IT support for financial services and insurance companies

IT support for financial services firms is not a back-office concern that sits apart from the regulated side of the business. In a firm that holds a Part 4A permission, the state of your systems is part of your compliance position. The FCA does not draw a neat line between the advice you give or the policies you place and the infrastructure that stores the records proving you did it properly.

Computercentric has spent more than twenty years supporting small and medium-sized businesses across Birmingham, Walsall, Wolverhampton, Sutton Coldfield, Lichfield and the wider West Midlands, and a good number of those have been regulated firms.

Insurance brokers, advice practices, intermediaries and claims businesses tend to sit in an awkward middle ground. They are too small to justify a full internal IT department, and far too heavily regulated to leave systems to whoever in the office is best with computers.

Talk to us about IT support for your firm:

Team of IT professionals providing reliable and tailored IT support for small businesses in Birmingham, ensuring smooth operations and robust cybersecurity.

Managed IT services for financial services firms: what we include

Most firms come to us wanting two things at once. They want the day-to-day irritations to stop, and they want someone who can answer a compliance question without needing it explained first.

  • Unlimited helpdesk support for your staff, by phone, email and remote session
  • Full Microsoft 365 management, covering licensing, mailboxes, SharePoint, Teams and identity
  • Security monitoring across servers, endpoints and cloud accounts
  • Backup for both on-premise systems and Microsoft 365, with scheduled restore testing
  • Patch and update management for operating systems and third-party software
  • Device management and encryption for laptops, desktops and mobiles
  • Network, firewall and connectivity management across your offices
  • Business telephony, including VoIP systems and call routing
  • Secure remote access for advisers, account handlers and hybrid staff
  • Supplier and line management, so you have one number to call rather than five
  • Hardware procurement, build and configuration, ready to use on day one
  • Starter and leaver processes that actually remove access when someone leaves
  • System documentation and audit logs you can hand to a compliance reviewer
  • Ongoing IT planning tied to your business plan rather than to a sales cycle

The point of all of it is that your people spend their time on clients and cases rather than waiting for something to load.

Could you report an incident to the FCA in 24 hours?

Eight things that are hard to arrange once an incident has already started.

0
of 8
Not started
How UK businesses compare
Enforce MFA47%
Cyber in continuity plan44%
Board-level owner31%
Formal incident plan25%

Benchmarks: DSIT Cyber Security Breaches Survey 2025/2026. Nothing is recorded or sent.

Why regulated firms need more than general IT support

There is a principle in the FCA Handbook that catches a surprising number of firms off guard.

Under SYSC 8.1, you can outsource the work, but you cannot outsource the responsibility. If your IT provider misconfigures something and your firm ends up unable to evidence compliance, the regulator’s conversation is with you, not with them. That single fact should shape how a regulated firm chooses a provider, and yet most selection processes still come down to price per user and how quickly someone answers the phone.

Downtime carries a different weight here too. A manufacturer losing an afternoon loses an afternoon of production, which is painful but recoverable. A broker who cannot access the policy administration system during a renewal run is missing deadlines that carry client detriment, and an advice firm that cannot reach its back office system in the days before a suitability report is due has a problem that is regulatory as well as commercial. Renewal cycles and reporting deadlines do not move because your server did not come back up.

Then there is the question of what a generalist provider knows about evidence. Keeping a business running and keeping a business auditable are related but genuinely different jobs, and the second one requires somebody to have thought about retention periods, access logging, and whether the trail of who saw what still exists eighteen months later when somebody asks.

None of this means a regulated firm needs an enterprise-scale IT operation. It means the person looking after your systems should understand why you are asking the questions you are asking, and should be able to give you something in writing when your compliance consultant wants to see it.

Software support for brokers and advice firms: Acturis, Open GI, Intelligent Office and more

The platform your firm runs on is the platform your firm runs on, and no amount of general IT competence substitutes for understanding how it behaves. We support the environments these systems depend on, work with the vendors where escalation is needed, and take responsibility for everything underneath the application itself.

Broker management systems

Acturis holds the leading position in UK commercial broking and powers the extranet offerings of many of the main insurers, which means a broker’s day frequently involves moving between Acturis and half a dozen insurer portals with different authentication requirements.

Open GI serves around 500 intermediaries and handles roughly a third of UK insurance transactions across commercial and specialist personal lines. SSP remains widely used across the market.

What all three need from us is much the same: stable and properly sized connectivity, browser and endpoint configuration that does not fight the application, single sign-on that works without staff writing passwords down, and printing that behaves when documents need to go out.

One development worth flagging is that Applied Systems has withdrawn its Epic product from the UK broker market, so any firm still on that platform is facing a migration, and the data and integration planning around that is exactly the sort of project worth starting early rather than late.

Adviser back office and planning tools

Advice firms tend to run a back office system alongside a planning or cashflow tool, and the two need to talk to each other.

Intelligent Office from Intelliflo and Xplan from Iress remain the most widely deployed back-office platforms, with Curo and the newer Plannr taking share among firms seeking a lighter solution.

On the planning side, FE CashCalc, Voyant, FE Analytics and Defaqto all appear regularly.

Our work sits around these rather than inside them: making sure integrations authenticate reliably, that documents route into the right client record, that fact-find data is not being duplicated into a spreadsheet on somebody’s desktop, and that the whole chain still works when an adviser is at a client’s kitchen table rather than in the office.

Microsoft 365 as the layer underneath

Every platform above depends on identity, email and file access working properly, which is why Microsoft 365 configuration matters more in a regulated firm than the licence cost suggests.

We handle conditional access policies so that sign-ins from unexpected places are challenged, mailbox permissions so that shared inboxes do not quietly become a data protection problem, retention policies that match what your compliance manual says you keep, and SharePoint structures that a new joiner can navigate without asking three people where the renewals folder lives.

Supporting the environment, in practice, means we own the problem when something breaks even if the fault turns out to sit with a vendor. Your account handler does not need to work out whether an error is Acturis, the network, or Microsoft. That is our job.

What your platform actually depends on

Most days that go wrong go wrong below the application. Pick your system.

The stack underneath
Where it breaks

Dependencies drawn from vendor and developer documentation published by Acturis, Open GI, Iress, intelliflo, Time4Advice and Plannr, and from trade press reporting.

Cyber security for financial services

Firms that hold client money and client data are targeted differently from firms that do not, and the difference shows up in the type of attack rather than the volume.

The threats aimed at firms handling client money

Phishing remains the most common form of attack against UK businesses, reaching 38% of them in the year to late 2025, and 69% of affected businesses rated it the most disruptive breach they experienced.

In a broking or advice context, phishing is rarely the end goal. It is the way in.

Once an attacker holds a mailbox, the valuable move is business email compromise: watching the flow of premium payments, claims settlements or client transfers, then intervening at the right moment with revised bank details that look entirely plausible because they arrive from a genuine internal address, in the middle of a real conversation, at exactly the point the money was expected to move.

Payment redirection fraud of this kind works because it exploits a legitimate process rather than breaking a technical control. That is why the answer is never a single product.

The controls we put in place

  • Multi-factor authentication on every account, with conditional access rules for unusual sign-in locations and unmanaged devices
  • Endpoint detection and response across laptops, desktops and servers
  • Email filtering with DMARC, SPF and DKIM configured properly, so your domain cannot be spoofed
  • Patch and vulnerability management on a defined schedule rather than when someone remembers
  • Privileged access control, so administrative rights are held deliberately and reviewed
  • Phishing simulation and staff training aimed at the payment-change scenario specifically
  • Centralised logging and alerting, giving you a trail that survives an incident
  • Full disk encryption on all mobile devices and laptops
  • Restore testing, because an untested backup is a hope rather than a control

We handle the technical side and give you the documentation to show your compliance function or your insurer what is in place. For firms wanting the full picture of what we do beyond the sector, there is more detail on our cyber security support across the West Midlands.

What the FCA expects from your IT, and what changes in March 2027

Regulatory expectations around technology have tightened steadily, and there is a significant change already dated in the diary that a lot of smaller firms have not yet registered.

  • Under SYSC 8.1, you must take reasonable steps to avoid undue operational risk from third parties, and you must not outsource in a way that impairs your internal controls or the FCA’s ability to monitor your compliance
  • You should notify the FCA before entering a material outsourcing arrangement, using the SUP 15 route
  • Firms in scope of the operational resilience rules must identify their important business services, set impact tolerances, map dependencies and test against severe but plausible disruption
  • You need records and audit trails that remain accessible and intact for as long as your retention obligations run
  • From 18 March 2027, a new operational incident and third party reporting regime applies

That last point deserves unpacking, because the scope is frequently misdescribed. The FCA published PS26/2 on 18 March 2026, alongside finalised guidance FG26/3 and FG26/4, creating a single coordinated regime across the FCA, the PRA and the Bank of England. The rules come into force on 18 March 2027, giving firms twelve months to prepare.

The operational incident reporting element applies broadly. It catches all firms with a Part 4A permission, which includes small brokers and advice firms who may reasonably have assumed a rule of this kind was aimed at banks. It defines what counts as an operational incident, sets thresholds for when you must report, and standardises the submission so one report goes to whichever regulators need it.

The third party reporting element is narrower, and this distinction matters. The requirement to notify the FCA of material third party arrangements and maintain an annual register applies to enhanced scope SM&CR firms, banks, designated investment firms, building societies, Solvency II firms, CASS large firms and a handful of other categories. Most small and mid-sized firms fall outside it.

If a provider tells you the register requirement applies to everyone, they have not read the policy statement.

Worth saying plainly: Computercentric is not, and will not be, a designated critical third party. That regime, live since January 2025 with the first designations taking effect in July 2026, is aimed at providers whose failure could threaten the stability of the UK financial system. It applies to a small number of very large technology and infrastructure companies. A regional managed service provider is not in that population, and any provider implying otherwise is overselling.

What a firm should actually do in the next twelve months is unglamorous. Work out which of your services are important business services, understand which of your suppliers you genuinely could not operate without for a week, and make sure the person who would have to write an incident report knows where the information would come from.

We help clients with all three.

Local coverage

Managed IT services across the West Midlands & Staffordshire

We support small businesses and SMEs in each of the areas below — delivering the same structured, proactive IT service to every client, locally.

West Midlands

Birmingham

  • Managed IT support
  • Cybersecurity & EDR
  • Cloud & Microsoft 365
IT services in Birmingham →
West Midlands

Walsall

  • Managed IT support
  • Backup & disaster recovery
  • Proactive monitoring
IT services in Walsall →
West Midlands

Wolverhampton

  • Managed IT support
  • Cybersecurity & compliance
  • Network management
IT services in Wolverhampton →
West Midlands

Sutton Coldfield

  • Managed IT support
  • Microsoft 365 management
  • Business continuity
IT services in Sutton Coldfield →
Staffordshire

Lichfield

  • Managed IT support
  • Cybersecurity & EDR
  • Backup & recovery
IT services in Lichfield →
West Midlands

Aldridge

  • Managed IT support
  • Cloud services & hosting
  • IT consultancy
IT services in Aldridge →
West Midlands

Bournville

  • Managed IT support
  • Endpoint protection
  • Business continuity
IT services in Bournville →

Backup and business continuity for financial services firms

A backup that has never been restored is not a backup.

  • When was the last time a full restore was actually tested, rather than a job simply reporting success?
  • How long would it take to bring the firm back to a working state, and does that number match what your business would tolerate?
  • Is the backup immutable, so that ransomware reaching your network cannot also reach your recovery point?
  • Does it cover Microsoft 365 as well as your servers, given that Microsoft’s own retention is not a backup?
  • Who holds the credentials, and what happens if that person is unavailable during the incident?
  • Is your recovery time objective documented anywhere a regulator or insurer could see it?

Firms are often surprised by how far the honest answers sit from the assumed ones. We set up backups that are tested on a schedule, documented in a form that supports your continuity planning, and sized around how long your firm can genuinely be down rather than around what was cheapest to configure. 

There is more on the underlying approach in our guide to how to build a recovery plan that holds up.

IT support for financial services firms in Birmingham and the West Midlands

The West Midlands has a substantial financial services base that gets less attention than the City. Birmingham remains the largest business, professional and financial services cluster outside London, with roughly 66,000 people employed in the sector across the city, and the wider region carries a dense population of general insurance brokers, motor and specialist intermediaries, mortgage and protection advisers, and independent advice firms, many of them long-established family businesses that have grown steadily rather than dramatically.

Computercentric works with businesses across Birmingham, Walsall, Wolverhampton, Sutton Coldfield, Lichfield, Aldridge and the surrounding Black Country, as well as with firms further afield who want a provider that will actually turn up when turning up is the only thing that will fix it.

One of our longest-standing customers is Think Insurance Services, a Walsall-based specialist insurance provider in motor trade, car, and business insurance, and one of the UK’s fastest-growing brokers, with more than 100 staff. They have their own in-house IT team handling day-to-day issues, and we provide second and third line support behind them, along with their telephone system, Ethernet and broadband connectivity, anti-virus and anti-ransomware protection, and Microsoft 365 services. It is a useful illustration of something a lot of MSP marketing skips over. 

Not every firm wants to hand everything across. Sometimes the right arrangement is a specialist sitting behind an internal team, picking up the work that team does not have the depth or the bandwidth to cover.

Getting started with us usually runs like this:

  • An initial conversation about how your firm works, what you are regulated to do, and where things currently hurt
  • A technical audit of your systems, security posture, backups and licensing
  • A written findings report, including anything we think presents a regulatory or security risk
  • An agreed transition plan with dates, so you know what changes and when
  • Documentation and handover from your existing provider, managed by us
  • Onboarding of your staff, with support arrangements explained clearly to everyone

Most day-to-day support is delivered remotely, which is faster for both sides. When something needs a person in the building, being based in the West Midlands means one turns up.

Frequently asked questions about IT support for financial services

What does IT support for a financial services firm actually include?

At minimum, it covers your helpdesk, Microsoft 365, security monitoring, backups, patching, devices, network and connectivity. For a regulated firm, it should also include the documentation and audit trails your compliance function needs, plus someone who can answer questions about the IT side of your regulatory obligations without you having to explain the FCA to them first. 

If a provider’s proposal reads identically to one they would send a builder’s merchant, they have not thought about your sector.

Do we have to tell the FCA that we have outsourced our IT?

You should notify the FCA before entering into a material outsourcing arrangement, using the SUP 15 notification route. Whether your IT arrangement is material depends on whether a failure in it would cast doubt on your ability to keep meeting the conditions of your authorisation, so a firm running everything through one provider is more likely to be in scope than one where IT support is genuinely peripheral. 

The FCA expects proportionality here, judged against the nature, scale and complexity of your firm, and we are happy to help you document the arrangement either way.

Do the new FCA incident reporting rules apply to a small firm?

The operational incident reporting rules in PS26/2 apply to all firms with a Part 4A permission, so yes, small brokers and advice firms are included. They come into force on 18 March 2027. The separate requirement to report material third party arrangements and maintain a register is much narrower, covering enhanced scope SM&CR firms, banks, Solvency II firms and similar, so most smaller firms are outside that part of the regime.

Can you support Acturis, Open GI, Intelligent Office and similar systems?

Yes. We support the environment these systems run in, which covers connectivity, endpoints, browser and authentication configuration, integrations, printing and the Microsoft 365 layer underneath, and we work directly with vendors when an issue needs escalating to them. 

If you are on Applied Epic and planning a move following its withdrawal from the UK broker market, that migration is a project we can scope with you.

Do we need Cyber Essentials?

The FCA does not mandate it, but it has become close to expected in practice. The NCSC recommends it for financial services firms, larger counterparties increasingly ask for Cyber Essentials Plus as a contractual condition, and cyber insurers now routinely want to see certification, multi-factor authentication on administrative accounts and tested backups before quoting a competitive premium. 

We help firms get certified and, more usefully, help them meet the underlying controls rather than just pass the assessment.

How much does IT support cost for a financial services firm?

Pricing is normally per user per month, and the figure depends on how many staff you have, how much of your infrastructure is still on-premise, what security tooling you need, and whether you want us covering everything or working alongside an internal resource. 

Regulated firms usually sit slightly higher than the general small business average because of the additional security and documentation requirements. Our guide to what IT support typically costs a UK small business sets out the pricing models in detail, and we will give you a fixed monthly figure after the audit.

Can you work with the IT person or team we already have?

Yes, and this is a more common arrangement than people expect. 

We provide second and third line support behind in-house teams, take on the specialist areas they do not cover, and give them somewhere to escalate. Think Insurance has worked with us on exactly that basis for years. It tends to suit firms where an internal person handles the daily requests well but needs depth behind them on infrastructure, security and projects.

How quickly do you respond when something breaks?

Response times are agreed in your service level agreement and prioritised by impact, so a firm-wide outage during a renewal run is treated very differently from a single user with a printer problem. Most issues are resolved remotely within the same working day. 

What matters more than a headline number is whether the provider is monitoring your systems well enough to catch problems before you notice them, which is where proactive management earns its keep.

What happens to our data if we decide to leave?

Your data is yours, and your systems and licences stay in your name rather than ours. If you decide to move on, we hand over documentation, credentials and configuration details to your new provider and support a clean transition. 

We would rather firms stayed because the service is good than because leaving would be painful, and any provider who makes exit difficult is telling you something about their confidence in the first part.

Computercentric — Independent IT Consultancy
Birmingham & West Midlands
Birmingham City Centre Jewellery Quarter Aston Erdington Digbeth Bordesley Green Moseley Selly Oak Edgbaston Harborne Sutton Coldfield Lichfield Walsall Solihull Bournville Aldridge HQ
✕

Proactive IT support for financial services: work with us

The difference between a reactive and a proactive IT arrangement is not really about response times. It is about what happens in the weeks when nothing has gone wrong.

A reactive provider is quiet during those weeks. A proactive one is patching, checking restores, reviewing access rights, watching alerts and telling you about the certificate expiring in six weeks before it expires, which is the difference between a Tuesday morning that goes to plan and one that does not.

At Computercentric, proactive management means monitoring your systems continuously, keeping documentation current rather than writing it once at onboarding, reviewing your setup against how your firm has actually changed, and raising things with you before they become urgent. It also means being straight with you about what you do and do not need, which occasionally involves telling a firm that the expensive thing they were about to buy will not solve the problem they have.

Firms weighing up whether to bring in an external provider at all may find our thinking on the case for handing IT to an external team useful, and there is a fuller explanation of what managed IT services actually cover if you are still mapping out the scope.

If you run an insurance brokerage, an advice firm or any other FCA-regulated business in the West Midlands and you are not confident your IT would stand up to a hard question from a compliance reviewer, an insurer or an attacker, we should talk. We will look at what you have, tell you what we find, and let you decide what to do about it.

Call us on 01922 830000 or Talk to Computercentric.

Join our mailing list

If you’d like to receive useful information, news and advice to help you stay smart and ahead of the game when it comes to IT in business, then let us know below!  We won’t spam you, and you can opt-out any time.

Latest from Instagram