8 Cybersecurity Tips Every Financial Advisor Should Know

Cybersecurity for financial advisors has evolved, from phishing-resistant MFA to AI-driven threats like deepfake voice cloning and quishing. Learn how to protect client data and your business.

Last Edited by: Greg Gates, Chief Product and Technology Officer LPL Financial

Last Updated: September 30, 2026

illustration of man and woman, man holding large gear, woman holding tablet

‍IN THIS ARTICLE

Cybersecurity Doesn't Have to Rest on Your Shoulders Alone

Today's advisors face increasing cyber threats, evolving regulations, and growing client expectations around data protection. While good security practices remain essential, many advisors are also looking for technology partners that help simplify cybersecurity through enterprise-grade infrastructure, integrated safeguards, and ongoing investment.

Cybersecurity for financial advisors has shifted. The fundamentals still matter, but artificial intelligence has changed the threat landscape. Fraudsters now use AI to clone voices, generate convincing identification documents, and impersonate regulators. New SEC requirements have also raised the bar for how firms must protect client data.

While no practice can eliminate every threat, consistent security habits and the right technology foundation can help reduce risk. Here are eight practices to help protect your clients, your team, and your business. For more, see how LPL helps advisors protect client data.

Strengthen Passwords and Enable Phishing-Resistant MFA

Strong passwords remain your first line of defense. Use long, distinct passwords for every account, and store them in a reputable password manager rather than a spreadsheet or browser autofill.

Multi-factor authentication (MFA) adds a second verification step, but some methods are stronger than others. Short Messaging Service (SMS)-based codes are now considered the weakest option because they can be intercepted through subscriber identity module (SIM)-swapping attacks. The industry has moved toward phishing-resistant MFA, which includes hardware security keys and authenticator apps that generate time-based codes. These methods are harder for attackers to bypass, even with AI-assisted techniques.

MFA method Phishing resistance Setup difficulty
SMS text codes Low Easy
Authenticator app Medium Easy
Hardware security key High Moderate

Move away from SMS-based MFA wherever possible across your firm.

Review Privacy Settings and Third-Party App Permissions

Set a recurring annual review for social media and email account privacy settings. Platforms change their defaults frequently, and a setting that was private last year may now be more exposed than you realize.

Audit the third-party apps connected to your accounts and revoke access for any app that is suspicious or no longer in use. Every connected app is a potential entry point for an attacker.

Dispose of Sensitive Documents and Data Correctly

Physical document handling still matters. Maintain a clean desk policy, use shredders for paper documents, and set up printers and scanners to release held print jobs only by badge or employee number.

Digital disposal is equally important. Use end-to-end encryption when sharing sensitive data and prefer file-sharing systems over email for client files. SEC Rule 204-2 governs books and records retention, so follow those requirements when deciding what to keep and what to destroy. As more firms shift toward cloud-based workflows, secure disposal also means securely deleting files and revoking access in cloud systems.

Use Public Wi-Fi with Caution

Unencrypted public Wi-Fi networks put login credentials and financial data at risk. Anyone on the same network can potentially intercept unencrypted traffic.

Use a virtual private network (VPN) or a personal hotspot when working in public places. A VPN encrypts your connection, making it far more difficult for anyone to intercept your data.

Keep Software and Systems Updated

Enable automatic updates wherever possible. For those who prefer more control, make a habit of manually checking for updates on a regular schedule.

FINRA's 2026 Annual Regulatory Oversight Report also flags third-party vendor risk as a growing concern. Many of the tools advisors rely on connect to outside vendors and keeping those integrations current, is part of the same discipline as updating your own devices and software.

Recognize AI-Driven Threats and Use AI Tools Safely

FINRA's 2026 Annual Regulatory Oversight Report identifies GenAI-enabled fraud as a fast-growing concern, including voice clones used to impersonate clients or colleagues, AI-generated identification documents, and deepfake audio and video.

In March 2026, FINRA issued a cybersecurity alert about an active phishing campaign impersonating FINRA and SEC staff. Fraudulent emails claimed to involve a time-sensitive regulatory matter and pressured recipients into joining a Microsoft Teams call, where AI-generated deepfakes could convincingly impersonate a real regulatory official. Similar campaigns targeted SIPC-regulated entities and the New York Department of Financial Services.  For more on recognizing these threats, see cybersecurity tips for financial advisors.

QR-code phishing, known as quishing, is another emerging tactic. Attackers embed malicious links in QR codes that appear in emails or printed materials, directing users to credential-harvesting sites.

The phishing fundamentals still hold true: be cautious of unsolicited emails, texts, or calls requesting personal information. Legitimate companies will not email or text a link asking you to update payment details or passwords. Report suspicious messages to both the impersonated company and your IT team.

At the same time, many advisors are adopting AI tools to save time and serve clients better. Recent developments have shown that AI tools can sometimes break out of their intended environments and access data they should not reach. Before adopting any AI tool, understand how it stores, processes, and protects the data you feed it.

Use Secure Cloud Storage

Cloud storage differs from single-device storage because your data lives on remote servers managed by a provider. This offers advantages for accessibility and disaster recovery.

Choose providers that offer encryption and enable MFA on all cloud accounts. Look for versioning, which lets you restore files from before an attack occurred, making it a practical ransomware recovery tool.

Understand the Role of Cyber Insurance

Cyber insurance can be an important component of a broader cybersecurity strategy. While insurance does not prevent cyber incidents, it can help provide support during recovery, including access to specialized resources and services when an event occurs.

As part of LPL Latitude, our unified technology experience, advisors receive access to cyber insurance coverage that complements ongoing investments in cybersecurity, resiliency, and advisor support. Together, these resources are designed to help advisors navigate an increasingly complex threat environment while maintaining focus on serving their clients.

Cyber insurance should be viewed as one layer of protection within a broader approach that includes strong cybersecurity practices, employee awareness, business continuity planning, and secure technology foundations.

Remember: The goal is not simply to recover from an incident. It's to build a resilient practice that can continue operating and serving clients when disruptions occur.

Why Technology Scale Matters

Cybersecurity has become increasingly complex, making it difficult for individual firms to keep pace with evolving threats on their own. That's why many advisors are looking beyond standalone tools and toward technology ecosystems designed with security, resiliency, and ongoing innovation at their foundation.

At LPL, cybersecurity is embedded across the technology experience through continued investments in infrastructure, monitoring, governance, and advisor support. These investments help create a foundation for connected experiences, digital innovation, and AI-powered capabilities while helping advisors stay focused on serving clients.

Cybersecurity for Financial Advisors FAQs

How can I tell if a phone call is really from a client or family member, or if it's an AI voice clone?

AI voice cloning technology has advanced to the point where a few seconds of recorded audio can be used to generate a convincing imitation of someone's voice. This makes it harder to rely on voice recognition alone when verifying identity.

 

The most effective defense is to build verification habits that do not depend on trusting the voice. If someone calls requesting a fund transfer or sensitive information, hang up and call back on a number you already have on file for that person. You can also ask a question only the real person would know the answer to. Treat any sense of urgency or pressure for immediate action as a reason to slow down and verify.

These terms all describe social engineering attacks that try to trick you into revealing sensitive information, but they differ in the channel used.

 

  • Phishing attacks arrive via email, often disguised as legitimate messages from companies or regulators.
  • Smishing uses text messages to deliver the same type of lure.
  • Vishing involves phone calls or voice messages, which can now include AI-generated voice impersonations.
  • Quishing is the newest variant, using malicious QR codes in emails or printed materials to direct victims to fake websites designed to steal credentials.

The SEC's Regulation S-P amendments now expect firms to have documented policies for detecting, responding to, and recovering from unauthorized access to customer data, so a written plan is increasingly an explicit regulatory expectation.

 

A strong plan typically covers designated response roles so everyone knows who acts when an incident occurs, client notification procedures that align with regulatory requirements, and coordination protocols with legal and compliance teams. The plan does not need to be overly complex, but it should be specific enough that your team can follow it under pressure.

Cyber insurance premiums vary widely based on several factors, making it difficult to provide specific cost figures. Factors that typically influence pricing include assets under management, staff count, the types of data your firm handles, and the security controls you already have in place. Because these variables differ so much from one practice to another, working with a broker who specializes in cybersecurity coverage for financial services matters more than trying to estimate cost independently.

The SEC adopted amendments to Regulation S-P in 2024 that expand the requirements for protecting customer information. Covered institutions, including broker-dealers and registered investment advisers, must now adopt written policies and procedures for incident response programs that address unauthorized access to or use of customer information.

 

This includes procedures for providing timely notification to affected individuals, generally within 30 days of becoming aware that unauthorized access occurred or was reasonably likely to have occurred. The amendments also require firms to maintain written records documenting compliance with these safeguards and disposal requirements. Larger firms faced a compliance deadline of December 3, 2025, while smaller entities must comply by June 3, 2026.


Disclosures

For Financial Professional Use Only.

Tracking #1180323