Home  /  Services  /  Cyber & Compliance

In the plan

Security built for a regulated industry.

Every BrokerReady client gets enforced MFA, endpoint protection monitored around the clock, tested restores, and privileged access reviews. It’s included from day one, we don’t quote it separately, and we keep the records as we go.

The problem

What makes a brokerage worth targeting.

01

You hold the things worth stealing

Client identity documents, payment instructions, policy histories, trust account details. A ten-person brokerage often holds the same kind of data as a bank branch, with a fraction of the security budget.

02

It only takes one person

Nearly every incident we deal with starts with a staff member opening an attachment, or following instructions on a page that looked legitimate. No amount of care removes the risk entirely, but you can control the blast radius.

03

The cost isn’t just the cleanup

A day of downtime during renewal season, a notifiable data breach, and a set of conversations with your licensee and your clients that you’ll be having for months.

The Solution

The security measures we impliment.

  • Identity protection. MFA enforced on every account, conditional access set by user, device and location, with admin accounts kept separate from the ones people work in.
  • Endpoint protection. Detection and response on every machine, watched around the clock by a security operations team. If a device is compromised at 2am it gets isolated, and you hear about it in the morning.
  • Vulnerability scanning and management. Continuous scanning across operating systems and third-party software, which is usually where the gaps are. Every month you get a report of what we found, patching metrics, and what's still outstanding with the reason and a plan to close it.
  • Access tracking and logging. A running record of who can reach what, with alerts in place for major access changes. Everything is logged with associated timestamps for better visibility.
  • Backup and disaster recovery. Backups run daily, and we restore from them on a schedule to prove they work. You get the date of the last successful restore and what came back.
  • Essential Eight ML1 alignment, by default. Every client sits on the Maturity Level One baseline from the day we take the environment on. We re-check it on a schedule, and you'll see where you stand against each of the eight.
In practice

The defence mechanism in action

  • AN ATTACK STARTS

    A pop-up tells a staff member to paste something in to proceed.

    A page they had no reason to distrust throws an error and walks them through a quick fix: copy this, paste it into the Run box, press enter. The industry calls it ClickFix, and it works because the instructions look like the ones IT would give. The people who fall for it are usually the careful ones.

  • IT GETS CONTAINED

    The script runs, and the device comes off the network.

    What it pulls down gets killed on what it’s doing rather than on what it’s called, within seconds of the first action. Nobody had to decide anything.

  • WE CALL YOU

    The team picks it up and gets straight on the phone.

    Two calls at once: one to the person whose machine it was, so they know what’s happened and stop sitting there thinking they’ve destroyed the business, and one to whoever needs to know at your end. While that’s going on we’re working out where it came from, what it ran, and whether it reached anything else.

  • BACK TO WORK

    The laptop’s rebuilt and they’re back working.

    The same link pulled out of any other inbox it landed in, passwords reset, the machine clean. The only person at your end who had to deal with any of this was the one whose laptop went quiet for a couple of hours.

  • YOU GET THE REPORT

    An incident report either way, whether the attack succeeded or not.

    What happened, what we did, and what it reached. Everyone ends up on the same page, and it tells us what to change: a control to tighten, or training for the people who saw it and the ones who didn’t.

VISIBILITY

You can see what you're paying for.

Most security work happens in the background without you noticing. These are the things that are delivered to you, and when

What you getWhenWhat’s in it
Security gap assessmentDuring onboardingYou see what was in place before, anything that was missing, and what we’ve added during the onboarding process.
Vulnerability reportMonthlyWhat we found across your operating systems and third-party software, what we’ve patched, and what’s still open with the reason and a plan to resolve it.
Incident reportEvery incidentIncluding the ones stopped in seconds. What happened, what we did about it, and how far it reached.
Access change alertsAs they happenMaterial changes to who has access to what data within your environment.

Swipe the table sideways to see all three columns →

Everything here is produced as the work happens. When your licensee or your insurer asks, you are forwarding something you already have rather than building it that week.

How it is charged

In the plan.

Not a project, and not an upsell
How it usually works

Endpoint protection, monitoring, vulnerability management and assessments get quoted as separate line items, then quoted again the next time something needs looking at.

How we run it

All of it is part of how every BrokerReady client is run, at one per-user price. We keep the baseline consistent across the board, which is why we can model our pricing this way.

When security is an optional extra, it is often the first thing cut.
What’s quoted separately

Essential Eight Maturity Level Two and Three, extended log retention, and formal audit support. These change how people work and carry a real operational cost, so they get scoped individually.

Not sure if you need more? Just ask. We’ll tell you if the answer is nothing.

Common questions

What people ask about cybersecurity.

We already have antivirus. Is that not enough?
Antivirus checks a file against a list of things already known to be bad. Most of what we see now isn’t on any list — it’s a legitimate Windows tool being used badly, or a script written that morning. What runs on the machines we manage watches what a process does and stops it on that basis, and there’s a team watching the alerts it raises.
Will this slow my staff down?
A bit, in specific places. MFA adds a few seconds at sign-in, and a new device gets challenged the first time it’s used. Where we’ve had a choice we’ve taken the least disruptive option that still holds up. If a control is causing real friction we’d rather hear about it and look at alternatives, because people who are fighting a control end up working around it.
Who is watching outside business hours?
A security operations team, continuously. Detections are triaged by people as they come in, and a compromised device can be isolated at 3am without waiting for anyone at your end to wake up. Our service desk hours are for the things that can wait.
Does this cover our broking platform, or only Microsoft 365?
Both. Access to the broking system is part of the same access review and the same offboarding process, which is the bit that usually falls through the gap when the broking platform is somebody else’s problem.
What happens if the gap assessment finds problems?
It will, on the first run. Nearly every environment we pick up has something — a shared login, an exempt account nobody remembers creating, a backup that’s never been restore-tested. You get the list, in priority order, with what it’d take to fix each one. Nothing’s left out to make the report look better.
You mention Essential Eight ML1. Does that make us compliant?
There’s no Essential Eight certification, so nobody can make you compliant with it. Maturity Level One is a baseline we build your environment to and measure against on a schedule, which is what a licensee or an insurer is actually asking about. Higher maturity levels are achievable and get scoped separately, because they carry a real operational cost.
Are you doing an audit, or just the IT?
Just the IT, and the evidence that comes out of running it properly. We’re not auditors and we don’t sign anything off. What we do is make sure that when an auditor, a licensee or an insurer asks a question, the answer already exists and holds up.
Our licensee has not asked for any of this. Why does it matter?
Because the request usually arrives with a deadline attached, and the work takes weeks if none of it has been running. The firms that find it painful are the ones starting from nothing the week they’re asked. It’s also increasingly the insurer who asks first.
We already have cyber insurance. Is that not enough?
Insurance pays out after something happens, and only if the questionnaire you filled in was accurate. It won’t stop the incident, give you back the time you lost, or repair the client relationship afterwards. It's worth having, but not a substitute for the controls that stop you needing it.
The rest of it

The other four services.

Not sure about what you've got covered? Let’s talk.

Thirty minutes to go through what’s already in place, what’s missing, and what we’d do first.