24 hours |
| Notify and register material third party arrangements | SUP 15.19, SUP 16.33 | A live supplier register, submitted annually |
| Record calls and electronic communications | SYSC 10A.1.6R | Capture on every channel the firm accepts, retained five years |
| Prevent unrecordable private-device use | SYSC 10A.1.7R | Device policy plus technical enforcement, not a signed form |
| General record keeping for MiFID business | SYSC 9.1.2R | Five-year retention that survives mailbox deletion |
| Complaints records | DISP 1.9 | Three years of complaint files, retrievable by client |
| Customer due diligence records | MLR 2017 reg 40 | Five years from the end of the relationship, then deletion |
| Outsourcing and cloud oversight | FG16/5 | Due diligence, data residency, audit rights and an exit plan |
| Consumer Duty outcomes evidence | PRIN 2A | Data you can actually extract, on demand, per outcome |
The obligations on IT support for financial services are joint, not sequential
The mistake firms make is treating this list as a project plan. It is not. The incident report you file in 2027 will be judged against the impact tolerance you set in 2025 and the supplier register you submitted in between. Good IT support for financial services builds one evidence base that answers all of them, because the alternative is four disconnected folders that contradict each other under scrutiny.
Nothing in the Handbook requires a specific product
Notice what the table does not say. It does not name a firewall, an endpoint agent or a backup vendor. Firms buying IT support for financial services are frequently sold “FCA-compliant” products; no such certification exists. What exists is a firm that can demonstrate the outcome. Any provider using the phrase “FCA-approved software” in a proposal has told you something useful about their understanding of the rulebook.
Operational Resilience: SYSC 15A in Practice
The operational resilience rules have been fully in force since 31 March 2025 — 509 days by 22 August 2026 — and they remain the framework every other obligation on IT support for financial services hangs from. Firms in scope include enhanced scope SMCR firms, banks, designated investment firms, building societies, Solvency II firms, payment and e-money institutions, and UK recognised investment exchanges.
Important business services are defined by harm, not by org chart
An important business service is one whose disruption could cause intolerable harm to consumers or risk to market integrity. For an advice firm that is usually client onboarding, the ability to place a trade or submit an application, and access to the client file. For a broker it is quotation and claims notification. It is rarely “email”, even though email is how all of those actually reach the client — which is exactly why the mapping step matters.
Impact tolerance is a number IT support for financial services has to defend
SYSC 15A.2.5R requires a tolerance per service and 15A.2.9R requires the firm to remain within it during a severe but plausible disruption. A tolerance of “as soon as possible” is not a tolerance. A tolerance of four hours means the firm has to be able to prove it can restore that service in four hours, from a test, not from a vendor datasheet. This is the single most common gap we see when reviewing IT support for financial services arrangements inherited from a previous provider.
The mapping rule is where most self-assessments fall apart
SYSC 15A.4.1R asks for the people, processes, technology, facilities and information behind each service. Most buyers of IT support for financial services produce a network diagram. What is actually required is a chain: this service depends on this application, hosted by this provider, authenticated by this identity platform, with this data set, restorable from this backup, operated by these three named people. If any link in that chain is unnamed, the map is decoration.
Scenario testing has a minimum that IT support for financial services must cover
The rules list scenarios firms must consider, including corruption or deletion of data critical to an important business service, unavailability of critical third party services, disruption to other market participants, and loss of technology underpinning the service. Three of those four are technology tests, and they belong in the IT support for financial services test plan. A provider that has never run a restore test in front of you has not tested the first one.
The self-assessment must be kept for six years, wherever your provider sits
SYSC 15A.6 requires a written record covering services, tolerances, mapping, testing and identified vulnerabilities, retained for at least six years. Six years is longer than the average firm’s relationship with its IT provider, which is why IT support for financial services has to keep the document in the firm’s own tenant under the firm’s own retention policy — never in a provider’s ticketing system.
Review cadence for IT support for financial services is annual, and the rules say so
Both the identification of important business services and the impact tolerances must be reviewed no later than one year after the last assessment. Diarise it. An annual review of IT support for financial services that happens in month fourteen is a finding, and it is an entirely avoidable one.
PS26/2: The Incident Reporting Clock That Starts in March 2027
On 18 March 2026 the FCA published PS26/2, its final rules on operational incident and third party reporting, alongside the PRA’s PS7/26 and finalised guidance FG26/3 and FG26/4. The rules come into force on 18 March 2027. As of 22 August 2026 that leaves every buyer of IT support for financial services 208 days, about 29.7 weeks, or 56.99% of the twelve-month transition still to run.
Who is in scope: effectively every regulated firm
Incident reporting applies to all firms with a Part 4A permission, payment service providers, UK recognised investment exchanges, registered trade repositories and registered credit rating agencies. The FCA kept all firms in scope deliberately, noting that the impact of incidents “can be felt across the sector and is not limited to larger firms”. If you hold a permission, this is your rule and your IT support for financial services has to serve it.
Standard and enhanced: 90% of firms file the short form
The FCA split firms into two groups. Standard reporting covers around 90% of FCA-regulated firms and is a single short form with a small number of questions, with no obligation to update it afterwards. Enhanced reporting applies to a smaller cohort listed in SUP 15.18.3R and keeps the three-phase structure — initial, intermediate and final — on one form, with roughly 20% fewer questions than were consulted on, which lightens the load on IT support for financial services.
The three thresholds are qualitative, and that is deliberate
A firm must report where it reasonably believes an operational incident poses a risk of causing intolerable levels of harm to consumers from which they cannot easily recover; a risk to the safety and soundness of the firm or other market participants; or a risk to market stability, market integrity or confidence in the UK financial system. The FCA declined to set quantitative thresholds for IT support for financial services to key on because its rules apply to firms of vastly different scale.
Twenty-four hours, and four hours if you are a payment firm
The initial phase must be submitted as soon as practicable and, at the very most, within 24 hours of determining that the incident meets one or more thresholds. Payment service providers must continue to report within 4 hours of first detecting an incident. Enhanced-reporting firms must file the final phase within 30 working days of resolution, extendable in exceptional circumstances, and rarely comfortable for IT support for financial services, to no more than 60 working days.
What twenty-four hours means for IT support for financial services in practice
Twenty-four hours from a determination, not from detection, sounds generous until you work backwards. Someone has to notice, escalate, assess against three thresholds, decide, and submit through the FCA’s Connect platform. In a firm where the only person who understands the estate is the IT provider’s account manager, that chain has three handoffs in it before anyone opens the form. The firms that will cope are the ones whose IT support for financial services already runs a documented triage path with named deputies.
| Report | Who | Deadline | Practical trigger |
|---|---|---|---|
| Initial, standard | Most FCA solo-regulated firms | As soon as practicable, at most 24 hours from determination | Threshold decision recorded by a named person |
| Initial, enhanced | Firms listed in SUP 15.18.3R | As soon as practicable, at most 24 hours from determination | Same, plus a running incident log |
| Initial, payment service providers | PSPs | 4 hours from first detection | Detection, not determination — a much harder clock |
| Intermediate | Enhanced firms | On material change | Judgement, with examples in FG26/3 |
| Final | Enhanced firms | 30 working days after resolution | Roughly 42 calendar days |
| Final, exceptional circumstances | Enhanced firms | No more than 60 working days | Roughly 84 calendar days, and you must explain why |
One incident, one report, one portal
The regulators built a single regime. All firms submit through the FCA’s Connect platform, and a dual-regulated firm files one report that is shared with both the FCA and the PRA. Only one report is required per incident even where multiple services are affected — a firm lists them all in the affected-services field. That removes an old excuse for delay in IT support for financial services, which was working out who to tell first.
Do not wait for the deadline to build the IT support for financial services runbook
The reporting form is the easy part. The hard part is the detection and escalation path behind it, and that takes months of habit to build. With 208 days to go, a sensible programme is to run the process now on real incidents that do not meet the thresholds, so that the first real report is the twentieth rehearsal rather than the first attempt.
Material Third Party Reporting and the Register You Do Not Have Yet
The second half of PS26/2 is quieter and, for most firms, more work. Alongside incident reporting, and squarely in the path of IT support for financial services, the FCA has created a unified third party regime with a single definition, a single notification template, a single register template and one portal shared with the PRA and the Bank of England.
Who has to keep a material third party register
Third party reporting applies to enhanced scope SMCR firms, banks, designated investment firms, building societies, Solvency II firms, CASS large firms, UK RIEs, authorised electronic money and payment institutions, and consolidated tape providers. That is a narrower list than incident reporting, but it captures a great many mid-sized firms whose IT support for financial services keeps the supplier list in a spreadsheet that one person maintains.
What “material” means, and what it does not
The FCA has defined a material third party arrangement in the Handbook and declined to attach a monetary threshold, because such a threshold “would need to apply to firms of vastly differing scale and nature”. Critically, materiality is not limited to arrangements supporting an important business service — the FCA’s own example for IT support for financial services is a new provider running a secondary data centre that never touches an important business service but leaks customer data through a cyber incident.
SUP 16.33: maintain it, and submit it annually
SUP 16.33.6R requires a firm to maintain a register of information relating to its material third party arrangements and to submit that register to the FCA annually, online. There is a carve-out at SUP 16.33.7R for intragroup arrangements where the group provider has no external dependency, with UK RIEs excluded from that carve-out. Firms do not have to resubmit the register every time a notification is made; the register is an annual artefact for IT support for financial services and notifications are event-driven.
The register is an IT support for financial services asset, not a compliance document
Here is the practical consequence for IT support for financial services: the supplier register has to be generated from something real. Firms that build it by emailing department heads once a year produce a document that is wrong within a fortnight. Firms that generate it from the same inventory that drives their access reviews, their data-flow map and their exit planning produce one that is right by construction. The second approach costs more to set up and almost nothing to maintain.
What belongs in every row of the register
At minimum, and IT support for financial services should populate it: the provider’s legal entity, the service, the data categories processed, the jurisdictions where data is stored or accessed, whether the arrangement is intragroup, which important business services depend on it, the contract end date, the notice period, and the named internal owner. Nine columns. Most firms can populate seven of them today and will discover the other two are the ones that matter during an incident.
Critical Third Parties: What the July 2026 Designations Change
On 10 July 2026 HM Treasury announced the first designations under the Critical Third Parties regime, with effect from 13 July 2026 — 40 days before this article was written. The designated entities are Microsoft Ireland Operations Limited, Google Cloud EMEA Limited, Amazon Web Services EMEA SARL and Oracle Corporation UK Limited.
What designation of a critical third party actually does
The Bank of England, PRA and FCA now jointly oversee the critical services those providers supply to the financial sector. Regulators can gather information from them, assess resilience arrangements, and make and enforce CTP-specific rules. Oversight applies only to the systemic services provided to the financial sector, not to the providers’ wider businesses. The rules themselves took effect on 1 January 2025 under PS24/16; the designation orders are what switched them on.
What designation does not do for your own obligations
It does not transfer your responsibility, and it does not soften a single obligation on IT support for financial services. The FCA has been explicit that the regime “is not about replacing firms’ responsibilities for managing their own operational resilience and third party arrangements”. If your tenant is misconfigured, your backup untested or your exit plan fictional, the fact that Microsoft is now a designated CTP changes nothing about your position.
Why concentration is now a board-level number
The FCA’s own figures are the argument. In 2025, 27% of incidents reported to the FCA by firms were attributed to a third party issue, and 37% of those were cyber-related — which is 9.99% of all reported incidents arising from third party cyber events. Roughly one incident in ten now originates outside the perimeter that IT support for financial services controls and inside somebody else’s cyber problem.
The uncomfortable concentration question for small firms
If a designated cloud provider fails, a small firm has no leverage and no alternative in the timescale that matters. That is not an argument against cloud — it is an argument for knowing precisely which of your important business services die with which provider, and having a documented, tested answer for the first four hours. A one-page provider-outage card per service is a two-hour job for IT support for financial services and the most useful artefact a small firm can own.
Rolling designations mean IT support for financial services cannot plan around four names
HM Treasury has described a rolling regime in which further providers may be designated over time. Firms should not build a control that depends on the current list of four. Build the dependency map into IT support for financial services; the designations are a signal about concentration, not a substitute for knowing your own estate.
Record Keeping: The Retention Clocks IT Support for Financial Services Must Run
Retention is where IT support for financial services diverges most sharply from ordinary IT, and where the cheapest mistakes are made. Ordinary businesses delete to save space. Regulated firms delete to comply, and keep to comply, and the two obligations run on different clocks over the same mailbox.
Five years for recorded calls, seven if the FCA asks
SYSC 10A.1.14R requires records of relevant telephone conversations and electronic communications to be kept for five years and, where requested by the FCA, for a period of up to seven years. That is a design constraint on IT support for financial services, not a policy preference: the storage platform must be able to extend a hold on a specific record set without rewriting the whole retention scheme.
The private-device rule is a technical control, not a policy
SYSC 10A.1.7R requires firms to take all reasonable steps to prevent employees and contractors from making, sending or receiving relevant communications on privately owned equipment the firm cannot record or copy. A signed acceptable-use policy is not “all reasonable steps” without IT support for financial services behind it. Conditional access that blocks unmanaged devices from the relevant applications is. This is one of the clearest examples of a Handbook rule that only a technology control can actually satisfy.
Monitoring the recordings is a rule IT support for financial services has to enable
SYSC 10A.1.15R(7) requires firms to monitor compliance with the recording obligations by periodically monitoring the records of transactions and orders, including relevant conversations. Somebody has to sample, and IT support for financial services has to make sampling possible. If nobody in the firm has ever listened to a stored call or opened a stored chat since the system was installed, that rule is not being met and the gap is easy for a supervisor to find.
The other retention clocks, and where they conflict
MLR 2017 regulation 40 requires customer due diligence records to be kept for five years from the end of the business relationship — and then, by design, deleted. DISP 1.9 requires complaint records for three years from receipt for non-MiFID business. SYSC 9.1.2R requires five years for MiFID business records. SYSC 15A.6 requires the operational resilience self-assessment for at least six years. Four different clocks, one file store, and one IT support for financial services arrangement holding all of them.
Deletion is an obligation for IT support for financial services too
The MLR clock is the one people forget, because it runs in the opposite direction. Keeping customer due diligence records indefinitely is not cautious, it is non-compliant, and it is also the reason a breach at a small brokerage can expose two decades of identity documents. A retention policy that only ever adds is not a retention policy, and IT support for financial services should say so.
Where the records have to live, and who holds the keys
The practical answer for most firms is Microsoft Purview retention policies and retention labels applied inside the firm’s own Microsoft 365 tenant, with regulatory-record labels where immutability is required. The important design point is ownership: retention must be configured in the firm’s tenant, under the firm’s global administrator, so that changing IT support for financial services does not put five years of recorded calls at risk. Any provider who resists that is protecting their own switching costs.
| Record type | Rule | Keep for | Then |
|---|---|---|---|
| Relevant telephone calls and electronic communications | SYSC 10A.1.14R | 5 years | Up to 7 years if the FCA requests it |
| MiFID business records | SYSC 9.1.2R | At least 5 years | Review, then dispose under policy |
| Customer due diligence | MLR 2017 reg 40 | 5 years from end of relationship | Delete unless another duty applies |
| Complaint files, non-MiFID | DISP 1.9 | 3 years from receipt | Dispose under policy |
| Operational resilience self-assessment | SYSC 15A.6 | At least 6 years | Keep versions, not just the latest |
| Material third party register | SUP 16.33 | Maintained continuously | Submitted to the FCA annually |
Microsoft 365 for Financial Services Firms: Which Licence, and Why
Almost every UK firm in this sector runs Microsoft 365. The licence decision is therefore the single largest recurring cost in IT support for financial services and, more importantly, the thing that determines which of the Handbook obligations above can be satisfied natively and which require a bolt-on. Getting it wrong in either direction is expensive.
The published UK list prices, read on 22 August 2026
Microsoft’s UK list prices, on annual commitment and excluding VAT, are £5.40 per user per month for Business Basic, £9.80 for Apps for business, £18.10 for Business Standard, £24.60 for Business Premium, £33.50 for Microsoft 365 E3, £51.60 for E5 and £81.60 for E7. Annualised, that is £64.80, £117.60, £217.20, £295.20, £402.00, £619.20 and £979.20 per user per year. The step from Business Premium to E5 is £27.00 per user per month, or £324.00 per user per year.
The 300-seat ceiling that shapes IT support for financial services estates
Business plans are capped at 300 seats. Given that 86.53% of operating financial services companies file as small companies, the overwhelming majority of this sector will never approach that ceiling — which makes Business Premium the correct default for IT support for financial services in this market, not a compromise. It carries Entra ID Plan 1, Intune, Defender for Office 365 Plan 1, Defender for Business and Purview retention capability. That is enough to meet most of the table in the rulebook section.
When the step up to E5 is genuinely justified
Three situations justify E5 rather than Business Premium: a firm with more than 300 users; a firm that needs advanced eDiscovery and insider risk tooling because it deals with market-sensitive information; and a firm whose supervisory obligations require communication surveillance at a level Purview’s basic retention cannot supply. Outside those three, the £324 per user per year is usually better spent by IT support for financial services on tested backup, an identity review and a genuine restore exercise.
Mixing licences is normal, and good IT support for financial services proposes it
Nothing requires a uniform estate. A twelve-person advice firm might put its three directors and the compliance officer on E5 for eDiscovery and leave the rest on Business Premium. The worked example later in this article prices exactly that pattern and shows it landing at 60.76% of the all-E5 cost. Sensible IT support for financial services proposes the mix rather than the tier.
| Plan | Per user/month | Per user/year | What it does for a regulated firm |
|---|---|---|---|
| Business Basic | £5.40 | £64.80 | Web apps and mailbox only; not sufficient on its own |
| Apps for business | £9.80 | £117.60 | Desktop apps, no mailbox, no security stack |
| Business Standard | £18.10 | £217.20 | Productivity, but no Intune and no Defender for Business |
| Business Premium | £24.60 | £295.20 | The sensible default: identity, device control, mail security, retention |
| Microsoft 365 E3 | £33.50 | £402.00 | Above 300 seats, with broader compliance tooling |
| Microsoft 365 E5 | £51.60 | £619.20 | Advanced eDiscovery, insider risk, deeper analytics |
| Microsoft 365 E7 | £81.60 | £979.20 | Top tier; rarely proportionate below several hundred seats |
Licensing is not compliance, and the invoice proves nothing
Buying E5 and configuring none of it is the most expensive way to fail an audit. We regularly review firms paying for advanced tooling with default policies, no retention labels, no conditional access and no device compliance rules. The licence is the permission to build the control. The control is a separate piece of work, and it is the work IT support for financial services should be measured on that IT support for financial services should be measured on.
The Security Controls That Actually Matter, in the Order to Do Them In
A regulated firm with limited budget should not buy controls alphabetically. There is a defensible order for IT support for financial services, and it follows the shape of how these firms are actually attacked: identity first, then mail, then device, then data, then supplier.
One: identity, because that is where the money goes
Almost every financial loss in this sector begins with a credential, which is why IT support for financial services starts here. Multi-factor authentication on every account with no exceptions, conditional access that blocks unmanaged devices and legacy authentication, and privileged accounts that are separate from daily-driver accounts. If a firm does exactly one thing this quarter, it is this, and the licence to do it is already in Business Premium.
Two: mail, because that is where the instruction arrives
Payment redirection fraud does not need malware, and IT support for financial services cannot filter judgement. It needs a plausible email at the right moment in a transaction. Anti-phishing policies with impersonation protection for the directors and the finance mailbox, safe links and safe attachments, external-sender warning banners, and a hard rule that bank details are never changed on the strength of an email alone.
Three: device, because the adviser works everywhere
Intune compliance policies, disk encryption enforced and reported, screen lock, and a working remote wipe that has actually been tested on a real device. A firm whose IT support for financial services cannot prove a lost laptop was encrypted has a reportable personal data breach; a firm that can has an inconvenience.
Four: data, because retention is the regulated bit
Retention policies and labels mapped to the clocks in the previous section, restricted sharing defaults on client folders, and a data map good enough to answer “where is this client’s file” in one query rather than three phone calls. Our data protection work with regulated clients almost always starts here, because it is the control that ages worst when neglected.
Five: supplier, because one incident in ten now starts there
Given that 9.99% of reported incidents in 2025 traced to third party cyber events, supplier assurance has stopped being paperwork and become part of IT support for financial services. A short annual review of your top ten providers — certification status, incident history, notification commitments, exit terms — is proportionate for a small firm and evidences the SUP 16.33 register at the same time.
The order matters more than the products IT support for financial services sells you
Firms that buy IT support for financial services in this order end up with controls that reinforce each other. Firms that start with a shiny detection product and no identity hygiene end up paying to watch themselves be breached. Effective cybersecurity for a small regulated firm is mostly sequencing, not spending.
Identity, Conditional Access and the Privileged Account Problem
Identity deserves its own section in any review of IT support for financial services because it is the control that most often looks finished and is not. Firms enable multi-factor authentication, see the tick in the portal, and never revisit the exclusions list.
The exclusions list is where the identity risk lives
Every real deployment accumulates exemptions: the shared reception mailbox, the director’s phone that could not do it, the accounts package’s service account, the legacy application that only speaks basic authentication. Each is a documented decision at the time and an undocumented liability two years later. An annual exclusions review with a named approver from IT support for financial services is a five-minute meeting that prevents most identity incidents in this sector.
Conditional access is how SYSC 10A.1.7R gets enforced
The rule requiring firms to prevent unrecordable communications on private equipment is not satisfiable by policy alone. Conditional access, configured by IT support for financial services, that requires a compliant or hybrid-joined device before Outlook, Teams or the client system will open is the enforcement mechanism. It also happens to be the control that makes a lost personal phone a non-event.
Privileged access: the global administrator nobody owns
Small firms very often have a global administrator account created by a previous provider, shared, unmonitored and still active. Every regulated firm should be able to name every account with administrative rights in its tenant, say who holds it, and show the last time it was used. Break-glass accounts belong in a sealed envelope with IT support for financial services named in the procedure with a documented procedure, not in a password manager shared with a departed engineer.
Joiners, movers and leavers is a regulated process, not an IT ticket
When an adviser leaves, the mailbox holds records that are subject to five-year retention and a client list that is subject to a great deal of commercial interest. The leaver process must place the mailbox on retention, revoke sessions, remove device access and hand over the client folder before the account is disabled. Doing those in the wrong order destroys evidence that IT support for financial services is expected to preserve. This is the single process where good IT support for financial services most visibly differs from generic managed IT.
Email, Payment Fraud and the Adviser's Inbox
Financial services firms are targeted specifically because the payment instruction sitting in an adviser’s inbox is worth more than the data next to it. The controls are well known to IT support for financial services; the discipline is not.
Impersonation protection needs a list of real names, supplied by the firm
Anti-phishing impersonation protection works from a list of protected users. The firm, not IT support for financial services, has to supply that list: directors, the finance function, the compliance officer, and anyone whose signature moves money. Most tenants we review have the feature enabled and the list empty, which is protection in the same sense that an unplugged alarm is protection.
Authentication records on your own domain
SPF, DKIM and DMARC on every sending domain, including the ones used by the marketing platform and the e-signature tool. DMARC at enforcement rather than monitoring, once IT support for financial services has cleaned the reports. A firm sending client documents from a domain that any third party can spoof has an avoidable problem.
The out-of-band payment rule, written down and tested
No change to bank details, no new payee and no unusual payment on the strength of an email or a message alone. A callback to a number held on file before the change, not the number in the email. Two people for anything above a stated threshold. Written into the procedure, rehearsed with IT support for financial services, trained annually and tested with a simulated request at least once a year.
Phishing simulations are cheap and the results are uncomfortable
Phishing simulation is available in Business Premium and above, and a firm that has never run one is guessing about its own exposure. The value is not the click rate. It is the reporting rate — the proportion of staff who tell someone within ten minutes — because that number is what decides whether an incident is contained inside the 24-hour reporting window or discovered a fortnight later.
Recording Calls and Electronic Communications Without Breaking the Budget
For firms doing MiFID business, recording is not optional and it is one of the largest technical dependencies in the estate. It is also where IT support for financial services most often wastes money on the wrong architecture.
Decide the recording perimeter before the product
The rule bites on communications relating to activities in financial instruments made on equipment the firm provides or accepts. So the first decision is which channels the firm accepts at all. A firm that permits mobile calls, personal WhatsApp and Teams chat has three capture problems. A firm that permits Teams and the desk phone only has one. Narrowing the perimeter is cheaper for IT support for financial services than instrumenting it.
Capture, retain, retrieve — three separate problems
Capture is the recording itself. Retention is the five-year, potentially seven-year clock. Retrieval is the ability to produce every communication with one client across every channel within a working day. Firms usually buy capture from IT support for financial services and discover retrieval a year later, during a complaint. Specify retrieval in the tender.
Teams-native capture or a third party platform
Compliance recording for Teams is delivered through certified partner solutions integrated with the platform, with the recordings retained in the firm’s own tenant or in the partner’s platform. Either is defensible; what matters is who holds the master copy, what the export format is and what happens on the day the contract ends. Ask IT support for financial services for a test export in the first month, not in year five.
The monitoring obligation needs a rota, not a promise
Because SYSC 10A.1.15R(7) requires periodic monitoring of the records, a firm needs a sampling rota with a documented outcome. Two calls a month, pulled by IT support for financial services, reviewed by the compliance officer, recorded in a log. It is a small amount of work that converts an unevidenced control into an evidenced one.
Backup, Restore and the Difference Between Backup and Resilience
Backup is the control most buyers of IT support for financial services believe they have and fewest have tested. In a regulated firm the distinction matters more than usual, because an impact tolerance is a restore-time commitment made to a regulator.
Microsoft 365 is not backed up by default, whatever the licence says
Microsoft operates the service; the firm owns the data; IT support for financial services owns the copy. Recycle bins and retention policies are not backup — they will not survive a malicious administrator, a mass deletion by a departing employee, or a ransomware event that encrypts synchronised files. A separate backup of Exchange, SharePoint, OneDrive and Teams, held under separate credentials, is the baseline for any firm with a Handbook retention obligation.
The restore test is the IT support for financial services deliverable, not the backup job
A green backup dashboard from IT support for financial services evidences nothing. What evidences an impact tolerance is a documented restore: this file set, restored at this time, by this named engineer, in this many minutes, verified by this named person at the firm. Two of those a year, one announced and one not, is proportionate for a small firm and is exactly the artefact SYSC 15A.5 testing expects.
Immutability, because ransomware targets the backup first
Backups must be immutable or otherwise protected from deletion within their retention window, and the credentials that manage them must not be the same credentials that administer the production tenant. If the same global administrator account can delete both the mailbox and its backup, the firm has one copy of its data and IT support for financial services has extra steps.
Recovery order is a business decision, not one for IT support for financial services
When everything is down, what comes back first? Client onboarding or the ability to place a trade? Email or the client system? The answer belongs to the business, written down in advance, and it should match the priority order implied by the important business services. Discovering the order during the incident is how IT support for financial services breaches an impact tolerance.
Test the third party failure, not just the fire
SYSC 15A.5 explicitly contemplates unavailability of critical third party services. Given the CTP designations, the most realistic severe-but-plausible scenario for a small firm in 2026 is not a fire in the office — it is a regional cloud outage. A documented answer to “we cannot reach our tenant for six hours” is worth more than a fire drill.
Third Party and Supplier Assurance: What IT Support for Financial Services Owes You
Your IT support for financial services is itself a third party, and under the new regime quite possibly a material one. That creates an unusual dynamic: the firm has to assure the supplier who is helping it assure its suppliers.
Your provider’s own certifications are the starting point
Ask for the provider’s Cyber Essentials or Cyber Essentials Plus certificate and its expiry date, its ISO 27001 certificate and scope statement, and its most recent penetration test summary. Scope matters more than the badge when assessing IT support for financial services — an ISO 27001 certificate scoped to a single office and not to the remote support platform tells you very little about the service you are buying.
Administrative access, and the log of it
Your provider holds administrative access to the systems that hold your client data. You are entitled to know which named engineers hold it, how their own accounts are protected, whether access is standing or requested per-job, and where the log of their activity lives. A supplier of IT support for financial services using shared administrative credentials across clients should be a disqualification for a regulated firm.
Notification commitments belong in the IT support for financial services contract
Because your reporting clock starts when you determine a threshold is met, your provider’s notification commitment to you is part of your regulatory timeline. The contract should say how quickly they must tell you about an incident affecting your data or services — hours, not “promptly” — and who they tell. Without that, the 24-hour clock is run by IT support for financial services with no obligation to start it.
Exit is a control, and FG16/5 says so
FG16/5 expects a plan to manage termination and the secure transfer of data and services back to the firm. In practice that means the firm owns its tenant, its domain, its licences and its backups, and can be handed administrative credentials without renegotiation. Firms that discover otherwise usually discover it during a dispute with their IT support for financial services. The related discipline of vendor management is not glamorous, but it is what makes an exit plan real.
Data residency belongs in writing
FG16/5 also expects a data residency policy agreed with the provider setting out the jurisdictions where data can be stored, processed and managed. For a Microsoft 365 estate that is a specific configuration and a specific set of answers about where support engineers sit. Have IT support for financial services write it down once, review it annually, and reference it in the SUP 16.33 register.
Cyber Essentials, ISO 27001 and What Clients Actually Ask For
Certification is not a regulatory requirement for IT support for financial services in most of this sector, but it is increasingly a commercial one — networks, panels, lenders and institutional clients ask.
The published Cyber Essentials fees for 2026
IASME’s assessment fees are £320 + VAT for 0–9 employees, £440 + VAT for 10–49, £500 + VAT for 50–249 and £600 + VAT for 250 or more. Including VAT that is £384, £528, £600 and £720. Certification lasts twelve months. Cyber Essentials Plus adds a technical audit covering a representative set of user devices, all internet gateways and all internet-facing servers, and is quoted per network.
Group structures make certification cost more than it should
Because the fee is per certified organisation, a group that certifies three FCA-regulated entities separately at 18, 14 and 8 staff pays 3 × £440 = £1,320 where a single certification covering all 40 people costs £440 — £880 more, a factor of 3.00×. Scope decisions of that kind should be made deliberately with the certification body and IT support for financial services, not discovered on the invoice.
ISO 27001 is a different order of commitment
ISO 27001 is a management system, not an assessment. It requires an information security management system, internal audits, management review and a certification cycle. For a firm of forty people it is a meaningful programme for IT support for financial services, and it is worth doing when clients demand it or when the firm’s risk profile justifies it — not as a substitute for the controls in the Handbook, which apply either way.
What to certify first, and when
The pragmatic order for a small regulated firm is Cyber Essentials in year one, Cyber Essentials Plus in year two if clients ask, and ISO 27001 only when a named commercial requirement exists. Doing them in the other order spends the IT support for financial services budget on documentation before the controls are in place.
What the Cyber Security Breaches Survey Says About Finance
The government’s Cyber Security Breaches Survey 2025/2026, published on 30 April 2026 from interviews with 2,112 UK businesses and 1,085 UK charities between August and December 2025, is the best free benchmark available to IT support for financial services and it treats finance and insurance as a distinct sector.
The sector takes security seriously, and the numbers show it
89% of finance or insurance businesses said cyber security was a high priority for senior management, against 72% of businesses overall — 17 percentage points higher, or 23.61% higher in relative terms. 54% had a board member with responsibility for cyber security, against 31% overall — 23 points, or 74.19% higher. And 61% sought external information or guidance, against 44% overall, which is 38.64% higher.
The headline breach figure, read in context
Across all UK businesses, 43% identified a cyber breach or attack in the previous twelve months. The perceived cost figures are worth reading carefully: the median cost of the most disruptive breach was reported as £0 across all businesses, with the 95th percentile at £4,000, rising to £10,000 for medium and large firms. Those numbers understate regulated firms badly, because they do not price a supervisory response, a rebuild of IT support for financial services, a redress exercise or the time of a compliance function.
Priority is not the same as capability, and IT support for financial services closes the gap
A sector can care a great deal and still be exposed, because attention concentrates in the largest firms and the survey’s sector figures are dominated by them. Set against our own finding that 86.53% of operating financial services companies file as small companies, the survey’s picture of an engaged, board-led sector describes the top of the market far better than it describes the median firm. That gap is the whole commercial case for IT support for financial services delivered as a managed service rather than hired in-house.
Where the enforcement risk actually sits for a small firm
The ICO’s recent enforcement pattern is fewer, larger fines following cyber attacks — a £14 million penalty against Capita on 15 October 2025, part of £15 million issued across related entities in that quarter. For a small buyer of IT support for financial services the realistic exposure is not a headline fine; it is a reprimand, a redress bill and a supervisory relationship that becomes expensive to maintain.
Where IT Support for Financial Services Firms Goes Wrong
Patterns repeat. These are the IT support for financial services failures that show up most often when a regulated firm asks for a second opinion on an inherited arrangement.
The provider owns the tenant, and everything else follows from that
The single most damaging arrangement in this sector: the Microsoft 365 tenant, the domain or the licence agreement sits under the provider’s account rather than the firm’s. Everything else — retention, exit planning, data residency, the SUP 16.33 register — becomes negotiable. Check this before anything else in an IT support for financial services review, because every other control is downstream of it.
Nobody has ever tested a restore
A backup product is bought, an agent is installed, a dashboard turns green, and no one ever asks for a file back. The first restore attempt then happens during an incident, which is the worst possible moment to discover a retention window, a licensing gap or an expired credential.
Retention exists in the policy and not in the platform
A written retention schedule in the compliance manual, and a Microsoft 365 tenant with no retention policies configured at all. This is extremely common in IT support for financial services and easy to check: open the compliance portal and count the policies. If the answer is zero, the schedule is aspirational.
The supplier list is a spreadsheet with three columns
Name, service, cost. No data categories, no jurisdictions, no notice periods, no owner. That spreadsheet cannot become a SUP 16.33 register without IT support for financial services rebuilding it, and the rebuild always takes longer than the deadline allows.
Incident escalation stops at the IT support for financial services account manager
The firm’s escalation path is “call our IT company”. The IT company’s path is a ticket queue. Nobody has agreed what happens at 6pm on a Friday, who has authority to declare an incident, or who assesses it against three FCA thresholds. This is the gap PS26/2 will expose in IT support for financial services most sharply, and it costs nothing to close.
Change happens without a record anyone can read
Regulated firms need to be able to say what changed and when, because “we made a change on Tuesday” is the answer to a surprising proportion of incident investigations. A change log from IT support for financial services that a non-technical director can read is a low-effort, high-value artefact.
Security awareness is an annual video nobody measures
One e-learning module in January, no simulation, no measurement, no follow-up for the people who fail. Given that payment fraud in this sector arrives by email, training that IT support for financial services never tests is a cost rather than a control.
What a Regulated Firm Should Expect From an IT Partner Day to Day
Beyond the compliance artefacts, there is the ordinary service. A regulated firm should expect more from IT support for financial services than an unregulated one does, and should be able to describe what “more” means before signing anything.
Response and restoration targets, and why only one of them counts
A response target is when somebody picks the ticket up. A restoration target is when the service works again. Only the second one maps to an impact tolerance. Any service agreement that quotes response times alone is not measuring the thing the FCA asks about. Our guidance on what belongs in a managed IT services agreement applies here with an extra column for the regulatory consequence.
A named engineer who has seen your systems before
Regulated firms run niche software: back-office platforms, portfolio systems, quotation engines, compliance tooling. A rotating pool of first-line agents supplying IT support for financial services will never learn them. The practical test is whether the same two or three engineers appear on your tickets month after month, and whether one of them can name your client system without checking.
Monthly IT support for financial services reporting that a director can read
Not ticket volumes. A one-page report covering: incidents and near misses, patch status by device, identity exceptions outstanding, backup restores tested, supplier changes, and outstanding risks with owners and dates. That page is the raw material for the board pack, and IT support for financial services should own it and, eventually, for the self-assessment.
An annual review with the compliance function in the room
Once a year the technology review and the compliance review should be the same meeting: important business services confirmed, tolerances retested, register refreshed, exclusions reviewed, retention checked against activities. Splitting them is how firms end up with an IT support for financial services plan and a compliance plan that contradict each other.
Onboarding new IT support for financial services takes weeks, not days
Switching IT support for financial services is a project with a data-protection dimension, and rushing it is how credentials get shared and access lingers. The pattern set out in our onboarding checklist for the first 30 days holds for regulated firms with two additions: retention must be verified before any mailbox is touched, and the outgoing provider’s administrative access must be revoked on a documented date with evidence.
Where AI tooling fits into IT support for financial services, and where it does not
Copilot and similar assistants are arriving in this sector fast, and they raise a specific question: what happens when a tool that uses natural language processing reads a mailbox subject to five-year retention and produces a summary that is itself a business record? The answer is for the firm and its IT support for financial services to decide deliberately — which data the assistant may see, whether its outputs are retained, and how that squares with the firm’s obligations — before enabling it tenant-wide.
IT Support for Financial Services Pricing: What UK Firms Pay
Pricing for IT support for financial services is per user per month, and the spread is wide because the scope varies enormously. The figures below are indicative UK market ranges for a regulated firm, and they exclude Microsoft licensing, which is priced separately above.
| Tier | Per user/month | What is typically included | Suitable for |
|---|---|---|---|
| Essential | £45 | Helpdesk, patching, endpoint protection, backup, basic reporting | Firms with an appointed representative structure and simple systems |
| Regulated | £65 | All of the above plus identity management, retention configuration, restore testing, monthly board reporting | Most directly authorised advice, broking and lending firms |
| Regulated plus assurance | £85 | All of the above plus supplier register maintenance, incident triage against FCA thresholds, resilience testing, annual review with compliance | Firms in scope of SYSC 15A or third party reporting |
What moves an IT support for financial services quote up or down
Legacy on-premises servers, a bespoke back-office platform, call recording, multiple offices, out-of-hours cover, and the number of Microsoft 365 tenants in a group all push a quote upward. A single modern tenant, cloud-only applications, standard devices and one office push it down. The largest single variable is usually whether the firm asks IT support for financial services to own the evidence or merely to keep the lights on.
Project costs sit outside the monthly fee
Expect one-off costs for tenant remediation, identity redesign, retention configuration, backup deployment and migration off a legacy server. For a forty-seat firm those typically land as a single project rather than a monthly increment, and they are the work that makes an IT support for financial services fee defensible. Our broader analysis of IT outsourcing cost in the UK sets out how in-house, managed and co-managed models compare on total cost.
The cost of not doing it, in one number
The Financial Ombudsman Service charges respondent businesses a case fee of £680 for 2026/27, against a case fee allowance worth £2,000 per financial year. The allowance absorbs 2.94 cases. A firm with ten ombudsman cases in a year pays £6,800 gross, £4,800 after the allowance — before any redress, and before the staff time. Poor IT support for financial services generates complaints, and complaints have a per-unit price.
A Worked Example: A 40-Seat Advice and Broking Firm
To make the cost of IT support for financial services concrete, here is a modelled firm: 40 users, of whom 28 are fee-earning advisers and brokers, 8 are administrative and 4 are management. Every figure below is arithmetic on prices already stated in this article.
The licensing decision, priced four ways
At published UK list prices, 40 users cost £11,808 a year on Business Premium, £16,080 on E3, and £24,768 on E5. A tiered estate of 10 E5 licences and 30 Business Premium licences costs £15,048, which is 60.76% of the all-E5 figure and saves £9,720 a year. All-Business-Premium is 47.67% of all-E5. For most firms of this shape, IT support for financial services should propose the tiered option, which buys the eDiscovery capability where it is needed without paying for it forty times.
The IT support for financial services cost, priced three ways
At the three tiers above, 40 users cost £21,600, £31,200 or £40,800 a year. Expressed per fee-earner — dividing by the 28 advisers and brokers — that is £771.43, £1,114.29 or £1,457.14 per fee-earner per year. The gap between the cheapest and the most expensive tier is 1.89×, and the difference in what is delivered is the entire evidence layer.
Total annual technology cost for the modelled firm, assembled
Take the middle support tier and the tiered licensing: £31,200 + £15,048 = £46,248 a year, plus £440 + VAT for Cyber Essentials, plus backup and any call recording. Per user that is £1,156.20 a year before certification; per fee-earner it is £1,651.71. Those are the IT support for financial services numbers a board should be shown, not a per-user helpdesk rate in isolation.
Certification, and the group structure trap
At 40 staff the firm sits in the 10–49 band at £440 + VAT. If the same 40 people are split across three regulated entities certified separately, the cost becomes £1,320 — three times as much for the same estate. Have IT support for financial services decide the certification scope alongside the group structure, not after it.
What the firm still owns, whoever supplies IT support for financial services
No amount of provider spend removes the firm’s own obligations: naming the important business services, setting the tolerances, deciding the retention schedule against its permissions, approving the exclusions, and submitting the register. Good IT support for financial services makes each of those a half-hour decision with the evidence already assembled. It cannot make them for you.
Choosing a Provider: Twelve Questions and the Answers That Should Worry You
The proposal is not the product. These twelve questions separate suppliers of IT support for financial services who understand regulated firms from those who have simply added the word “compliance” to a template.
| Ask | A good answer | A worrying answer |
|---|---|---|
| Who owns our Microsoft 365 tenant and domain? | You do; here is how to verify it today | We manage that for you |
| Show me a restore you performed for another client | A redacted restore record with times and a verifier | Our backups have never failed |
| How fast will you tell us about an incident affecting us? | A contractual number in hours, plus who we call | As soon as we know |
| Which of your engineers will hold administrative access? | Named individuals, per-job elevation, logged | Our whole technical team |
| What retention policies would you configure for us? | A draft mapped to our permissions and activities | We keep everything forever |
| How do you evidence an impact tolerance? | A test plan, results and a lessons-learned record | Our infrastructure is highly available |
| What is in your Cyber Essentials scope statement? | The certificate and the scope, offered unprompted | We are fully certified |
| Where will our data be stored and supported from? | Named regions and a data residency statement | The cloud |
| What happens on the day we leave? | A written exit plan with timings and deliverables | Nobody leaves us |
| Who at your firm has read PS26/2? | A named person who can summarise the thresholds | Our compliance partner handles that |
| How will you help us build the SUP 16.33 register? | From the asset and access inventory, with owners | We can send you a template |
| Can we speak to a regulated client of yours? | Two references in our sub-sector, arranged this week | We work with lots of financial firms |
Weight the answers, do not just collect them
Any provider can answer eleven of twelve well and fail on tenant ownership, which alone should end the conversation. Treat questions one, three and nine as pass or fail for any IT support for financial services proposal, and score the rest. If you are running a formal process, the discipline in our guide to switching IT support providers without disruption will save a month.
The 100-Point IT Support for Financial Services Scorecard
Score your current IT support for financial services arrangement honestly. Anything below 70 means the next incident will be handled by improvisation.
| Area | Test | Points |
|---|---|---|
| Ownership | The firm holds its own tenant, domain, licences and backup credentials | 12 |
| Identity | MFA everywhere, conditional access enforced, exclusions reviewed in the last year | 12 |
| Privileged access | Every administrative account named, owned and last-used date known | 8 |
| Backup and restore | Separate backup of Microsoft 365, immutable, with two documented restore tests a year | 12 |
| Retention | Policies configured in the tenant and mapped to the firm’s permissions | 10 |
| Resilience | Important business services named, tolerances set, mapping current, testing done | 10 |
| Incident readiness | Documented triage against the three FCA thresholds, with named deputies | 10 |
| Third parties | A live register with owners, jurisdictions, notice periods and data categories | 8 |
| Mail and fraud | Impersonation list populated, DMARC at enforcement, out-of-band rule tested | 8 |
| Communications capture | Every accepted channel recorded, retrievable per client, sampled periodically | 6 |
| Reporting | A monthly page a director can read, and an annual review with compliance present | 4 |
How to use the IT support for financial services score
Score it with your supplier of IT support for financial services in the room and make them justify each mark with an artefact. The conversation is the point. A provider who can produce evidence for eight areas out of eleven in a single meeting is a good provider; one who needs a fortnight to find anything is telling you where their weaknesses are.
A 90-Day Plan to Get From Where You Are to Defensible
With PS26/2 live on 18 March 2027 and 208 days remaining as of 22 August 2026, ninety days of deliberate IT support for financial services work leaves a comfortable margin.
| Days | Deliverable | Evidence produced |
|---|---|---|
| 1–10 | Verify tenant, domain and licence ownership; list every administrative account | Ownership statement and admin inventory |
| 11–20 | Close MFA gaps and review every conditional access exclusion | Signed exclusions register with an approver |
| 21–35 | Name important business services and set impact tolerances | Service list with tolerances and owners |
| 36–45 | Map each service to systems, suppliers, data and named people | Dependency map, one page per service |
| 46–55 | Configure retention against the firm’s permissions and activities | Retention policy screenshots and a schedule |
| 56–65 | Run a full restore test on the highest-priority service | Restore record with times and a verifier |
| 66–75 | Build the material third party register from the asset inventory | Register with nine populated columns |
| 76–85 | Write and rehearse the incident triage path against the three thresholds | Runbook plus one rehearsal record |
| 86–90 | Assemble the self-assessment and present it to the board | Versioned document under six-year retention |
Sequence beats speed in every IT support for financial services programme
Every step above produces an artefact that the next step reuses. Firms that run these in parallel with four different people produce four documents that do not reconcile. One owner of IT support for financial services, ninety days, nine artefacts.
Frequently Asked Questions About IT Support for Financial Services
Does the FCA require a specific provider of IT support for financial services?
No. The FCA regulates outcomes from IT support for financial services, not tooling. There is no register of approved IT suppliers and no such thing as FCA-certified software. What matters is whether the firm can evidence the outcome the rules require. Any provider claiming otherwise is describing a marketing position, not a regulatory one.
Is Microsoft 365 Business Premium enough for a regulated firm?
For most firms under 300 seats, yes — it carries the identity, device, mail security and retention capability needed to satisfy the majority of the obligations in this article. The step to E5 is justified by scale, by advanced eDiscovery needs, or by surveillance requirements, and it costs £324 per user per year more at list price.
Do the new incident reporting rules apply to small firms?
Yes, and IT support for financial services has to be ready. The FCA deliberately kept all firms with a Part 4A permission in scope, noting that incident impact is not limited to larger firms. Around 90% of FCA-regulated firms will use the short standard report rather than the enhanced one, but the obligation to detect, assess and report inside 24 hours applies either way.
Our cloud provider is now a designated Critical Third Party. Are we covered?
No. Designation gives the regulators oversight of that provider’s systemic services to the sector; it does not transfer your obligations. You still have to map your dependencies, set tolerances, test recovery and report your own incidents.
How long do we have to keep recorded calls?
Five years, extendable to seven where the FCA requests it. The important design consequence for IT support for financial services is that the storage platform must support extending a hold on a defined record set without rebuilding the retention scheme.
We are an appointed representative. Does any of this apply to us?
Your principal carries the regulatory obligations, but the systems holding client data are yours, and the principal will increasingly ask you to evidence the controls your IT support for financial services runs on them. Appointed representatives should expect the same identity, retention and supplier questions to arrive through their principal’s oversight programme.
What should IT support for financial services fix first if the budget is small?
Tenant ownership, then identity, then a tested restore, in that order. Those three cost comparatively little, remove the largest share of realistic loss, and produce evidence that every subsequent conversation depends on.
How do we know a provider of IT support for financial services understands regulated firms?
Ask any supplier of IT support for financial services to describe an impact tolerance and how they would evidence one. A provider that answers with uptime percentages has not read SYSC 15A. A provider that answers with a test plan, a restore record and a lessons-learned document has.
Can we run IT support for financial services in-house instead?
A firm with a genuine internal technology team can run IT support for financial services itself, and some do. Below roughly fifty staff the economics rarely work, because the firm is buying one person’s availability rather than a team’s coverage, and the evidence obligations do not shrink with headcount. Co-managed arrangements — internal ownership, external depth — are the usual middle ground.
Where does Cyber Essentials fit in the regulatory picture?
It is not an FCA requirement, but it is a proportionate baseline of five technical controls for IT support for financial services and it is increasingly asked for commercially. At £320 to £600 plus VAT depending on size, it is also the cheapest external validation available that the basics are in place.
References and Further Reading
FCA PS26/2: Operational incident and third party reporting
FCA PS26/2 policy statement (PDF)
PRA PS7/26: Operational incident and third-party reporting
FCA Handbook SYSC 15A: Operational resilience
FCA Handbook SYSC 15A.2: Operational resilience requirements
FCA Handbook SYSC 10A: Recording telephone conversations and electronic communications
FCA Handbook SYSC 9.1: General rules on record-keeping
FCA Handbook DISP 1.9: Complaints record rule
FCA Handbook SYSC 24: Allocation of prescribed responsibilities
FCA FG16/5: Guidance for firms outsourcing to the cloud and other third party IT services
FCA PS24/16: Operational resilience, critical third parties to the UK financial sector
HM Treasury: UK financial system strengthened with new safeguards for major technology providers
Bank of England: UK financial regulators to begin overseeing Critical Third Parties
FCA: Strengthening resilience across an increasingly interconnected financial system
FCA: Aggregate complaints data 2025 H2
FCA: TSB fined for operational resilience failings
Cyber Security Breaches Survey 2025/2026
Money Laundering Regulations 2017, regulation 40: record-keeping
IASME: Cyber Essentials certification and fees
Financial Ombudsman Service: case fees
Microsoft 365 Business plans and UK pricing
Microsoft 365 Enterprise plans and UK pricing