Protect financial client information and sensitive communications

Secure accounts, email, and devices, and maintain security records for client, insurance, and regulatory reviews.

Or email hello@teclara.tech

Security risks

Protect client information throughout the relationship.

Client onboarding, payment instructions, and advisor departures require controlled access and clear records. Documenting these controls helps the firm respond to compliance and partner reviews.

  1. Onboarding

    Collect client identification documents

    Know-your-client records, void cheques, and statements often arrive as attachments. Define where these documents are stored and who is authorized to access them.

  2. Instructions

    A client asks to move money

    Attackers may impersonate clients or compromise mailboxes to send fraudulent transfer requests. Email controls help identify suspicious messages.

  3. Advisor departure

    An advisor leaves the firm

    When an advisor leaves, their mailbox, client folders, and devices hold records that belong to the firm. Access is removed on the agreed schedule, and mailbox retention follows the firm’s requirements.

  4. Review

    Compliance asks for evidence

    Dealer reviews, regulatory examinations, and partner assessments may require historical records showing how client information was protected.

Security controls

Reviews and incidents depend on the same underlying records

A reviewer may ask different questions from an insurer or a client, but each needs to know who had access, which controls were running, what was backed up, and how an alert was handled.

  • Identity

    Protect advisor and administrator accounts

    Multi-factor authentication, administrator controls, and sign-in monitoring help prevent unauthorized access using stolen credentials. The security team investigates suspicious sessions and inbox-rule changes under the agreed response process.

  • Email

    Reduce impersonation and transfer fraud

    Email controls filter phishing, fake-invoice, and impersonation attempts. The firm remains responsible for independently verifying changed payment or transfer instructions.

  • Access

    Limit access to client information

    Permissions, external sharing, and administrator roles are reviewed in Microsoft 365 or Google Workspace.

  • Devices

    Protect your work devices

    Managed endpoint protection, encryption, and security updates apply to supported laptops and phones covered by the service. The security team reviews alerts, investigates suspicious activity, and coordinates the response.

  • Recovery

    Test recovery for Microsoft 365 or Google Workspace

    We maintain independent backups of Microsoft 365 or Google Workspace data and test restores.

  • Evidence

    Keep control records current

    Scheduled reporting documents the controls Teclara operates, current gaps, and assigned actions. The firm uses those records in its own client, insurance, audit, or regulatory process.

Security documentation

Review requirements depend on the firm’s activities and registration.

We provide records of the technical controls we operate.

Dealer or regulator
How is client information protected, and would you know if an account were compromised?
Sign-in monitoring records, access reviews, and alert handling history for the systems we manage, with dates and a record of actions taken.
Bank or insurer partner
What controls do you run, and how would you tell us about an incident?
Control descriptions and evidence for the partner’s third-party risk review, which OSFI Guideline B-10 expects federally regulated financial institutions to carry out.
Cyber insurer, at renewal
Is MFA enforced? Are payment-change requests verified outside email?
MFA coverage and email protection reports. The firm documents its payment-verification procedure; we provide evidence of the account and email controls we manage.

Your responsibilities

The firm remains responsible for determining which laws, regulators, contractual duties, and notification requirements apply. Teclara operates and documents the security controls we manage but does not certify compliance or replace legal, compliance, insurance, or regulatory advisers. Portfolio, CRM, trading, policy, and custodian systems, other line-of-business applications, and local servers are included only when specified in the service agreement.

Managed Security & Compliance

Ongoing security for your accounts, devices, and data.

The security controls on this page run on the platform you use, with access controls, reporting, and maintenance schedules adapted to your firm.

On Microsoft 365

  • MFA, Conditional Access, and administrator controls
  • SharePoint and OneDrive access reviewed on a schedule
  • Managed endpoint protection on supported devices
  • Sign-in and sharing records retained for review

On Google Workspace

  • MFA and administrator access controls
  • Gmail phishing and impersonation protection
  • Shared-drive and external-sharing access reviewed
  • Admin and sign-in reporting retained for review

Configuration updates are part of the service. When our security baseline changes, your environment is updated without a separate project fee.

See the full service

Frequently asked questions.

Can you support regulatory or compliance reviews?

We operate and document the technical controls we manage, such as sign-in policies, access reviews, endpoint protection, monitoring, backup, and response records. Which laws, regulators, frameworks, and notification requirements apply depends on the firm and its activities. Teclara does not certify compliance or replace legal and compliance advisers.

Can you provide evidence for a cyber insurance application?

Yes. We review the insurer’s questions and provide current evidence for the security controls we manage. Requirements vary by insurer and policy, so the work supports the application but does not guarantee approval, coverage, or a claim outcome.

How are potential incidents handled?

The security team reviews alerts and follows the agreed response and escalation process around the clock. Available containment actions depend on the systems covered and the response actions authorized in your agreement. Legal, regulatory, client, and insurance notifications remain the firm’s decision with its advisers.

What can be recovered after ransomware or deletion?

Microsoft 365 or Google Workspace data in the backup scope can be restored to an available recovery point after the threat has been contained in the affected account or systems. Recovery time depends on the systems affected, data volume, dependencies, and agreed priorities. Portfolio, CRM, trading, policy, local-server, and custodian systems need their own recovery arrangements.

Is security awareness training included?

Yes. Managed Security & Compliance includes ongoing awareness training and safe phishing simulations. Training helps staff recognize impersonation, fraudulent invoices, and payment-change scams. It complements technical controls and your payment-verification procedures.

Client feedback

What a client says about working with us.

“Teclara materially improved both our operational responsiveness and our security posture.”

E.C.

Senior Leadership, GTA Consulting Firm

Wadhah Hussain, Founder of Teclara

Led by Wadhah Hussain, Teclara's founder

20+ years enterprise IT · Big Four alumnus · Microsoft & Google Cloud specialist

Short on time? Let your favourite AI sum up Teclara.

Review access to client information and communications

In a 30-minute conversation, we discuss client information, access controls, and the requirements your firm needs to meet. We agree on the next step. Technical checks and written findings belong to a separately scoped engagement.

hello@teclara.tech