- Brokerages hold passport data, travel patterns and payment details for high-profile individuals — a concentrated, attractive target.
- Email compromise is the dominant attack, and it is defeated by process controls more than by technology.
- Collect the minimum, retain it for a stated period, restrict access and delete on schedule.
- Have an incident plan written before you need it, including who notifies whom and within what deadline.
What a brokerage actually holds
A typical brokerage's systems contain passport scans and dates of birth, home and office addresses, movement patterns showing where named individuals will be and when, family and staff details, dietary and sometimes medical requirements, and payment instructions with bank details.
That combination is more sensitive than most brokerages assume. Travel-pattern data on identifiable high-net-worth individuals has physical-security implications, and it sits in the same mailbox as the invoices.
The realistic threat model
The dominant attack is not a sophisticated intrusion; it is business email compromise. An attacker obtains access to a mailbox — usually through a phished credential — monitors an active transaction, then inserts a payment instruction with altered bank details at the moment the client expects to pay.
The second common failure is a lost or unmanaged device holding client documents, and the third is over-broad access inside the firm: everyone can see everything because the firm was five people when the folder structure was created.
Minimisation and retention
Collect only what the operator or authority actually requires for the specific flight. Full passport scans are frequently requested out of habit when the required fields would suffice; each unnecessary copy is a liability with no offsetting benefit.
Set a retention period, write it down, and enforce it with a scheduled deletion routine. 'We keep everything forever in case it is useful' is not a retention policy and will not survive scrutiny under most data-protection regimes.
- Define required fields per document type and collect no more.
- Store documents in a controlled system, not in mailboxes.
- Set a written retention period aligned to legal and tax needs.
- Run scheduled deletion and record that it happened.
Controls a small firm can operate
Multi-factor authentication on email and on every system holding client data is the single highest-value control and is available at no meaningful cost. Beyond that: unique accounts per person, role-based access to client folders, full-disk encryption on laptops and phones, managed device wipe for departing staff, and a documented offboarding routine.
None of this requires a security department. It requires a checklist that is actually completed when someone joins and when someone leaves, and a quarterly review of who currently has access to what.
Third parties and transfers
Client data is routinely transmitted to operators, handling agents and authorities across borders. Know which processors you rely on, what they hold, where they hold it and under what contractual terms. Where your regime restricts international transfers, ensure a lawful mechanism is in place rather than assuming.
Send documents through a controlled channel where possible. Attaching passport scans to ordinary email is convenient and is exactly the practice that turns a mailbox compromise into a data breach.
Incident response
Write a one-page plan now: who is called first, who can lock accounts and reset credentials, who assesses whether personal data was affected, who notifies the regulator and within what deadline, and who communicates with affected clients.
Notification deadlines in several regimes are measured in hours, not weeks. A firm improvising the plan during the incident will miss them, and the regulatory consequence of a late notification frequently exceeds the consequence of the breach itself.
Practical checklists
- Multi-factor authentication enforced on email and core systems.
- Unique accounts and role-based access to client files.
- Documents stored in a controlled system rather than mailboxes.
- Written retention periods with scheduled deletion.
- Payment-detail change rule published to clients and staff.
- Processor inventory with locations and contractual terms.
- One-page incident plan with named roles and notification deadlines.
Frequently asked questions
- Do we need a formal data-protection officer?
- That depends on your jurisdiction and processing profile. Most small brokerages do not, but all of them need a named person accountable for these controls.
- Is encrypted email enough?
- It helps in transit but does not address the dominant risk, which is an attacker inside a legitimate mailbox. Process controls on payment changes matter more.
- • Brokerages hold unusually sensitive data for identifiable individuals.
- • Business email compromise is the dominant, preventable threat.
- • Minimise, restrict, retain briefly and delete on schedule.
- • Write the incident plan before the incident.