A place for our thoughts, recommendations, news and alerts.
- How Much Should Managed IT and Cybersecurity Cost for a 25–50 Employee Financial Services Firm in London?
For most London-based financial services firms with 25–50 employees, managed IT and cybersecurity costs typically range between £75 and £150 per user per month, depending on compliance requirements, security maturity, support expectations, and risk profile.
At the lower end of the range, organisations generally receive core IT support, Microsoft 365 management, endpoint protection, and backup services. At the higher end, firms benefit from advanced cybersecurity monitoring, Security Posture Management, compliance support, vulnerability management, and strategic security guidance.
The key question isn’t simply how much you should spend. The real question is whether your investment is reducing risk, supporting compliance, and protecting your ability to operate.
Why Financial Services Firms Pay More for IT and Cybersecurity
Financial services organisations face unique security and compliance obligations compared to most other industries.
Cybersecurity investments are influenced by:
- FCA regulatory expectations
- Cyber insurance requirements
- Client due diligence questionnaires
- Operational resilience requirements
- Data protection obligations
- Third-party risk management
As a result, the lowest-cost provider is rarely the best fit for a regulated organisation.
Typical Managed IT and Cybersecurity Pricing in London
The following ranges reflect what many London-based firms encounter when evaluating providers.
Basic IT Support
£50–£75 per user per month
Typically includes:
- Helpdesk support
- Device management
- Microsoft 365 administration
- Basic backup services
- Patch management
Best suited for firms with limited compliance requirements and minimal security needs.
Managed IT and Security
£75–£125 per user per month
Typically includes:
- Everything in Basic IT Support
- Multi-Factor Authentication (MFA)
- Endpoint Detection and Response (EDR)
- Email security
- Security awareness training
- Vulnerability management
- Backup and recovery management
This is where many 25–50 employee financial services firms operate today.
Fully Managed IT, Security and Compliance
£125–£200+ per user per month
Typically includes:
- Everything in Managed IT and Security
- 24/7 Security Monitoring (MDR)
- Security Posture Management
- Compliance reporting
- Executive security reporting
- Incident response support
- Strategic security planning
- Cyber Essentials and ISO 27001 support
This level is generally appropriate for firms seeking greater operational resilience and regulatory confidence.
The Five Factors That Drive Cost
Factor 1: Regulatory Requirements
A wealth management firm subject to extensive client due diligence requirements will typically require more security controls than a general professional services business.
The greater the compliance burden, the higher the investment.
Factor 2: Number of Users
While larger organisations benefit from some economies of scale, more users generally means:
- More endpoints
- More licences
- More support requests
- Greater attack surface
A 50-user environment will typically require significantly more management than a 25-user environment.
Factor 3: Security Monitoring Requirements
One of the biggest cost differences between providers is whether security monitoring is included.
Questions to ask:
- Is monitoring provided 24/7?
- Is threat investigation included?
- Are incidents actively managed?
- Is a Security Operations Centre (SOC) involved?
Many lower-cost providers simply generate alerts without providing meaningful investigation or response.
Factor 4: Microsoft Licensing
Microsoft licensing often forms a significant portion of overall technology expenditure.
Costs vary depending on whether firms require:
- Microsoft Business Premium
- Microsoft E5
- Advanced security features
- Compliance tools
Not all managed service proposals include licensing in their headline figures.
Factor 5: Security Posture and Existing Infrastructure
Organisations with legacy systems, unsupported applications, or significant security gaps may require greater investment during the first 12 months.
In many cases, remediation work represents a larger cost than ongoing support.
What Should Be Included in a Modern Managed IT and Cybersecurity Service?
When comparing providers, we recommend ensuring the following services are included.
Essential IT Services
- Unlimited helpdesk support
- Device management
- Microsoft 365 administration
- Patch management
- Backup management
Essential Security Services
- Multi-Factor Authentication
- Endpoint Detection and Response
- Email security
- Vulnerability management
- Security awareness training
Advanced Security Services
- Managed Detection and Response (MDR)
- Security Posture Management
- Compliance reporting
- Incident response planning
- Security assessments
If these services are not included, organisations may face additional costs later.
Common Pricing Mistakes Financial Services Firms Make
Choosing Based on Price Alone
The cheapest provider often excludes critical security controls.
What appears less expensive initially can become significantly more costly following a security incident.
Paying for Security Tools Without Management
Many firms purchase security products but lack the expertise to manage them effectively.
Technology alone does not reduce risk.
Ignoring Compliance Costs
Cybersecurity spending should be viewed alongside:
- Regulatory expectations
- Cyber insurance requirements
- Client due diligence processes
Failing to account for these factors often results in unexpected expenditure later.
Real Client Example
London Mortgage Advisory Firm (60+ Employees)
Challenge
The organisation was working with multiple suppliers and lacked visibility into overall technology spending.
Annual challenges included:
- Rising support costs
- Inconsistent security controls
- Limited reporting
- Increasing compliance demands
Approach
A consolidated managed IT and cybersecurity programme was introduced including:
- Microsoft 365 management
- Endpoint Detection and Response
- Security monitoring
- Security Posture Management
- User awareness training
Results
Within the first year:
- Reduced technology vendor complexity
- Improved security visibility
- Strengthened compliance readiness
- Enhanced executive reporting
- Established a structured cybersecurity roadmap
- Reduced incident response time from several hours to approximately 45 minutes
- Improved Microsoft Secure Score from below 35 to over 70, and still improving!
How to Evaluate Value Rather Than Cost
The best question to ask a potential provider is not:
“How much do you charge?”
Instead ask:
“What risks will you help us reduce?”
A strong managed IT and cybersecurity partner should provide:
- Measurable security improvements
- Clear reporting
- Regulatory awareness
- Strategic guidance
- Continuous improvement
For regulated organisations, value is often determined by risk reduction rather than monthly cost.
Frequently Asked Questions
What is the average managed IT cost for a financial services firm?
Most firms with 25–50 employees invest between £75 and £150 per user per month when managed IT and cybersecurity services are combined.
Why are financial services firms charged more?
Additional security, monitoring, compliance, and reporting requirements increase the resources needed to support regulated organisations.
Is Cyber Essentials included?
Some providers include support for Cyber Essentials requirements, while others charge separately. Always confirm what is required and never assume that just because you pay for IT support, that everything is covered.
Should cybersecurity be separate from managed IT?
In most cases, no.
Combining IT management and cybersecurity creates better visibility, stronger accountability, and a more coordinated approach to risk management.
Why Pond Group Supports Financial Services Firms
Pond Group specialises in supporting financial services organisations across London and the South East through:
- Managed IT Services
- Cybersecurity Services
- Security Posture Management
- Cyber Essentials Support
- ISO 27001 certified Consultancy
- Compliance and Risk Management
Our approach combines practical IT management with cybersecurity and compliance expertise, helping firms reduce risk while maintaining operational efficiency.
Next Steps
If you’re currently reviewing IT and cybersecurity providers, start by understanding exactly what services are included, what risks are being addressed, and how success will be measured.
The cheapest option is rarely the most cost-effective.
For regulated financial services firms, the right investment can significantly improve security, compliance readiness, and business resilience.
- What Cybersecurity Controls Does an FCA-Regulated Financial Services Company Actually Need in 2026?
For London-based financial services firms with 25–50 employees
Financial services firms face some of the highest cybersecurity expectations of any industry. In 2026, a typical FCA-regulated business should have at least 10 core cybersecurity controls in place to protect client data, maintain operational resilience, satisfy cyber insurance requirements, and demonstrate compliance with regulatory expectations.
For firms with 25–50 employees, cybersecurity and managed IT costs typically range from £75–£150 per user per month, depending on the maturity of controls, compliance obligations, and monitoring requirements. However, simply spending money on security tools is not enough. The firms that successfully reduce risk focus on implementing the right controls in the right order.
This guide outlines the essential cybersecurity controls every FCA-regulated financial services company should have in place and how to prioritise them effectively.
Why FCA-Regulated Firms Need a Different Security Approach
Financial services firms operate in a highly regulated environment where cybersecurity failures can have significant operational, financial, and reputational consequences.
Threat actors increasingly target:
- Wealth management firms
- Financial advisers
- Asset managers
- Investment firms
- Insurance brokers
- FinTech organisations
At the same time, regulators expect firms to demonstrate:
- Effective risk management
- Operational resilience
- Third-party risk oversight
- Protection of client data
- Incident response capabilities
The result is that cybersecurity can no longer be treated as an IT issue. It has become a board-level business risk.
The 10 Essential Cybersecurity Controls Every Financial Services Firm Needs
The following controls form the foundation of a modern cybersecurity programme.
1. Multi-Factor Authentication (MFA)
MFA should be enforced across:
- Microsoft 365
- VPN access
- Remote desktop services
- Business-critical applications
- Privileged administrator accounts
Compromised credentials remain one of the most common causes of security incidents. MFA significantly reduces this risk.
2. Endpoint Detection and Response (EDR)
Traditional antivirus is no longer sufficient.
Modern EDR solutions provide:
- Behavioural threat detection
- Automated response actions
- Ransomware protection
- Threat hunting capabilities
Every workstation and server should be protected.
3. Advanced Email Security
Email remains the primary attack vector for financial services firms.
Key protections include:
- Anti-phishing controls
- Anti-spoofing protection
- Attachment sandboxing
- URL rewriting
- Executive impersonation detection
4. Vulnerability Management
Many breaches exploit vulnerabilities that have remained unpatched for months.
A formal vulnerability management programme should include:
- Continuous scanning
- Risk-based prioritisation
- Patch management
- Monthly reporting
5. Security Monitoring and Incident Detection
Most organisations are unaware of attacks until days or weeks after compromise.
Effective monitoring includes:
- 24/7 alerting
- Log collection
- Threat detection
- Incident investigation
This is often delivered through a Managed Detection and Response (MDR) service.
6. Backup and Recovery
Backups are critical for operational resilience.
Best practice includes:
- Immutable backups
- Offsite storage
- Regular recovery testing
- Defined recovery objectives
A backup that has never been tested should not be considered a recovery strategy.
7. Access Control and Least Privilege
Users should only have access to systems and data required for their role.
This includes:
- Privileged Access Management
- Joiner-Mover-Leaver processes
- Role-based access controls
- Regular access reviews
8. Security Awareness Training
Employees remain one of the largest security risks.
A structured programme should include:
- Monthly awareness training
- Simulated phishing campaigns
- Executive-specific training
- New starter onboarding
9. Incident Response Planning
Many firms have never tested their response to a cyber incident.
An effective plan should define:
- Roles and responsibilities
- Escalation procedures
- Regulatory notification processes
- Communication plans
- Recovery actions
10. Security Posture Management
Security Posture Management provides continuous visibility of cybersecurity risk across the organisation.
This includes:
- Security configuration monitoring
- Compliance tracking
- Risk scoring
- Continuous improvement planning
For many financial services firms, this becomes the central framework that ties all other security controls together.
A Practical Framework for Prioritising Security Investments
Not every organisation can implement everything at once.
We recommend a three-stage approach.
Stage 1: Establish Security Foundations
Implement:
- MFA
- EDR
- Backup and Recovery
- Email Security
These controls address the most common attack methods.
Stage 2: Improve Compliance Readiness
Add:
- Vulnerability Management
- Security Awareness Training
- Access Controls
- Incident Response Planning
This stage strengthens governance and reduces regulatory risk.
Stage 3: Achieve Continuous Security Improvement
Implement:
- Security Monitoring
- Security Posture Management
- Regular security assessments
- Executive reporting
This provides ongoing visibility and demonstrates security maturity.
The Most Common Security Gaps We See in Financial Services Firms
During assessments, we regularly encounter several recurring issues.
Inconsistent MFA Deployment
Many firms enable MFA for some systems but not all.
Excessive User Privileges
Administrative rights are often granted without adequate justification.
Microsoft 365 Misconfigurations
Common issues include:
- Legacy authentication enabled
- Weak conditional access policies
- Excessive sharing permissions
Lack of Visibility
Many organisations have security tools but no central monitoring capability.
Untested Recovery Processes
Backups exist, but recovery procedures have never been validated.
Each of these gaps can significantly increase cyber risk and may impact regulatory compliance.
Real Client Example
London-Based Fund Management Firm (35 Employees)
Challenge
The firm had grown rapidly and accumulated multiple security solutions over time. Despite significant investment, management lacked visibility into overall security risk.
Key issues included:
- Inconsistent MFA adoption
- No central security monitoring
- Unpatched vulnerabilities
- Limited incident response planning
Approach
A structured security improvement programme was implemented, including:
- Full (enforced) MFA rollout
- Endpoint Detection and Response deployment
- Security monitoring implementation
- Security Posture Management framework
- Staff awareness training
Results
Within six months:
- Critical vulnerabilities reduced by over 80%
- Security monitoring coverage increased to 100% of endpoints
- Improved cyber insurance readiness
- Enhanced management reporting and risk visibility
*Results may vary based on organisational maturity and risk profile.
How Security Posture Management Changes the Conversation
Many firms invest in cybersecurity tools without understanding whether those tools are reducing risk.
Security Posture Management changes this by providing:
- A measurable security baseline
- Continuous risk visibility
- Prioritised remediation actions
- Executive-level reporting
- Compliance alignment
Rather than asking, “Do we have security tools?” organisations can ask:
“How secure are we today compared to last month?”
That shift is critical for modern cyber risk management.
Frequently Asked Questions
Is Cyber Essentials enough for an FCA-regulated firm?
Cyber Essentials is an excellent foundation but should not be considered sufficient on its own. Most firms require additional controls covering monitoring, incident response, vulnerability management, and governance.
Is ISO 27001 mandatory?
No. However, ISO 27001 provides a recognised framework for managing information security and is increasingly viewed as a competitive advantage during client due diligence processes.
How often should cybersecurity controls be reviewed?
At minimum:
- Monthly vulnerability reviews
- Quarterly security assessments
- Annual penetration testing
- Annual incident response testing
Higher-risk firms may require more frequent reviews.
How Pond Group Helps Financial Services Firms Reduce Cyber Risk
Pond Group helps London and South East financial services organisations strengthen cybersecurity through:
- Managed IT Services
- Cybersecurity Services
- Security Posture Management
- Cyber Essentials Support
- ISO 27001 Consultancy
- Risk and Compliance Advisory
Our approach combines operational IT expertise with deep financial services compliance knowledge, helping organisations build resilient, measurable, and continuously improving security programmes.
Next Steps
If you’re unsure whether your current cybersecurity controls meet modern regulatory and business expectations, the best place to start is with an independent security posture assessment.
Understanding your current risks, gaps, and priorities provides the foundation for a more secure and compliant organisation.
- AI hacker escapes it’s jail…
Remember the film Short Circuit? “Number 5 is alive”, “Need more input…”.

Robot goes rogue and causes a right mess. Well, the advances in AI mean we’re already way past that and what was science fiction is now happening for real.
Anthropic (you know, that world leading AI firm) have a new AI model called Claude Mythos. It’s designed to sniff out bugs and vulnerabilities in pretty much anything. While being tested, it was so good that it managed to break out of the secure sandbox it was running in, and email the researchers to tell them it escaped!
The creators have done the honourable thing and not yet released it to the general public, but have to several tech giants. This is to give them a head start on the attacks they are soon to be bombarded with once this is in the hands of people/groups around the world who will jump at the opportunity to have a world-class hacker in their backpack.
I think it’s time we all started thinking seriously about the consequences of being hit by a cyber attack. Not just account takeover, or website hacks, but full-on data compromise or large scale outages where entire ISPs or cloud services providers are taken offline.The National Cyber Security Centre, AI Security Institute and many other trusted authorities are recommending companies invest in their cyber security posture and take steps to increase protection across the board. Happy to help if we can!
Have a lovely weekend 😛
References:
https://www.computing.co.uk/analysis/2026/claude-mythos-how-ai-broke-out-of-its-sandbox
https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities
- Can you reset my password? Err… No!

In today’s threat landscape, security incidents are rarely the result of dramatic technical exploits. Increasingly, they begin with something far simpler: a helpdesk password reset.
We want to explain why our password reset procedures are deliberately rigorous and why that caution is essential to protecting your organisation.
The Real Risk: Social Engineering, Not System Failure
Over the past several years, a significant number of breaches affecting organisations and Managed Service Providers (MSPs) have originated from service desk interactions.
Attackers are no longer focused solely on finding technical vulnerabilities. Instead, they target people.
Through social engineering, threat actors contact helpdesks while impersonating legitimate users and attempt to persuade technicians to reset credentials without sufficient verification. In many widely reported incidents, attackers have successfully gained access by:
- Impersonating employees over the phone (VERY easy with free AI tools)
- Spoofing email addresses to submit password reset requests
- Using publicly available information to “verify” their identity
- Targeting privileged or administrative accounts to maximise impact
Once access is obtained, the damage can escalate quickly. This includes privilege escalation, data exfiltration, lateral movement across systems, identity theft or ransomware deployment.
Our Responsibility as Your MSP
As a Managed Service Provider, we maintain privileged access to your systems. That access is necessary to support and manage your environment, but it also carries significant responsibility.
A compromised helpdesk interaction can become a gateway to your entire infrastructure.
For that reason, we no longer treat a password reset as “routine”.
Even when additional steps introduce slight delays, our obligation is to ensure that credentials are never reset without robust and defensible verification.
What Our Password Reset Process Requires
To protect your organisation, our process includes:
- A formally logged support ticket before verification begins – this can be via email, phone or any of the usual methods.
- Verified call-backs using stored and pre-validated contact details
- Mandatory multi-factor authentication (MFA) enforcement
- Additional approval checks for privileged or administrative accounts
- Full documentation of the verification and authorisation process for our team
- We NEVER store client passwords and advise that once reset, they are changed immediately.
These controls are not optional, and they are not bypassed for convenience.
Why This Matters
A single improperly verified password reset can lead to:
- Account compromise
- Data breach
- Business disruption
- Regulatory exposure
- Reputational damage
The strictness of our process is proportional to the level of risk.
While the procedure may occasionally feel cautious, it exists to protect your organisation from exactly the types of incidents currently affecting businesses across all sectors. The news of several recent high profile compromises demonstrates how real and current this threat is.
Security Is a Shared Responsibility
Strong processes are only effective when supported by accurate information and user awareness.
We ask that you:
- Ensure user contact details remain accurate within our systems
- Communicate to your staff that verification steps are mandatory
- Support a security-first culture when interacting with service desks
Security controls are most effective when both provider and client operate with aligned expectations.
- Generative AI use – company risks and mitigations

