Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

AI-assisted attackers can move from phishing to client data within hours. Financial advisory firms need tighter access, MFA, and response controls.

AI Attacks Can Reach Client Data in Hours
Insight ai

AI Attacks Can Reach Client Data in Hours

Sam McKay

The breach timeline has changed

For years, many financial advisory firms have treated a cyber breach as something that unfolds over days or weeks. Someone clicks a phishing link. An attacker gets a mailbox. The firm notices unusual activity later. IT starts tracing what happened.

That model is no longer safe.

A recent report on AI agents used in an enterprise network breach simulation showed how an attack path could move from initial access to deeper network compromise in roughly 10 hours. The point isn’t that every attacker can compromise every business in 10 hours. The point is that AI can compress the work that used to slow attackers down.

An attacker no longer needs to manually read hundreds of emails, test every access path, or patiently map a system over several days. AI tools can sort information, create convincing messages, identify likely targets, and test common pathways at a pace a small advisory firm won’t match manually.

For a wealth management business, that changes the risk calculation.

A compromised adviser mailbox can expose client review packs, fact finds, identity documents, portfolio information, bank account details, signed authorities, tax records, and correspondence about family structures. A compromised operations account can provide access to onboarding files, CRM records, document stores, workflow tools, and financial planning platforms.

The attacker doesn’t need to take down the whole firm to cause serious damage. They need one account with too much access, weak multi-factor authentication, or a team member who isn’t certain what to do when something feels wrong.

This is also a business issue, not just an IT issue. Firms in the USD 1M to USD 25M revenue range often carry $70K to $200K each year in operational leakage across rework, manual administration, slow onboarding, and fragmented systems. A security incident adds another layer of cost through downtime, client communication, compliance review, remediation work, and lost trust.

The practical response is not to stop using AI. It is to put access controls, human approval, and incident procedures around both your existing systems and the AI agents you introduce.

Why advisory firms are attractive targets

Financial advisory firms hold information that attackers can use immediately. Client identity data can support fraud. Email history can make impersonation attempts far more believable. Portfolio information gives an attacker context for a convincing request. A message that refers to a real client review, a known family member, or a recent rollover is much harder to spot than a generic phishing email.

Most firms also have an operating model that creates exposure:

  • Advisers work from email, CRM, planning software, document storage, and portfolio reporting tools.
  • Paraplanners and client service teams need broad access to keep advice documents moving.
  • External providers may access systems for IT, compliance, administration, or software support.
  • Senior staff are busy, which makes them more likely to approve a request that appears urgent and familiar.
  • Client service workflows often happen across inboxes, spreadsheets, shared drives, and practice management systems.

That last point matters. If a firm cannot clearly map where client information travels during onboarding, meeting preparation, and advice production, it will struggle to contain access during an incident.

The AI audit for financial advisory firms starts with that operational map. We look at where work begins, which people and systems touch the data, where approvals happen, and where a compromised account could create damage.

This isn’t about producing a long security checklist that sits in a folder. It is about understanding the real work your team does every day.

A phishing email is now the beginning, not the attack

Picture a common sequence.

A client service manager receives an email that appears to come from a software provider or a senior adviser. The message refers to an upcoming client meeting and asks them to review an attached document or reauthenticate their account. It looks credible because the attacker has gathered public information, scraped social media, or accessed an earlier email thread.

Once the attacker gets into the mailbox, AI can help them move faster. It can identify messages about client transfers, authority forms, onboarding, and financial planning. It can summarise relationships between staff, clients, custodians, accountants, and referral partners. It can draft replies in the tone of the person whose account it controls.

From there, the attacker may try to:

  • Reset passwords through email-based recovery paths.
  • Request MFA changes or new device enrolment.
  • Search for documents containing identity information.
  • Send fake payment or account-change instructions.
  • Impersonate an adviser to clients or staff.
  • Find privileged accounts through internal conversations and support tickets.
  • Locate shared credentials, API keys, or unprotected spreadsheets.
  • Create inbox rules that quietly forward messages outside the business.

In a small firm, one compromised account can be enough to expose a surprising amount of client data. The risk grows when staff share logins, use a single generic operations account, or retain access long after their role changes.

The response has to be designed around hours, not days.

If your team sees a suspicious login, an unexpected MFA prompt, a sent email they didn’t write, or a new inbox forwarding rule, the first question should not be, “Can we look at this tomorrow?” It should be, “Who can disable access now, preserve the evidence, and check whether client data has been touched?”

Tighten MFA before you add more automation

Multi-factor authentication is one of the clearest places to start, but not all MFA controls provide the same protection.

Text-message codes are better than passwords alone, yet they can be vulnerable to phishing and number-porting attacks. Push notification approvals can fail when a tired employee accepts an unexpected prompt just to make the alert stop.

For key systems, aim for phishing-resistant MFA where the platform supports it. This may include hardware security keys, passkeys, or authentication methods tied to a managed device. Prioritise the systems that hold or connect to client information:

  • Email and identity provider accounts.
  • CRM and practice management systems.
  • Document storage and e-signature platforms.
  • Financial planning and portfolio reporting platforms.
  • Password managers.
  • Remote access tools.
  • Accounting, billing, and payment platforms.
  • AI platforms that can access internal knowledge or documents.

MFA also needs operational controls around it. A help desk or outsourced IT provider should have a documented process for changing an MFA device, resetting a password, or granting emergency access. If a caller says they are a partner and need urgent access, the provider needs a verification step that cannot be bypassed by urgency or familiarity.

Review dormant accounts every month. Remove access when staff leave. Check that contractors and external providers have named accounts rather than shared logins. Require separate administrator accounts for people who need privileged access.

These aren’t glamorous improvements. They are the controls that stop a phishing incident becoming a client data incident.

Privileged access needs a smaller blast radius

Many advisory firms give people broad access because it makes daily work easier. The operations manager can see everything. The paraplanner can open every client folder. The IT provider has a permanent administrator account. The managing partner has a single login that can approve almost anything.

It works, until that account is compromised.

The better model is least-privilege access. Each person gets the access needed for their current role, not every access right they might possibly need. High-risk actions require another control.

For example, an adviser should be able to view the client information needed for their meetings. They should not automatically be able to change system-wide user settings. A paraplanner may prepare an advice document but should not have unrestricted access to payment systems. An IT provider may need administrator access, but it should be time-limited, logged, and used through a named account.

There are three practical questions to ask.

First, which accounts can access the most sensitive client data?

Second, which accounts can change permissions, reset passwords, create integrations, or disable security settings?

Third, if one of those accounts is compromised at 4:00 pm on a Friday, how quickly can you revoke access and confirm what it did?

If the answer to the third question is “we would call our IT provider and wait”, you have an incident-response gap.

The Omni operating model can help document the handoffs that create those gaps. Security controls work better when they reflect actual roles and workflows, rather than an organisation chart that hasn’t matched reality for two years.

AI agents can reduce manual work without creating open access

There is a tension here. Financial advisory firms need AI to reduce administrative drag. At the same time, every new tool and integration can create another access path.

The answer is not to give an AI agent unrestricted access to every system. The answer is to define its job narrowly, provide only the information it needs, log what it does, and retain human approval for consequential actions.

Take the Meeting Prep Agent from Omni ops. Its job is straightforward. Before a client review, it pulls approved portfolio data, recent communications, open tasks, and goal progress into a one-page brief for the adviser.

A secure end-to-end workflow might look like this:

  1. The agent runs only for clients with a scheduled meeting.
  2. It uses a service account with read-only access to approved data sources.
  3. It retrieves only the fields needed for the brief.
  4. It creates the draft in a controlled workspace, not a public AI chat.
  5. The adviser reviews the brief before the meeting.
  6. The agent logs the source systems accessed and the output created.
  7. The brief follows the firm’s document retention rules.

The agent does not send client emails. It does not change portfolios. It does not create new users. It does not have administrator rights.

That distinction matters. The Meeting Prep Agent can save advisers five to 10 hours per week in preparation and note-writing activity when deployed properly. Yet it should never become a shortcut around identity, access, or review controls.

The same principle applies to the Advice Document Agent. It can draft SOAs, ROAs, and file notes from a meeting transcript and the firm’s compliance template. That can reduce the paraplanner effort that often sits behind advice documents costing roughly $3K to $8K in internal labour and outsourced support.

But the agent should draft, not approve. It should not submit a document to a client, lodge an advice record, or make compliance declarations without a named person reviewing the output. The output needs version control, a clear record of the source material used, and approval steps that match the firm’s compliance process.

You can see how this fits across the wider Omni platform, where agents are designed around a specific operating job rather than broad, uncontrolled access to every system.

Incident response has to fit the first 10 hours

Most firms have some form of cyber policy. Far fewer have a response procedure that a stressed staff member can follow during the first hour of an incident.

A useful plan is short, specific, and practiced. It should answer five questions.

Who declares an incident? Staff need permission to escalate quickly. They should not worry about proving an attack before raising the alarm.

Who can disable access? Name the person and backup who can suspend accounts, revoke active sessions, remove inbox rules, and contact your IT provider.

What systems must be checked first? Start with identity provider logs, email rules and forwarding, recent MFA changes, privileged accounts, document storage access, and key client systems.

How do you preserve evidence? Avoid deleting suspicious messages or wiping devices before your security provider advises. Preserve logs, timestamps, messages, and screenshots.

Who communicates with clients and regulators? Prepare decision owners before an incident. Your response may require legal, cyber insurance, privacy, compliance, and client communication advice depending on the information involved.

Run a tabletop exercise with your leadership team. Use a realistic scenario: a client service manager receives unexpected MFA prompts, then notices that emails about account transfers have been marked as read. Give the team 30 minutes. Ask what happens in the first hour, the first four hours, and by the end of the day.

You will quickly see where responsibility is unclear.

This type of operating exercise is part of the work we cover in Omni advisory. The goal isn’t to make your firm paranoid. It is to make the right next action obvious when time is short.

If you want to map the exposure in your own workflows, Book a 60-min Omni Audit. You leave with three useful outputs, an operating map of the work, priority opportunities, and a practical view of where controls need to sit. There is no slide deck for the sake of a slide deck.

Focus on the work where data and delay meet

Client onboarding is a good example.

Many firms still take 30 to 60 days to move a new client from first conversation to a clean, complete onboarding file. Documents arrive by email. A team member chases missing ID. Risk-profile information is copied into several systems. An adviser reviews an incomplete pack, then sends more questions. The client loses momentum.

A Client Onboarding Agent can improve this workflow by running a guided fact-find, collecting KYC documents through approved channels, checking for missing information, and preparing a clean onboarding pack for adviser review.

Again, access design comes first.

The agent should request documents through a secure client portal, not by prompting clients to email passports or bank statements. It should flag missing or inconsistent information, not make identity verification decisions on its own. It should restrict access to the onboarding team and adviser assigned to that household. It should keep a log of document collection and approval steps.

Done well, this gives clients a better experience while reducing the temptation for staff to use insecure workarounds.

The financial case is usually clear. The $70K to $200K leakage band we often see in advisory firms is rarely one large waste item. It is accumulated friction. Repeated document chasing. Re-keying facts. Searching for the latest file. Preparing meetings from scratch. Rewriting notes. Correcting avoidable errors.

Secure automation can reduce that friction. Uncontrolled automation can magnify your risk. The difference is governance.

Build the next 30 days around control and clarity

You don’t need to rebuild every system this quarter. Start with the controls that reduce the chance a single phishing event becomes a firm-wide problem.

In the next 30 days, complete these actions:

  1. Enforce MFA across email, document storage, CRM, financial planning tools, and administrator accounts.
  2. Review every privileged account, shared login, external provider account, and dormant user.
  3. Disable unnecessary inbox forwarding and review email rules.
  4. Write a one-page incident escalation guide with named decision owners and contact details.
  5. Run a 30-minute breach tabletop exercise with partners, operations, compliance, and IT.
  6. Identify one workflow for controlled AI assistance, such as meeting preparation or onboarding.
  7. Define what that agent may read, what it may write, what it may never do, and who approves its output.

For a more detailed view of where AI can fit into your firm without creating unmanageable exposure, see Omni for financial advisory firms. You can also find practical operating material in our AI insights library.

AI-assisted attackers are getting faster. Your firm doesn’t need to respond by freezing every technology decision. It needs clearer access controls, fewer standing privileges, and a response plan that works before an incident turns into a client trust problem.

If you’d like to work through that with someone who understands the operational side of advisory firms, Book my Omni Audit. In 60 minutes, we’ll identify the workflows creating drag, the data access points creating risk, and the practical next moves for your firm.