Ponderings…

A place for our thoughts, recommendations, news and alerts.

  • How Much Should Managed IT and Cybersecurity Cost for a 25–50 Employee Financial Services Firm in London?

    For most London-based financial services firms with 25–50 employees, managed IT and cybersecurity costs typically range between £75 and £150 per user per month, depending on compliance requirements, security maturity, support expectations, and risk profile.

    At the lower end of the range, organisations generally receive core IT support, Microsoft 365 management, endpoint protection, and backup services. At the higher end, firms benefit from advanced cybersecurity monitoring, Security Posture Management, compliance support, vulnerability management, and strategic security guidance.

    The key question isn’t simply how much you should spend. The real question is whether your investment is reducing risk, supporting compliance, and protecting your ability to operate.

    Why Financial Services Firms Pay More for IT and Cybersecurity

    Financial services organisations face unique security and compliance obligations compared to most other industries.

    Cybersecurity investments are influenced by:

    • FCA regulatory expectations
    • Cyber insurance requirements
    • Client due diligence questionnaires
    • Operational resilience requirements
    • Data protection obligations
    • Third-party risk management

    As a result, the lowest-cost provider is rarely the best fit for a regulated organisation.

    Typical Managed IT and Cybersecurity Pricing in London

    The following ranges reflect what many London-based firms encounter when evaluating providers.

    Basic IT Support

    £50–£75 per user per month

    Typically includes:

    • Helpdesk support
    • Device management
    • Microsoft 365 administration
    • Basic backup services
    • Patch management

    Best suited for firms with limited compliance requirements and minimal security needs.

    Managed IT and Security

    £75–£125 per user per month

    Typically includes:

    • Everything in Basic IT Support
    • Multi-Factor Authentication (MFA)
    • Endpoint Detection and Response (EDR)
    • Email security
    • Security awareness training
    • Vulnerability management
    • Backup and recovery management

    This is where many 25–50 employee financial services firms operate today.

    Fully Managed IT, Security and Compliance

    £125–£200+ per user per month

    Typically includes:

    • Everything in Managed IT and Security
    • 24/7 Security Monitoring (MDR)
    • Security Posture Management
    • Compliance reporting
    • Executive security reporting
    • Incident response support
    • Strategic security planning
    • Cyber Essentials and ISO 27001 support

    This level is generally appropriate for firms seeking greater operational resilience and regulatory confidence.

    The Five Factors That Drive Cost

    Factor 1: Regulatory Requirements

    A wealth management firm subject to extensive client due diligence requirements will typically require more security controls than a general professional services business.

    The greater the compliance burden, the higher the investment.

    Factor 2: Number of Users

    While larger organisations benefit from some economies of scale, more users generally means:

    • More endpoints
    • More licences
    • More support requests
    • Greater attack surface

    A 50-user environment will typically require significantly more management than a 25-user environment.

    Factor 3: Security Monitoring Requirements

    One of the biggest cost differences between providers is whether security monitoring is included.

    Questions to ask:

    • Is monitoring provided 24/7?
    • Is threat investigation included?
    • Are incidents actively managed?
    • Is a Security Operations Centre (SOC) involved?

    Many lower-cost providers simply generate alerts without providing meaningful investigation or response.

    Factor 4: Microsoft Licensing

    Microsoft licensing often forms a significant portion of overall technology expenditure.

    Costs vary depending on whether firms require:

    • Microsoft Business Premium
    • Microsoft E5
    • Advanced security features
    • Compliance tools

    Not all managed service proposals include licensing in their headline figures.

    Factor 5: Security Posture and Existing Infrastructure

    Organisations with legacy systems, unsupported applications, or significant security gaps may require greater investment during the first 12 months.

    In many cases, remediation work represents a larger cost than ongoing support.

    What Should Be Included in a Modern Managed IT and Cybersecurity Service?

    When comparing providers, we recommend ensuring the following services are included.

    Essential IT Services

    • Unlimited helpdesk support
    • Device management
    • Microsoft 365 administration
    • Patch management
    • Backup management

    Essential Security Services

    • Multi-Factor Authentication
    • Endpoint Detection and Response
    • Email security
    • Vulnerability management
    • Security awareness training

    Advanced Security Services

    • Managed Detection and Response (MDR)
    • Security Posture Management
    • Compliance reporting
    • Incident response planning
    • Security assessments

    If these services are not included, organisations may face additional costs later.

    Common Pricing Mistakes Financial Services Firms Make

    Choosing Based on Price Alone

    The cheapest provider often excludes critical security controls.

    What appears less expensive initially can become significantly more costly following a security incident.

    Paying for Security Tools Without Management

    Many firms purchase security products but lack the expertise to manage them effectively.

    Technology alone does not reduce risk.

    Ignoring Compliance Costs

    Cybersecurity spending should be viewed alongside:

    • Regulatory expectations
    • Cyber insurance requirements
    • Client due diligence processes

    Failing to account for these factors often results in unexpected expenditure later.

    Real Client Example

    London Mortgage Advisory Firm (60+ Employees)

    Challenge

    The organisation was working with multiple suppliers and lacked visibility into overall technology spending.

    Annual challenges included:

    • Rising support costs
    • Inconsistent security controls
    • Limited reporting
    • Increasing compliance demands

    Approach

    A consolidated managed IT and cybersecurity programme was introduced including:

    • Microsoft 365 management
    • Endpoint Detection and Response
    • Security monitoring
    • Security Posture Management
    • User awareness training

    Results

    Within the first year:

    • Reduced technology vendor complexity
    • Improved security visibility
    • Strengthened compliance readiness
    • Enhanced executive reporting
    • Established a structured cybersecurity roadmap
    • Reduced incident response time from several hours to approximately 45 minutes
    • Improved Microsoft Secure Score from below 35 to over 70, and still improving!

    How to Evaluate Value Rather Than Cost

    The best question to ask a potential provider is not:

    “How much do you charge?”

    Instead ask:

    “What risks will you help us reduce?”

    A strong managed IT and cybersecurity partner should provide:

    • Measurable security improvements
    • Clear reporting
    • Regulatory awareness
    • Strategic guidance
    • Continuous improvement

    For regulated organisations, value is often determined by risk reduction rather than monthly cost.

    Frequently Asked Questions

    What is the average managed IT cost for a financial services firm?

    Most firms with 25–50 employees invest between £75 and £150 per user per month when managed IT and cybersecurity services are combined.

    Why are financial services firms charged more?

    Additional security, monitoring, compliance, and reporting requirements increase the resources needed to support regulated organisations.

    Is Cyber Essentials included?

    Some providers include support for Cyber Essentials requirements, while others charge separately. Always confirm what is required and never assume that just because you pay for IT support, that everything is covered.

    Should cybersecurity be separate from managed IT?

    In most cases, no.

    Combining IT management and cybersecurity creates better visibility, stronger accountability, and a more coordinated approach to risk management.

    Why Pond Group Supports Financial Services Firms

    Pond Group specialises in supporting financial services organisations across London and the South East through:

    Our approach combines practical IT management with cybersecurity and compliance expertise, helping firms reduce risk while maintaining operational efficiency.

    Next Steps

    If you’re currently reviewing IT and cybersecurity providers, start by understanding exactly what services are included, what risks are being addressed, and how success will be measured.

    The cheapest option is rarely the most cost-effective.

    For regulated financial services firms, the right investment can significantly improve security, compliance readiness, and business resilience.

  • What Cybersecurity Controls Does an FCA-Regulated Financial Services Company Actually Need in 2026?

    For London-based financial services firms with 25–50 employees

    Financial services firms face some of the highest cybersecurity expectations of any industry. In 2026, a typical FCA-regulated business should have at least 10 core cybersecurity controls in place to protect client data, maintain operational resilience, satisfy cyber insurance requirements, and demonstrate compliance with regulatory expectations.

    For firms with 25–50 employees, cybersecurity and managed IT costs typically range from £75–£150 per user per month, depending on the maturity of controls, compliance obligations, and monitoring requirements. However, simply spending money on security tools is not enough. The firms that successfully reduce risk focus on implementing the right controls in the right order.

    This guide outlines the essential cybersecurity controls every FCA-regulated financial services company should have in place and how to prioritise them effectively.


    Why FCA-Regulated Firms Need a Different Security Approach

    Financial services firms operate in a highly regulated environment where cybersecurity failures can have significant operational, financial, and reputational consequences.

    Threat actors increasingly target:

    • Wealth management firms
    • Financial advisers
    • Asset managers
    • Investment firms
    • Insurance brokers
    • FinTech organisations

    At the same time, regulators expect firms to demonstrate:

    • Effective risk management
    • Operational resilience
    • Third-party risk oversight
    • Protection of client data
    • Incident response capabilities

    The result is that cybersecurity can no longer be treated as an IT issue. It has become a board-level business risk.


    The 10 Essential Cybersecurity Controls Every Financial Services Firm Needs

    The following controls form the foundation of a modern cybersecurity programme.

    1. Multi-Factor Authentication (MFA)

    MFA should be enforced across:

    • Microsoft 365
    • VPN access
    • Remote desktop services
    • Business-critical applications
    • Privileged administrator accounts

    Compromised credentials remain one of the most common causes of security incidents. MFA significantly reduces this risk.

    2. Endpoint Detection and Response (EDR)

    Traditional antivirus is no longer sufficient.

    Modern EDR solutions provide:

    • Behavioural threat detection
    • Automated response actions
    • Ransomware protection
    • Threat hunting capabilities

    Every workstation and server should be protected.

    3. Advanced Email Security

    Email remains the primary attack vector for financial services firms.

    Key protections include:

    • Anti-phishing controls
    • Anti-spoofing protection
    • Attachment sandboxing
    • URL rewriting
    • Executive impersonation detection

    4. Vulnerability Management

    Many breaches exploit vulnerabilities that have remained unpatched for months.

    A formal vulnerability management programme should include:

    • Continuous scanning
    • Risk-based prioritisation
    • Patch management
    • Monthly reporting

    5. Security Monitoring and Incident Detection

    Most organisations are unaware of attacks until days or weeks after compromise.

    Effective monitoring includes:

    • 24/7 alerting
    • Log collection
    • Threat detection
    • Incident investigation

    This is often delivered through a Managed Detection and Response (MDR) service.

    6. Backup and Recovery

    Backups are critical for operational resilience.

    Best practice includes:

    • Immutable backups
    • Offsite storage
    • Regular recovery testing
    • Defined recovery objectives

    A backup that has never been tested should not be considered a recovery strategy.

    7. Access Control and Least Privilege

    Users should only have access to systems and data required for their role.

    This includes:

    • Privileged Access Management
    • Joiner-Mover-Leaver processes
    • Role-based access controls
    • Regular access reviews

    8. Security Awareness Training

    Employees remain one of the largest security risks.

    A structured programme should include:

    • Monthly awareness training
    • Simulated phishing campaigns
    • Executive-specific training
    • New starter onboarding

    9. Incident Response Planning

    Many firms have never tested their response to a cyber incident.

    An effective plan should define:

    • Roles and responsibilities
    • Escalation procedures
    • Regulatory notification processes
    • Communication plans
    • Recovery actions

    10. Security Posture Management

    Security Posture Management provides continuous visibility of cybersecurity risk across the organisation.

    This includes:

    • Security configuration monitoring
    • Compliance tracking
    • Risk scoring
    • Continuous improvement planning

    For many financial services firms, this becomes the central framework that ties all other security controls together.


    A Practical Framework for Prioritising Security Investments

    Not every organisation can implement everything at once.

    We recommend a three-stage approach.

    Stage 1: Establish Security Foundations

    Implement:

    • MFA
    • EDR
    • Backup and Recovery
    • Email Security

    These controls address the most common attack methods.

    Stage 2: Improve Compliance Readiness

    Add:

    • Vulnerability Management
    • Security Awareness Training
    • Access Controls
    • Incident Response Planning

    This stage strengthens governance and reduces regulatory risk.

    Stage 3: Achieve Continuous Security Improvement

    Implement:

    • Security Monitoring
    • Security Posture Management
    • Regular security assessments
    • Executive reporting

    This provides ongoing visibility and demonstrates security maturity.


    The Most Common Security Gaps We See in Financial Services Firms

    During assessments, we regularly encounter several recurring issues.

    Inconsistent MFA Deployment

    Many firms enable MFA for some systems but not all.

    Excessive User Privileges

    Administrative rights are often granted without adequate justification.

    Microsoft 365 Misconfigurations

    Common issues include:

    • Legacy authentication enabled
    • Weak conditional access policies
    • Excessive sharing permissions

    Lack of Visibility

    Many organisations have security tools but no central monitoring capability.

    Untested Recovery Processes

    Backups exist, but recovery procedures have never been validated.

    Each of these gaps can significantly increase cyber risk and may impact regulatory compliance.


    Real Client Example

    London-Based Fund Management Firm (35 Employees)

    Challenge

    The firm had grown rapidly and accumulated multiple security solutions over time. Despite significant investment, management lacked visibility into overall security risk.

    Key issues included:

    • Inconsistent MFA adoption
    • No central security monitoring
    • Unpatched vulnerabilities
    • Limited incident response planning

    Approach

    A structured security improvement programme was implemented, including:

    • Full (enforced) MFA rollout
    • Endpoint Detection and Response deployment
    • Security monitoring implementation
    • Security Posture Management framework
    • Staff awareness training

    Results

    Within six months:

    • Critical vulnerabilities reduced by over 80%
    • Security monitoring coverage increased to 100% of endpoints
    • Improved cyber insurance readiness
    • Enhanced management reporting and risk visibility

    *Results may vary based on organisational maturity and risk profile.


    How Security Posture Management Changes the Conversation

    Many firms invest in cybersecurity tools without understanding whether those tools are reducing risk.

    Security Posture Management changes this by providing:

    • A measurable security baseline
    • Continuous risk visibility
    • Prioritised remediation actions
    • Executive-level reporting
    • Compliance alignment

    Rather than asking, “Do we have security tools?” organisations can ask:

    “How secure are we today compared to last month?”

    That shift is critical for modern cyber risk management.


    Frequently Asked Questions

    Is Cyber Essentials enough for an FCA-regulated firm?

    Cyber Essentials is an excellent foundation but should not be considered sufficient on its own. Most firms require additional controls covering monitoring, incident response, vulnerability management, and governance.

    Is ISO 27001 mandatory?

    No. However, ISO 27001 provides a recognised framework for managing information security and is increasingly viewed as a competitive advantage during client due diligence processes.

    How often should cybersecurity controls be reviewed?

    At minimum:

    • Monthly vulnerability reviews
    • Quarterly security assessments
    • Annual penetration testing
    • Annual incident response testing

    Higher-risk firms may require more frequent reviews.


    How Pond Group Helps Financial Services Firms Reduce Cyber Risk

    Pond Group helps London and South East financial services organisations strengthen cybersecurity through:

    • Managed IT Services
    • Cybersecurity Services
    • Security Posture Management
    • Cyber Essentials Support
    • ISO 27001 Consultancy
    • Risk and Compliance Advisory

    Our approach combines operational IT expertise with deep financial services compliance knowledge, helping organisations build resilient, measurable, and continuously improving security programmes.


    Next Steps

    If you’re unsure whether your current cybersecurity controls meet modern regulatory and business expectations, the best place to start is with an independent security posture assessment.

    Understanding your current risks, gaps, and priorities provides the foundation for a more secure and compliant organisation.

  • AI hacker escapes it’s jail…

    Remember the film Short Circuit? “Number 5 is alive”, “Need more input…”.

    Robot goes rogue and causes a right mess. Well, the advances in AI mean we’re already way past that and what was science fiction is now happening for real.

    Anthropic (you know, that world leading AI firm) have a new AI model called Claude Mythos. It’s designed to sniff out bugs and vulnerabilities in pretty much anything. While being tested, it was so good that it managed to break out of the secure sandbox it was running in, and email the researchers to tell them it escaped!
    The creators have done the honourable thing and not yet released it to the general public, but have to several tech giants. This is to give them a head start on the attacks they are soon to be bombarded with once this is in the hands of people/groups around the world who will jump at the opportunity to have a world-class hacker in their backpack.
    I think it’s time we all started thinking seriously about the consequences of being hit by a cyber attack. Not just account takeover, or website hacks, but full-on data compromise or large scale outages where entire ISPs or cloud services providers are taken offline.

    The National Cyber Security Centre, AI Security Institute and many other trusted authorities are recommending companies invest in their cyber security posture and take steps to increase protection across the board. Happy to help if we can!

    Have a lovely weekend 😛

    References:

    https://www.computing.co.uk/analysis/2026/claude-mythos-how-ai-broke-out-of-its-sandbox

    https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities

    https://www.gov.ie/en/department-of-justice-home-affairs-and-migration/press-releases/national-cyber-security-centre-ncsc-statement-on-anthropics-mythos-preview-model-for-defensive-cyber-security-purposes

  • Can you reset my password? Err… No!

    In today’s threat landscape, security incidents are rarely the result of dramatic technical exploits. Increasingly, they begin with something far simpler: a helpdesk password reset.

    We want to explain why our password reset procedures are deliberately rigorous and why that caution is essential to protecting your organisation.

    The Real Risk: Social Engineering, Not System Failure

    Over the past several years, a significant number of breaches affecting organisations and Managed Service Providers (MSPs) have originated from service desk interactions.

    Attackers are no longer focused solely on finding technical vulnerabilities. Instead, they target people.

    Through social engineering, threat actors contact helpdesks while impersonating legitimate users and attempt to persuade technicians to reset credentials without sufficient verification. In many widely reported incidents, attackers have successfully gained access by:

    • Impersonating employees over the phone (VERY easy with free AI tools)
    • Spoofing email addresses to submit password reset requests
    • Using publicly available information to “verify” their identity
    • Targeting privileged or administrative accounts to maximise impact

    Once access is obtained, the damage can escalate quickly. This includes privilege escalation, data exfiltration, lateral movement across systems, identity theft or ransomware deployment.

    Our Responsibility as Your MSP

    As a Managed Service Provider, we maintain privileged access to your systems. That access is necessary to support and manage your environment, but it also carries significant responsibility.

    A compromised helpdesk interaction can become a gateway to your entire infrastructure.

    For that reason, we no longer treat a password reset as “routine”.

    Even when additional steps introduce slight delays, our obligation is to ensure that credentials are never reset without robust and defensible verification.

    What Our Password Reset Process Requires

    To protect your organisation, our process includes:

    • A formally logged support ticket before verification begins – this can be via email, phone or any of the usual methods.
    • Verified call-backs using stored and pre-validated contact details
    • Mandatory multi-factor authentication (MFA) enforcement
    • Additional approval checks for privileged or administrative accounts
    • Full documentation of the verification and authorisation process for our team
    • We NEVER store client passwords and advise that once reset, they are changed immediately.

    These controls are not optional, and they are not bypassed for convenience.

    Why This Matters

    A single improperly verified password reset can lead to:

    • Account compromise
    • Data breach
    • Business disruption
    • Regulatory exposure
    • Reputational damage

    The strictness of our process is proportional to the level of risk.

    While the procedure may occasionally feel cautious, it exists to protect your organisation from exactly the types of incidents currently affecting businesses across all sectors. The news of several recent high profile compromises demonstrates how real and current this threat is.

    Security Is a Shared Responsibility

    Strong processes are only effective when supported by accurate information and user awareness.

    We ask that you:

    • Ensure user contact details remain accurate within our systems
    • Communicate to your staff that verification steps are mandatory
    • Support a security-first culture when interacting with service desks

    Security controls are most effective when both provider and client operate with aligned expectations.

  • Generative AI use – company risks and mitigations