For most Irish IFAs, brokers, accountancy practices with FS clients, and other small regulated firms, the practical baseline is: Microsoft 365 (or equivalent) hardened with MFA everywhere, strong email protection, endpoint security, tested backups, a written incident-response plan, staff awareness, and a named IT partner who can evidence controls for GDPR, insurers, and — where it applies — DORA. Managed IT and cybersecurity from an Irish MSP typically starts around €45–€70 per user per month for support packages (Microsoft 365 licences usually billed separately). You do not need a bank-scale security team; you do need proportionate controls, clear third-party oversight, and a policy on AI tools before staff paste client data into ChatGPT.
1. Decide what “good enough” means for your firm — not for a bank
Start with your authorisation, client data, and how you actually work (email, CRM, cloud accounting, remote advice). Then map obligations:
- GDPR / Data Protection Act 2018 — applies if you process personal data (almost every FS SME does). Ireland’s Data Protection Commission (DPC) expects appropriate technical and organisational measures: access control, encryption where needed, breach readiness, and accountability. The DPC has also flagged specific risks when staff use AI/LLMs with personal data (see section 3).
- Central Bank expectations — even where a detailed IT rulebook is not spelled out for every firm type, supervisors care about operational resilience, outsourcing/third-party risk, and cyber hygiene. The Central Bank’s DORA pages and earlier cross-industry IT/outsourcing guidance are useful benchmarks.
- DORA (in force since 17 January 2025) — applies to a defined list of financial entity types under Regulation (EU) 2022/2554, not automatically to every tiny advisory business. Check your authorisation against Article 2 (and definitions in Article 3). Some smaller entities get a simplified ICT risk management framework (Article 16); microenterprises get further proportionality. Firms outside scope are still encouraged by the Central Bank to treat DORA as a good practice benchmark.
- Cyber insurance — applications commonly ask for MFA on email and admin accounts, endpoint protection, offline/immutable or well-isolated backups with restore tests, patching, and a documented incident plan. Exact wording varies by insurer; treat their questionnaire as a control checklist.
- NIS2 — for most DORA-in-scope financial entities, DORA acts as lex specialis for overlapping cyber risk-management and incident reporting. Do not assume NIS2 replaces your FS obligations; check with your compliance adviser if unsure.
Practical takeaway: write a one-page “ICT / cyber baseline” for the board or partners: what systems hold client data, who has access, who is the IT provider, how you backup and restore, and how you would notify if something goes wrong.
2. Put the non-negotiable controls in place (checklist)
These are the controls small FS firms are usually asked about by insurers, auditors, and (where relevant) supervisors:
Identity and access
- Enforce multi-factor authentication (MFA) for every mailbox, VPN/remote access, and administrator account. Prefer phishing-resistant methods where you can.
- Separate privileged (admin) accounts from day-to-day email accounts; review access when people join, leave, or change role.
- Block legacy authentication that bypasses MFA.
Email and collaboration
- Harden Microsoft 365 (or your platform): anti-phishing, Safe Links/Attachments or equivalent, external forwarding controls, and SPF, DKIM, and DMARC.
- Ireland’s NCSC has published Office 365 secure configuration guidance that is a solid reference for SMEs — use it as a hardening checklist, not a badge.
- Limit sharing of client folders; use sensitivity labels / DLP if you hold high volumes of personal or sensitive data.
Devices and networks
- Managed antivirus/EDR on laptops and servers; disk encryption (BitLocker or equivalent); automatic patching.
- Secure Wi-Fi and a clear rule for personal devices (BYOD) if advisers work from home.
Backups and recovery
- Backups that are off-site / isolated from the live environment (immutable or air-gapped options where proportionate).
- Document Recovery Time and Recovery Point objectives for critical systems (email, CRM, advice records).
- Test restores at least annually (and after major changes) — a backup you have never restored is a hope, not a control.
People and process
- Short, regular phishing awareness for advisers and admin staff.
- A written incident-response runbook: who to call, how to preserve evidence, when to involve the DPC (personal data breach), insurer, and — if in scope — major ICT incident reporting under DORA.
- Vendor list: email, cloud CRM, backup, MSP, AI tools — with contracts and a note on which support critical functions.
3. Treat AI and ChatGPT as a data-protection and third-party risk — not a productivity free-for-all
Staff will use AI whether you ban it or not. The safer path is a short, enforceable policy.
Ireland’s DPC guidance on AI, large language models and data protection (July 2024) is clear: if personal data goes into an AI tool, GDPR applies. Before you approve a tool, your organisation should understand:
- What data staff may input (client names, PPSNs, medical/financial detail — usually no for consumer GenAI).
- Whether the provider retains or re-uses prompts for training.
- Lawful basis, minimisation, retention, and how you would honour access/erasure requests.
- Security of the provider and any transfer outside the EEA.
- Accuracy risk — LLM outputs can be wrong; do not use them for unsupervised advice or automated decisions about clients.
Sensible default for IFAs and small FS firms:
- Allow approved tools only (e.g. enterprise Copilot with contractual data protections, or a vetted business plan) under a written Acceptable Use Policy.
- Ban pasting identifiable client data into free consumer ChatGPT / similar tools.
- Keep a human in the loop for anything client-facing.
- Record AI vendors on your third-party / processing inventory.
This is also third-party ICT risk in DORA language: if an AI or cloud tool supports a critical process, you remain responsible even when the provider fails.
4. Choose managed IT that matches FS reality (pricing and what to buy)
DIY IT breaks when someone is on leave, MFA locks out a partner, or a ransomware email hits on a Friday afternoon. For firms of roughly 5–40 users, a managed service is usually cheaper than a full-time IT hire and easier to evidence to insurers.
Indicative package pricing (Sweeney Computers, Ireland):
- Silver — from €45 per user / month
- Gold — from €70 per user / month
- Microsoft 365 licences — separate (you pay the licence cost on top of the managed package)
When comparing providers, ask specifically for FS-relevant deliverables:
| Ask the MSP | Why it matters |
|---|---|
| MFA, Conditional Access, and email hardening as standard | Stops most account-takeover and phishing losses |
| Documented backup + restore evidence | Insurance and continuity |
| Named escalation path / SLA | Incident response under pressure |
| Help with policies and evidence packs | GDPR accountability; DORA/third-party oversight where applicable |
| Clarity on who owns licences, data, and exit | Avoid lock-in and undocumented dependencies |
Pick Silver vs Gold based on how much security operations and proactive management you need — not on marketing labels. If you hold client money workflows, regulated advice records, or remote teams, favour the higher-touch package.
5. Worked example (illustrative — not a named client case study)
EXAMPLE scenario (illustrative — not a real client):
A Meath/Dublin-corridor IFA practice with about 12 users runs advice notes and client email in Microsoft 365, a cloud CRM, and shared advice PDFs. Before engagement they had MFA on some accounts only, consumer ChatGPT use by two advisers, and backups that had never been restore-tested.
A proportionate programme might look like:
- Enforce MFA and block legacy auth for all users and admins.
- Turn on Defender (or equivalent) anti-phishing and publish DMARC.
- Move backups to an isolated target; run a full mailbox + SharePoint restore test.
- Issue a one-page AI Acceptable Use Policy; replace consumer ChatGPT with an approved business tool or ban client-data prompts.
- Put the firm on a managed package (e.g. Gold from €70/user/month + M365 licences) with a written incident-response contact tree.
Outcomes to measure on your own engagement (use real figures only when you have them):
- MFA coverage across mailboxes
- Time to restore a sample SharePoint library
- Phishing simulation click rate after training
- Cyber insurance questionnaire completed with controls evidenced
Use this structure in your own board pack; only publish real metrics when you have them.
Trust signals (verifiable)
- Sweeney Computers is an Irish-owned MSP based in Meath, serving organisations that need practical managed IT and cybersecurity — including smaller financial services firms across Ireland.
- Managed packages: Silver from €45/user/month, Gold from €70/user/month; Microsoft 365 licences are separate.
- Focus: day-to-day IT support plus security controls that map to what GDPR, insurers, and (where relevant) DORA/Central Bank expectations actually ask for — without bank-scale theatre.
(No certifications, awards, or client names are claimed here beyond the facts above.)
Next step
If you run an IFA practice, brokerage, accountancy firm with FS clients, or another small regulated business in Ireland and want a clear view of gaps (MFA, email, backups, AI use, third-party risk), speak to Sweeney Computers about managed IT support and cybersecurity suited to financial services SMEs — starting from the Silver/Gold packages above. Bring your insurer questionnaire or a short list of systems that hold client data; that is enough to start a sensible conversation.


