Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

A reported AI-assisted breach is a warning for advisory firms to control agent access, permissions, MFA, and ownership.

AI Agent Access After a 10-Hour Breach
Insight ai

AI Agent Access After a 10-Hour Breach

Sam McKay

The breach story advisory firms shouldn’t ignore

A recent SC Media report described a human attacker using AI agents to breach an enterprise network in under 10 hours.

The useful lesson isn’t that every financial advisory firm is about to be targeted by a sophisticated AI attack. It is that the old model of security review is no longer enough.

A person does not need to manually work through every login screen, search every shared drive, or test every weak permission. AI agents can accelerate reconnaissance, identify exposed systems, draft phishing content, test credentials, and move through a network faster than a person working alone.

For a financial advisory or wealth management firm, that should put one question on the agenda at the next partner meeting:

Which AI tools, automations, and agents currently have access to client data or firm systems, and who owns each one?

Most firms are already using some form of AI. It might be a meeting transcription tool. It might be an assistant that drafts client emails. It might be a CRM workflow that enriches records. It might be a staff member pasting client notes into a public AI tool to speed up an SOA draft.

None of those decisions are automatically wrong. The issue is unmanaged access.

An AI agent with access to your CRM, portfolio platform, email inbox, cloud drive, or document management system can save serious administrative time. It can also become an entry point if permissions are too broad, accounts are not protected by multi-factor authentication, or nobody is accountable for reviewing how the connection works.

The firms getting real value from AI aren’t treating it as a staff experiment. They’re building controlled workflows around specific jobs, then putting guardrails around every system connection.

Why advisory firms have more exposure than they think

Advisory firms hold a concentrated set of information that attackers value. Client identity documents, bank account details, portfolio balances, tax records, estate planning documents, signed authorities, risk profiles, and communications history often sit across several platforms.

A typical firm might use:

  • A CRM for client and prospect records
  • A portfolio reporting or investment management platform
  • Microsoft 365 or Google Workspace for email and files
  • Meeting transcription software
  • A document management system
  • An advice production workflow
  • E-signature tools
  • KYC and identity verification tools
  • Financial planning software
  • Shared spreadsheets that have somehow become part of the operating system

Each connection creates a decision about access. Can the tool read client data? Can it write data back? Can it send emails? Can it download documents? Does it retain prompts or transcripts? Does it use firm data to train its own model? Does a former employee’s account still have an active integration?

The hard part is that this risk rarely appears as a single obvious failure. It builds gradually.

A paraplanner connects an AI note-taking tool to their calendar. An adviser grants a transcript tool access to recorded client calls. An operations manager creates a no-code automation using their personal login. A team member shares a CRM export with an external AI assistant because they need a faster way to sort prospects.

Soon, the firm has five or 10 AI-enabled workflows. Each one may be useful. Yet no one has a single register showing what has access to what.

That is where a secure AI access review starts.

Start with an AI access inventory, not an AI policy

Many firms begin by writing an AI policy. Policies matter, but they don’t tell you what is already connected to the business.

You need an inventory first.

The inventory should cover every AI tool, automation, browser extension, transcription service, chatbot, integration platform, and internal agent that touches firm information. Don’t limit the exercise to technology officially bought by the business. Include staff-led tools, free trials, and personal accounts used for work.

For each tool or agent, record six things:

  1. The business job it performs
    Be specific. “AI meeting tool” isn’t enough. “Creates a draft file note from a client review meeting” is useful.

  2. The systems it can access
    List the CRM, mailbox, calendar, portfolio platform, cloud storage, document platform, or other source.

  3. The level of permission granted
    Read-only access is different from the ability to edit records, create documents, send email, or delete files.

  4. The data it can see
    Note if it handles names, contact details, financial information, identity documents, investment records, meeting recordings, or advice documents.

  5. The authentication method
    Confirm multi-factor authentication is enabled and identify whether the connection relies on an employee’s personal login, a shared login, or a dedicated service account.

  6. The human owner
    One named person must be responsible for the integration. Not “operations” or “IT”. A person.

This doesn’t need to become a 70-page technology assessment. A working spreadsheet is enough to begin. The value comes from forcing decisions that have been left implicit.

If an integration has no clear owner, broad permissions, and access to sensitive client records, it needs attention before it becomes part of a larger AI rollout.

For a wider view of where automation belongs in the firm, see Omni for financial advisory firms. The aim isn’t to add tools for the sake of it. It is to identify high-value workflows that can be automated without creating avoidable exposure.

Least privilege is the practical control

“Least privilege” sounds like security language, but the operating principle is simple.

Give an agent only the minimum access needed to do its job.

If a Meeting Prep Agent needs to read upcoming appointments, recent emails, portfolio changes, and goal progress, it should not need permission to send client emails, delete CRM records, or access every historical folder in the firm.

If an Advice Document Agent needs meeting transcripts and approved compliance templates, it should not be able to browse the whole shared drive or change the final signed document.

If a Client Onboarding Agent needs to request KYC documents and collect fact-find responses, it should not have authority to approve identity checks or open investment accounts.

These boundaries matter because AI agents are not simply another software subscription. Agents can perform multi-step actions. They can retrieve information from one system, apply logic, generate an output, and push it into another system. The more systems they can touch, the more important permission design becomes.

A practical access model for an advisory firm usually includes:

Read access separated from write access

Start new agents with read-only access where possible. Let them retrieve data and prepare drafts. Keep final updates to CRM records, client communications, advice documents, and workflow status behind human approval.

That approach slows down an agent by a few minutes. It can prevent a bad output from becoming a client-facing mistake or an irreversible data issue.

Dedicated service accounts

Don’t build a core workflow on an employee’s personal Microsoft or Google account. If they leave, their account may be disabled, their access may remain active, or the automation can fail without warning.

Use a dedicated service account for the agent where the platform supports it. Give it a clear name. Apply MFA. Document its permissions. Review it on a defined schedule.

MFA everywhere it can be enabled

Every administrator account, CRM integration account, automation platform account, cloud storage account, and AI vendor login should use MFA.

This sounds basic because it is basic. Yet firms often discover that an old administrator login, shared mailbox, or integration token was exempted years ago to make a workflow easier.

Attackers look for the exception.

Approval checkpoints for sensitive actions

An agent can prepare. A human should approve sensitive actions.

For advisory firms, that includes sending client emails, changing bank details, lodging advice documents, altering client risk data, authorising portfolio transactions, and marking KYC or compliance checks as complete.

This is not a rejection of automation. It is a sensible division of labour. Let the agent do repetitive preparation. Keep accountability with the licensed professional or authorised team member.

What controlled AI agents look like in an advice firm

The best place to prove AI value is usually not a broad chatbot. It is a narrow workflow where the work is repetitive, inputs are known, and a person already reviews the result.

Take the Meeting Prep Agent (Omni ops).

Before a client review, an adviser may spend 30 to 60 minutes opening portfolio reports, checking last meeting notes, reading recent emails, reviewing goal progress, and trying to remember outstanding actions. Across a week, meeting preparation and follow-up can absorb 5 to 10 hours per adviser.

A Meeting Prep Agent can pull approved information from defined sources and prepare a one-page brief. It might include portfolio movements, recent client communications, outstanding actions, progress against stated goals, and questions to address in the meeting.

The secure version of that workflow is not an agent with unrestricted access to every client file. It is an agent with read-only access to the relevant records for the next scheduled meeting. It creates a draft brief in a controlled location. The adviser reviews it before the meeting. The agent does not send it externally or change any source record.

The Advice Document Agent (Omni ops) follows the same principle.

SOAs, ROAs, and file notes can consume substantial paraplanner capacity. Industry ranges vary by complexity and jurisdiction, but firms commonly see internal paraplanner cost in the $3,000 to $8,000 range for substantial advice documentation. Cycle times can stretch into weeks when information is incomplete, meeting notes are inconsistent, and templates need repeated rework.

An Advice Document Agent can take an approved meeting transcript, structured fact-find information, and the firm’s current compliance template to create a first draft. It can flag missing fields, cross-reference sections, and format file notes consistently.

It should not publish the document, decide suitability, or use unapproved templates. It should operate inside the firm’s document environment, with access limited to the client matter it is preparing. A licensed adviser and compliance process remain responsible for the final document.

That is a practical point many owners miss. Secure AI access doesn’t mean building less useful agents. It means designing agents around real boundaries.

You can learn more about these operating workflows through Omni ops, where the focus is on removing repetitive work without handing over uncontrolled decision-making.

The hidden cost is bigger than a security incident

Security risks get attention because the downside is obvious. But unmanaged AI also creates an operating cost.

When staff don’t have an approved, governed workflow, they create workarounds. They download spreadsheets. Copy client notes between systems. Use personal accounts. Re-key information into templates. Ask the same questions twice because data is held in separate places.

That costs time and creates more data exposure, not less.

For a financial advisory firm in the $1 million to $25 million revenue range, we usually see annual process leakage in the $70,000 to $200,000 band. It is rarely one dramatic problem. It is the accumulated cost of adviser time spent on preparation, paraplanner rework, delayed onboarding, duplicated data entry, and compliance follow-up.

Client onboarding is a clear example.

A 30 to 60 day onboarding process is common when document collection, risk profiling, identity verification, and fact-find information move through email chains and incomplete forms. Prospects lose momentum. Staff chase documents. Advisers spend time asking for information that could have been collected properly the first time.

A Client Onboarding Agent (Omni ops) can run a guided fact-find, request the right KYC documents, track missing items, and prepare a clean onboarding pack for adviser review.

The access design matters here too. The agent should collect documents into an approved environment. It should restrict access to the assigned team. It should flag missing or inconsistent information. It should not make the final KYC determination or send sensitive files into unsecured channels.

A controlled workflow is often safer than the current manual process because it reduces the number of inboxes, spreadsheets, and informal handoffs where information can be lost.

If you want a structured view of this across your firm, Book a 60-min Omni Audit. We use the time to identify the processes worth automating, the systems involved, and the access controls needed before build work starts.

Assign ownership before you scale

Every AI integration needs a business owner. This is different from the IT person who configured it.

The business owner is accountable for answering:

  • Why does this agent exist?
  • What client or firm data can it access?
  • Which systems does it connect to?
  • What permissions does it have?
  • Who approves sensitive outputs?
  • What happens if the owner leaves?
  • When was access last reviewed?
  • How do we disable it if there is a security concern?

For a small to mid-sized advisory firm, ownership may sit with a head of advice, operations manager, chief compliance officer, or a partner. The title matters less than the clarity.

Review ownership quarterly, and review it immediately when you change vendors, migrate systems, bring on a new staff member with administrator rights, or discover an unapproved tool.

This is also why AI work should not sit entirely with a single enthusiastic team member. That person may know how the workflow works, but the firm needs documentation, security controls, and management visibility.

The broader Omni advisory approach is designed for this kind of decision. It connects the operating problem, the technology design, and the commercial return. A useful agent has to work inside the way your firm actually handles clients, compliance, and accountability.

A 60-minute audit can create a practical starting point

You don’t need to solve every security and automation question in one workshop.

Start with the workflows carrying the most manual load and the most sensitive data. Meeting preparation, advice documentation, and onboarding are usually good places to begin because the work is visible, repetitive, and measurable.

An Omni Audit takes 60 minutes and produces three practical outputs:

  1. A view of the manual workflows creating the largest cost or delay
  2. A shortlist of AI agent opportunities, including the systems and data each one needs
  3. A priority plan for access controls, human approvals, ownership, and implementation order

There is no presentation deck designed to impress you. The point is to leave with a clear picture of what to fix first.

The report of an AI-assisted breach should not push advisory firms away from AI. It should push them away from unmanaged AI.

Your firm can reduce 5 to 10 hours of weekly adviser administration. It can shorten document cycles. It can stop onboarding from drifting for 30 days or more. But each agent needs a defined job, MFA-protected access, least-privilege permissions, and a named human owner.

For a closer look at the process, see the AI audit for financial advisory firms. When you’re ready to map the real opportunities and the controls around them, Book my Omni Audit.