Who proactively asks their software stack providers about security?
The results are in from ASIC's Cyber Pulse Survey, and the report has been released (12th November 2023). So much to unpack!
One of the points they make is around supply chain risk.
Without looking at the survey, I'm interested to know your thoughts on the percentage of advice firms that have already asked their software stack providers about the levels of security they have in place and can provide the evidence to show they did their DD.
What percentage do you think have this on file?
5 Replies
- roccomusumeciExploring Newcomer
I'm glad ASIC is keeping cybersecurity top of mind. Regarding supply chain risk, my guess is fewer than 20% of firms have proactively vetted their software vendors' security. Many see it as the vendor's responsibility. But we must take ownership too. If we don't ask the tough questions, we may be caught unaware. I think framing security reviews as collaborative partnerships, not interrogations, can open doors. Protecting client data is a shared priority.
- siran.taylor
Iress Contributor
Foe those who are not aware, the Iress Community now has a self serve section in the Trust Centre Knowledge Base.
This is a great first port of call for locating any of the standard Due Diligence documentation regarding Xplan and Iress.
- deborah.kent
Advisely Board
Fraser, we have an external IT guy who has ensured that we have all the necessary programs in place for cyber security, he also provides us with due diligence on any providers doesn't mean he is always happy with the answers he gets, however having someone external is a good thing for us as we would not be looking at this all the time.
- anne.graham
Advisely Board
Good question and I'd agree with jenny.brown
- jenny.brown
Advisely Board
Great point Fraser.Jack something I know we need to be more diligent about gathering, I would think less than 10% would have any evidence on file, hopefully I'm wrong.
Recent Discussions
Best Practice for Managing User Groups
Hi Network đź‘‹ Keen to tap into your collective wisdom on best practice strategies for managing user groups in Xplan. For practices that outsource administration and paraplanning, and need to grant th...michelle.butler.019 hours agoNetwork Navigator3Views0likes0CommentsSettings for client access to emails saved as Doc Notes
Does anyone know if or how I can change the standard setting in the client email template so that: Client Access = No At the moment the default is set to yes (as screen shot below) ...rebekah.young21 hours agoNetwork Navigator20Views1like2Comments🤓 Xplan Hint: Don’t let yourself be the last to know
Did you know you can subscribe to the release notes in Xplan? If you didn’t know, or if you did know but haven’t bothered yet, you’re missing out! By subscribing, you’ll get an email in your inbox ...courtney.youngblutt2 days agoIress Contributor7Views1like1Comment🤓Xplan Hint: Supercharge your Searches with Syntax
Did you know you can use search syntax in Xplan to create powerful and specific advanced searches—beyond what the basic interface allows? With just a few lines of code, you can target contact detai...andrew.wilson.02 days agoIress Contributor24Views2likes2Comments