Five stages.
One clear pathway
to defensible governance.

Each stage builds on the last. Start with a free checklist. Progress to full governance oversight. Every step moves you toward a documented, defensible position with your board, your insurer and the FCA.

Step 1 - Free Resource

IFA Cyber Governance Checklist

A simple, practical starting point. No commitment required.

Free
Instant download

Written by Patrick Murphy - Chartered Financial Planner, 50+ years in UK financial services - this practical checklist helps IFA managing directors ask the right questions about their firm's cyber governance position before engaging any adviser.

Ten questions. Plain English. No technical knowledge needed. Where several answers are "No" or "Not sure", it identifies where GOIA's independent assessment would add most value.

Download the checklist

You will receive the checklist by email immediately. No spam. Unsubscribe at any time.

IFA Cyber Governance Checklist
Patrick Murphy CFP - Chartered Financial Planner
1. Has cyber risk been formally reviewed by the board in the past 12 months?
2. Do you know which business services are critical to your firm?
3. Do you understand your technology dependencies?
+ 7 further questions...
Step 2

Cyber Risk Snapshot

A fast, independent view of your firm's external exposure and governance position.

£250+VAT
Credit applies toward the Executive Review

The Snapshot provides an independent rapid assessment covering the three highest-priority risk indicators for IFA firms. No system access required. The output is not a raw technical scan - it is translated into business and governance language: what the exposure means for your firm's operational continuity, regulatory position and director accountability.

Delivered within 48 hours of the information being received. The £250 fee is credited against the Executive Review if you proceed.

External exposure assessment

Independent scan of your public-facing attack surface - domains, IP addresses, exposed services and any leaked credentials identified in public breach datasets.

Email security review

SPF, DKIM and DMARC configuration checked. Plain-language explanation of any gap and the specific risk it creates for your firm.

Governance gap summary

Initial view of the most significant governance gaps, linked to FCA operational resilience expectations.

Executive risk summary

A structured, board-readable summary in governance and business impact language - not raw technical output.

Book Your Snapshot - £250 + VAT
Step 3 - Core Engagement

Executive Cyber Risk and Resilience Review

8-domain governance assessment. Board-ready report. Fixed fee. 10 working days.

£1,750+VAT
Fixed fee - 10 working days from final session

The Executive Review is GOIA's core engagement and the foundation for every ongoing client relationship. It covers all 8 governance domains through structured interviews, document review and independent assessment. No privileged system access required. All findings are presented verbally to the managing director before the written report is issued.

Executive Summary (2 pages)

Plain-language RAG rating per domain. Three most critical actions. Written for the board, not the IT team.

Domain Assessment Report (8-12 pages)

Findings across all 8 domains with risk ratings, regulatory linkage and prioritised remediation.

Prioritised Risk Register

Ready for board papers or FCA compliance file. Standard GOIA format.

90-Day Stabilisation Roadmap

Three to five highest-priority controls with suggested ownership and effort.

Verbal Briefing Session

All findings presented to the MD before the written report is issued.

CIS Controls v8 Gap Map

Framework-referenced remediation list for your IT provider. One page.

Insurer Evidence Pack available on request - a formatted summary of assessment findings for submission to your cyber insurer or broker at renewal.

Book the Executive Review - £1,750 + VAT
Step 4

Cyber Risk Stabilisation Projects

Targeted remediation aligned directly to Review findings.

On request
Scoped and agreed following the Executive Review

Following the Executive Review, GOIA scopes targeted remediation projects to address the highest-priority findings. Each project has a defined scope, defined ownership, board-level progress reporting and a clear completion point. Typical examples include: external exposure remediation; email authentication advisory; incident response plan creation and board sign-off; FCA Important Business Services mapping; third-party MSP due diligence.

Step 5

Ongoing Cyber Governance and Assurance

Structured oversight. Board reporting. Continuous monitoring. IR readiness.

£750-£2k/mo
+ VAT - Monthly ongoing engagement

The Ongoing Governance engagement provides structured independent oversight across your full cyber risk position - combining governance advisory, board-level reporting, independent control validation and continuous technical monitoring into a single joined-up service.

The monitoring layer is embedded within the governance service. It gives GOIA real-time visibility of your firm's security posture between governance sessions - so board reports are based on live evidence. The commercial relationship underpinning the monitoring capability is disclosed in full in the engagement letter, as required by GOIA's conflict of interest policy.

Monthly governance check-in

60-minute structured session covering control status, regulatory developments and action tracker review.

Quarterly board report

Board-ready summary covering posture update, control validation, regulatory horizon and open actions.

Continuous risk monitoring

Ongoing visibility of external posture, user risk and endpoint status between governance sessions.

IR tabletop exercise

Bi-annual facilitated exercise. Output: updated IR plan, board-aware response structure, FCA/insurer evidence.

On-call governance advisory

Email and phone access for governance questions. Response within one working day during business hours.

Annual re-assessment

Full Executive Review repeat with year-on-year comparison. Staff awareness briefing included.

Enquire about Ongoing Governance

Every governance relationship starts with the Executive Review.

£1,750 + VAT. Fixed fee. Board-ready in 10 working days.

Fixed fee - £1,750 + VAT
Board-ready in 10 working days
No IT system access required
Verbal briefing before written delivery
Fully independent advisory