01
Who this is for
Advice firms, operators, buyers
The firm
IFA networks and independents. SIPP and SSAS operators. Discretionary and advisory wealth firms. Usually 50-200 people, or a smaller firm whose client book already carries a 200-person risk.
Bristol first, then Bath, Exeter and the wider South West. A London wealth firm with a South West book is welcome too. And the firms doing the buying: consolidators and PE-backed platforms landing estate after estate, deal by deal.
If yours is a law firm, the sharper page is law firm IT security. The broader page for firms of 50-200 people is professional services IT.
The signs
- The FD is carrying IT on top of the day job.
- The next cyber form has landed, and the premium listens to the answers.
- Copilot is waiting on a tenant that still shares a drive called "Clients".
- The FCA put a date on incident and third-party reporting.
02
The FCA clock
In force 18 March 2027
The 2027 deadline
FCA incident and third-party reporting rules: final rules March 2026, in force 18 March 2027.
The standard tier of the new rules reaches most FCA-authorised firms, advice firms included. Qualifying operational incidents are reported through the FCA's Connect portal, and a register of material third-party arrangements is kept and stays current.
Your MSP contract, your platform, your back-office system: that register is IT work with a regulatory deadline, and 2026 is the preparation year the FCA gave firms. It is a bounded, board-readable project, and it belongs to whoever owns IT. If nobody does, that is the seat on this page.
The insurer
- MFA, patching, backups, access control: the questions on this year's form.
- The premium listens to the answers, and to the evidence behind them.
- CE+ from £2,950 answers most forms; ISO 27001 from £15,000 sits at the top end.
- The CE+ / ISO 27001 sprint builds the pack. We implement; an accredited assessor certifies.
03
The buyers
Consolidators and platforms
Consolidators
Every deal lands an estate somebody has to integrate.
Consolidators and PE-backed platforms are buying advice books at pace, and each completion hands the platform another tenant, another MSP contract, another back-office system. Integration is where the record sits: 250+ servers moved to Azure, and ISO 27001 and PCI DSS implemented in 12 months alongside.
If the platform needs a named senior inside an acquired firm, that is the Head of IT seat. If the acquired estate needs folding in on a deadline, the work is scoped to that deadline.
04
The AI angle
Saying yes, safely
AI, with the controls real
A wealth firm can say yes to AI once the tenant and the controls are real.
The blockers are real: client data in open shares, permissions nobody has reviewed, a regulator who will ask how the firm governs the tools it adopts. None of them is an argument for waiting. Each is a piece of work with a name on it.
The AI Opportunity Audit finds where AI pays in an advice business and what must be true first. Microsoft Copilot readiness closes oversharing before a 30-day pilot touches client files. And ISO 42001 readiness, part of the CE+ / ISO 27001 sprint from £6,500, gives the board a governance frame it can point to when the FCA, an insurer or a platform asks how AI is run.
05
Routes in
Six services, published prices
Pick the door
AI Opportunity Audit
Know where AI pays before you spend. The scored shortlist for an advice business.
FROM £4,950, FIXED
Fractional Head of IT & AI
The named senior above the MSP, the register and the renewal.
FROM £4,750 A MONTH
CE+ / ISO 27001 sprint
The insurer form and the platform questionnaire, answered with documents.
CE+ FROM £2,950 · ISO 27001 FROM £15,000 · ISO 42001 READINESS FROM £6,500
Microsoft Copilot readiness
Oversharing closed before anything touches client files. Then a 30-day pilot with the right people.
FROM £7,500, FIXED
Technology cost reduction
The whole technology bill, honestly scoped at diagnose. If the work will not pay for itself, we say so and stop.
FROM £4,950, FIXED
Production IT agent
One workflow put live. The agent answering our own line is the working example.
FROM £7,500, FIXED
All six services, and the framework they belong to, are on one page.
06
How it runs
Diagnose. Deliver. Decide.
01
Diagnose
We sit with the FD, the compliance lead and whoever holds the MSP contract. The insurer form, the register and the tenant come first.
02
Deliver
The board has an operating model, the insurer has evidence, and the register has an owner. You stop being the IT department.
03
Decide
Estates drift when nobody owns them. The fix is one or two days a week from someone who already knows your firm. Or keep the gains and run it yourselves: either way the firm is stronger.
07
What you leave with
Documents, owners, decisions
The pack
A named senior
Someone the MD can put in front of the board.
An insurer pack
Documents for the cyber questionnaire, owned.
The register, owned
Third-party arrangements mapped, ahead of the 2027 deadline.
A safe yes to AI
A tenant and controls that let the firm adopt, with evidence.
08
The record
Six facts, on the record
Proof
- 20+ years as Head of IT.
- 90% fewer incidents, service levels from 45% to 98%.
- ISO 27001 and PCI DSS implemented in 12 months.
- 80% off a live cloud bill, 250+ servers to Azure.
- The agent answering our phone line (0117 456 5486) is ours, in production.
- £130k for a full-time IT director. The seat here starts at £4,750 a month.
The detail sits on the proof page.
09
FAQs
Asked before, answered here
Do you understand IFA and SIPP IT security?
Yes. In an IFA or SIPP firm the job is client data, access, the tenant, and the evidence pack the insurer asks for, each with a named owner. We implement the controls. We do not pretend to be your compliance officer or your certification body.
Are you a Bristol IT support company?
No. We do not sell helpdesk or MSP tickets. The number is 0117, and the voice that answers it is our own AI call agent, in production. The offer is a named Head of IT plus the evidence.
Will this help with FCA or insurer questions?
The CE+ / ISO 27001 sprint is built for the insurance cyber questionnaire and for buyers who ask for CE+ or ISO 27001. FCA permissions stay with you and your compliance lead.
What are the FCA incident and third-party reporting rules?
Final rules land in March 2026 and take force on 18 March 2027. Most FCA-authorised firms, advice firms included, will report qualifying operational incidents and keep a register of material third-party arrangements. Building that register is a bounded piece of IT work, and 2026 is the year to do it.
Can a smaller IFA start the conversation?
Yes, when the risk is the client book rather than the headcount. The usual range is 50-200 people, and we say honestly at diagnose whether the fit is real.
Do you replace our outsourced IT?
You keep the MSP if it works. We sit above it, for the decisions, the evidence and the register.
We are a consolidator integrating acquired firms. Is this the right page?
Yes. The integration record is on the proof page. If you want a named senior inside a platform firm, that is the seat.
Can a wealth firm say yes to AI safely?
Yes, once the tenant and the controls are real. The AI Opportunity Audit finds where AI pays and what must be true first. Copilot readiness closes oversharing before a pilot touches client files. ISO 42001 readiness gives the board a governance frame it can point to.
10
Start the conversation
Bring the insurer form