Security · IT Support
Who Holds the Keys to Your Financial Services Firm?
20 July 2026

In financial services, a login is never just a login.
It is access to client money, regulated data, and the processes named individuals are personally accountable for.
That is what makes identity the highest-stakes domain of resilience for financial services firms. The question is whether your firm could evidence exactly who holds which keys — and whether one phished password would be enough to move money or expose client data.
This article relates to the Passwords & Access domain of the Technology Resilience Score. It looks at whether your firm controls access to the systems your regulatory obligations depend on — and whether you could prove it.
Why identity is a regulatory issue, not just a security one
The FCA's operational resilience framework asks firms to understand what their important business services depend on. Every one of those services depends on access control. Client money processes, payment approvals, portfolio systems, deal data — all of it sits behind credentials, and under SM&CR, accountability for the consequences sits with named people.
Payment diversion fraud remains one of the most reliable attacks against financial services firms, and it almost always starts the same way: a compromised mailbox, a period of quiet observation, then a convincing instruction at the right moment. No second factor, no second chance.
The access questions that decide the outcome
When something goes wrong, the questions are always the same. Who had access to the process? Was that access appropriate? When was it last reviewed? Could the person who approved the payment have been impersonated with a password alone? Firms with strong answers contain incidents. Firms without them explain themselves — to clients, auditors and the regulator.
Is your firm's technology environment resilient?
Find out where your firm stands on access control, and every other domain of resilience, with a free assessment for financial services firms.
Get your firm's Technology Resilience ScoreWhere access control quietly breaks down
Not by decision — by accumulation. A director whose account has admin rights left over from setup. A leaver in operations whose access outlived their notice period. MFA enforced on email but optional on the platform holding client data. An approver who can be impersonated because approval is an email, not an authenticated action.
Individually, each is survivable. Together they mean the firm cannot state, with evidence, who can touch client money today — and that is a finding waiting to be made.
What good looks like
In a well-run firm, multi-factor authentication is enforced for every user on every system that matters — including senior approvers, who are the most impersonated people in the building. Privileged accounts are separated and reviewed. Leavers lose access the same day, with a record to show it. Payment and client-money processes require authentication that a phished password cannot satisfy.
In that environment, access control stops being a vulnerability and becomes something the firm can evidence — to the FCA, to auditors, and to institutional clients doing due diligence.
How this TRS domain helps financial services firms improve
The Passwords & Access domain of the Technology Resilience Score helps firms assess how well identity is controlled. It asks questions such as:
- Is multi-factor authentication enforced for every user, with no exceptions?
- Are privileged and approval accounts separated and reviewed?
- How quickly is a leaver's access removed — and can we prove it?
- Could a phished password alone move client money?
- When did we last review who can access regulated data?
The result is a score out of 5. That score provides a clear baseline and a structured path to improvement — and a piece of evidence your resilience story can be built on.
The Technology Resilience Score gives financial services firms a clear benchmark across 10 domains, including Passwords & Access. Little Big Tech helps firms build an environment where access is controlled, evidenced and audit-ready. Find out more about our approach at our Technology Resilience Score™ framework.
Related reading
Is your firm's technology environment resilient?
Find out how prepared your firm really is to keep operating and evidence its resilience, with a free Technology Resilience Score™ for financial services.