AIIT SupportManaged Service Why AI-ready managed services are replacing traditional IT models_ We explore what modern managed services should do for your business – and why it can be the key to success.... AwardsCompany Update Infinity Group CEO named one of the UK’s Top 50 Most Ambitious Business Leaders for 2025_ Rob Young, CEO of Infinity Group, has been recognised as one of The LDC Top 50 Most Ambitious Busine...... AI AI agent use cases: eliminating project risk_ Find out how we’re using AI agents internally to streamline manual project work and eliminate risk for our clients....
AwardsCompany Update Infinity Group CEO named one of the UK’s Top 50 Most Ambitious Business Leaders for 2025_ Rob Young, CEO of Infinity Group, has been recognised as one of The LDC Top 50 Most Ambitious Busine...... AI AI agent use cases: eliminating project risk_ Find out how we’re using AI agents internally to streamline manual project work and eliminate risk for our clients....
AI AI agent use cases: eliminating project risk_ Find out how we’re using AI agents internally to streamline manual project work and eliminate risk for our clients....
Key takeaways_ A client data breach can trigger multiple obligations under SRA, FCA, ISQM and UK GDPR, each with different reporting thresholds. Regulators expect clear ownership, reliable evidence and documented decisions before, during and after an incident. The strongest firms build one control environment that supports security, governance, resilience and compliance together. Government research shows that 54% of professional, scientific and technical organisations identified a cyber breach or attack in the previous 12 months. Most firms understand that a breach would be serious. But what is often less clear is what happens next. Who should you inform? Does the incident need to be reported? What evidence should be retained? Who owns the decision-making process? And how quickly do those decisions need to be made? These questions matter because the wrong answers can quickly turn a breach into a bigger non-compliance issue. Firms may have security tools, policies and external advisers in place, yet still struggle to determine which reporting thresholds apply, what evidence is required and whether their response will stand up to regulatory scrutiny. The challenge becomes even more complex for professional services organisations operating under multiple regulatory frameworks, including FCA, GDPR, SRA and ISQM. These frameworks do not use the same threshold for determining whether an incident is reportable – and many firms fall into the trap of treating compliance as a collection of separate checklists. In reality, the strongest organisations focus on building a single control environment that supports governance, accountability, evidence collection and risk management across the business. In this guide, we’ll explain what regulators actually expect, where firms most commonly get caught out and how a modern security and compliance strategy can help. Why firms often get compliance wrong after a breach_ When a client data breach occurs, many firms assume the next step is straightforward: identify what happened, report it if necessary and move on. One of the most common misconceptions is that every breach is automatically reportable. As different regulators assess incidents through different lenses, the same event may trigger obligations under one framework but not another. This is where professional services firms often find themselves under pressure. Many already have security tools, policies and compliance processes in place. But the problem is that ownership, evidence and decision-making are often spread across multiple teams, systems and third-party providers. As a result, firms can struggle to answer fundamental questions such as: Who owns the reporting decision? What evidence can be trusted? Which regulatory thresholds apply? Has the incident been properly documented? Can we demonstrate that remediation was effective? This can cause you to fall short of compliance standards. Key compliance frameworks and what they mean_ A client data breach can trigger several different compliance obligations at the same time. Rather than a single reporting process, multiple frameworks may apply depending on the type of data involved, the impact of the incident and the regulatory status of the organisation. The four most common frameworks are: SRA compliance_ For SRA-regulated law firms, a breach may raise concerns around client confidentiality, safeguarding client assets and whether a serious regulatory breach has occurred. The SRA expects firms to assess incidents against its own reporting requirements rather than relying solely on GDPR or cyber security criteria. FCA compliance_ FCA-regulated firms must consider whether an incident is material enough to trigger regulatory notification requirements. Depending on the firm’s permissions and regulatory obligations, the FCA may also expect evidence of effective systems, controls and operational resilience. ISQM requirements_ For audit and assurance firms, a breach may expose weaknesses in the firm’s System of Quality Management (SoQM). This can create obligations around monitoring, remediation, information integrity, confidentiality and root-cause analysis, even where the incident itself is not externally reportable. UK GDPR and ICO reporting_ If personal data has been compromised, firms may need to assess whether the breach is reportable to the Information Commissioner’s Office (ICO) within 72 hours and whether affected individuals need to be informed. These frameworks are assessing different risks. That’s why effective breach management is about understanding which obligations apply, gathering the right evidence and making informed decisions against each reporting threshold. Addressing regulators’ expectations_ While SRA compliance, FCA compliance and ISQM have different scopes and reporting requirements, they share a surprising amount of common ground. Here’s what regulators expect from you: What regulators consistently expect before a breach happens_ Long before a breach occurs, regulators are looking for evidence that firms understand their risks, have appropriate controls in place and can demonstrate accountability when something goes wrong. Governance and accountability_ The first question regulators often ask is simple: who was responsible? Whether you’re assessing SRA obligations around firm governance, FCA expectations around systems and controls or ISQM quality management responsibilities, there needs to be clear ownership of cyber risk and incident response. Decisions cannot sit solely with IT. Leadership teams, compliance officers, risk owners and operational stakeholders all need defined responsibilities and escalation paths. If a breach occurs, firms should be able to demonstrate who made key decision, when those decisions were made and why they were considered appropriate at the time. Risk-based controls_ Regulators generally do not prescribe specific technologies. Instead, they expect firms to implement controls that are proportionate to their risks. For a law firm, that may mean focusing heavily on client confidentiality and protecting client assets. For an audit firm, it may mean preserving the integrity and availability of engagement information. And for FCA-regulated organisations, the emphasis may be on operational resilience and service continuity. The question is whether you can demonstrate that the controls you have are appropriate for your organisation, your clients and the data you hold. Evidence and audit trails_ Across all frameworks, firms are expected to maintain records that demonstrate compliance, support investigations and help regulators understand what happened during an incident. That includes: Security and access logs Risk assessments Incident records Reporting decisions Remediation activities Testing and review outcomes Without reliable evidence, it becomes difficult to prove that controls operated effectively or that regulatory obligations were met. Third-party oversight_ Outsourcing a service does not outsource accountability. Whether you rely on managed service providers, cloud platforms, audit software or other third-party suppliers, regulators expect firms to understand and manage those risks. SRA, FCA and ISQM guidance all reinforce the principle that responsibility remains with the regulated organisation. That means firms should understand: What suppliers have access to What protections are in place How incidents will be reported What evidence can be obtained if something goes wrong What regulators expect during a data breach_ The first few hours after a breach are often the most challenging. Teams are balancing containment, business continuity, client communications and regulatory considerations, all while working with incomplete information. The good news is that regulators do not expect firms to know everything immediately. What they do expect is a structured and documented response. Contain the incident_ The immediate priority is to stop the problem getting worse. This may involve isolating compromised systems, disabling accounts, removing unauthorised access or engaging specialist support. The goal is to minimise further exposure while preserving the information needed to investigate what happened. Understand what was exposed_ Before reporting decisions can be made, firms need a clear understanding of the scope and impact of the incident. Key questions include: What information was affected? Which clients were impacted? Has personal data been compromised? Are critical business services affected? Is there evidence of unauthorised access or disclosure? The answers will influence which regulatory frameworks are relevant and what obligations may apply. Assess regulatory reporting requirements_ This is where many firms become unstuck. A cyber incident, personal data breach, serious regulatory breach and operational resilience incident are not interchangeable concepts. Each framework uses different criteria to determine whether a notification is required. Reporting decisions should be assessed separately against: UK GDPR and ICO requirements SRA reporting expectations FCA materiality requirements ISQM quality management considerations Preserve evidence_ Investigations, reporting decisions and future reviews all depend on reliable evidence. Logs, timelines, communications, system records and decision-making documentation should be retained from the outset. Firms that fail to preserve evidence often struggle to demonstrate compliance later. Document decisions_ It’s not enough to make the right decision; you also need to show how you reached it. Maintaining a record of assessments, actions taken, reporting decisions and supporting evidence helps demonstrate that the incident was managed appropriately, even as new information emerges. What regulators expect after the incident_ Many organisations view recovery as the finish line, but regulators generally see it as the starting point for learning and improvement. A breach may be contained, systems restored and notifications completed, but firms are still expected to understand why the incident happened and how future risks will be reduced. Root cause analysis_ What actually caused the incident? Regulators increasingly expect firms to move beyond surface-level explanations and identify the underlying control, process or governance failures that allowed the breach to occur. Remediation_ Immediate fixes are important, but organisations should also address any wider weaknesses identified during the investigation. That could include improving processes, strengthening monitoring, addressing supplier risks or updating incident response procedures. Control improvements_ The most effective organisations treat incidents as opportunities to strengthen their control environment. For ISQM-regulated firms in particular, breaches should feed back into ongoing quality management, monitoring and remediation activities rather than being treated as isolated events. Evidence retention_ Regulators may request evidence long after an incident has been resolved. Investigation records, decisions, notifications, testing outcomes and remediation activities should be retained in a structured and accessible manner. Board reporting_ Cyber security and compliance are increasingly board-level concerns. Leadership teams should understand the impact of incidents, the actions taken and any ongoing risks or improvement activities. This helps demonstrate governance, accountability and organisational oversight. What a modern compliance and security framework looks like_ By this point, you’ve probably noticed a pattern. While SRA compliance, ISQM and FCA compliance each have their own requirements, they all place significant emphasis on governance, risk management, accountability and evidence. This is why leading professional services firms tend not to build separate controls for each framework. Instead, they create a single security and compliance environment that supports multiple regulatory objectives simultaneously. Identity and access controls_ Client information can only be protected if the right people have access to it and the wrong people don’t. Identity and access controls help firms manage who can access systems, data and applications, while reducing the risk of unauthorised disclosure or compromised accounts. This directly supports SRA confidentiality obligations, helps protect the integrity of engagement information under ISQM and contributes to the effective systems and controls expected by the FCA. Information protection_ Professional services firms handle some of their clients’ most sensitive information, from legal documents and financial records to commercial data and personal information. Protecting that information requires more than perimeter security. Firms need the ability to classify, secure and control data wherever it resides, whether that’s within email, collaboration tools, document repositories or business applications. Robust information protection helps organisations demonstrate that confidentiality and information integrity are being actively managed rather than assumed. Security monitoring_ Regulators increasingly expect organisations to identify, investigate and respond to incidents in a timely manner. Effective monitoring enables firms to detect suspicious activity, understand the scope of an incident and gather the evidence required for regulatory assessments and reporting decisions. Importantly, monitoring also helps create the audit trail needed to demonstrate what happened, when it happened and how the organisation responded. Governance and evidence_ One of the most consistent themes across compliance frameworks is the need to prove that appropriate action was taken. That means maintaining reliable records of: Risk assessments Decisions and approvals Incident investigations Regulatory notifications Remediation activities Testing and review outcomes Without this evidence, it becomes difficult to demonstrate compliance, regardless of how effectively the incident was actually managed. Operational resilience_ For many professional services firms, the impact of a breach extends beyond data loss. Regulators increasingly want to understand whether organisations can continue operating, serving clients and maintaining critical business services during periods of disruption. Recovery planning, resilience testing and service continuity are therefore becoming just as important as preventative security controls. This is particularly relevant for FCA-regulated firms, but resilience is becoming a wider expectation across the professional services sector. Risk and supplier management_ Third parties remain one of the most common sources of compliance risk. Whether it’s an outsourced IT provider, cloud platform, audit software vendor or specialist supplier, regulators expect organisations to understand the risks associated with external partners and maintain appropriate oversight. Responsibility for compliance cannot simply be delegated through a contract. This includes understanding who has access to information, how incidents will be communicated and what assurances exist around security, resilience and governance. Turning regulatory requirements into everyday operations_ Understanding compliance requirements is important. The harder challenge is embedding them into day-to-day operations. Use the checklist below to identify potential gaps in your security, governance and compliance posture. Governance and accountability_ Assign a named owner for cyber security, compliance and incident response Define who is responsible for regulatory reporting decisions Create documented escalation paths for security incidents Ensure board-level visibility of cyber and compliance risks Review roles and responsibilities at least annually Data and information protection_ Identify where client data is stored Classify sensitive and confidential information Review who has access to client data and why Remove unnecessary permissions and dormant accounts Establish clear retention and disposal policies Incident response readiness_ Create a documented breach response playbook Define separate assessment processes for (depending on which apply to you): ICO reporting SRA reporting FCA reporting ISQM considerations Establish out-of-hours incident contacts Run breach simulation exercises at least annually Test recovery and business continuity plans regularly Monitoring and evidence_ Retain security and access logs Record incident timelines and response activities Document compliance decisions and their rationale Store evidence centrally rather than across emails and spreadsheets Review whether audit trails would withstand regulatory scrutiny Third-party and supplier controls_ Maintain a register of suppliers with access to client information Review supplier security arrangements and certifications Define breach notification obligations in contracts Assess the impact of supplier failure on critical services Regularly review third-party risk exposure Testing and improvement_ Conduct regular cyber risk assessments Review controls following incidents and near misses Carry out root cause analysis after significant events Track remediation actions through to completion Test that improvements have actually reduced risk Technology foundations_ Strengthen identity and access management controls Implement multi-factor authentication across critical systems Monitor suspicious user activity and access attempts Protect sensitive information both in storage and in transit Protect and test backups Establish visibility across endpoints, users and cloud services Minimising the fall-out of a breach and retaining compliance_ A single data breach can raise questions around client confidentiality, regulatory reporting, operational resilience, audit quality and governance. Depending on the organisation and the nature of the breach, obligations may arise under several compliance frameworks. Regulators want to understand how your organisation responded, who made key decisions, what evidence was gathered, whether reporting obligations were met and what improvements were made afterwards. Across all frameworks, the themes remain remarkably consistent: strong governance, clear accountability, effective controls and reliable evidence. That’s why the most resilient firms build a single control environment capable of supporting multiple obligations at once. When governance, security, monitoring and evidence collection become part of everyday operations, compliance becomes easier to demonstrate and breaches become easier to manage. This is where Infinity Group can help. As one of the UK’s leading Microsoft partners, we help professional services firms strengthen security, governance and operational resilience through a combination of consultancy, Microsoft technology and ongoing managed services. Whether you’re reviewing your cyber security posture, preparing for regulatory scrutiny, improving operational resilience or looking to modernise your Microsoft security estate, we can help you build the foundations needed to protect client trust and respond confidently when incidents occur. Find out more about our services here.
GDPR and compliance GDPR: what are the penalties for non-compliance in the UK? Updated August 2026 Key takeaways_ GDPR penalties don’t just mean fines. For many SMBs, the bi...... AICyber SecurityData AI data security: how to prevent your exposure_ Learn best practice for AI data security to avoid breaches and other compliance concerns in your organisation.... AIProfessional Services AI in professional services: what actually works_ Find out the best AI use cases for professional services and how to get measurable outcomes – not just hype.... We would love to hear from you_ Our specialist team of consultants look forward to discussing your requirements in more detail and we have three easy ways to get in touch. Call us: 03454504600 Complete our contact form Live chat now: Via the pop up icon-arrow-up Subscribe
AICyber SecurityData AI data security: how to prevent your exposure_ Learn best practice for AI data security to avoid breaches and other compliance concerns in your organisation.... AIProfessional Services AI in professional services: what actually works_ Find out the best AI use cases for professional services and how to get measurable outcomes – not just hype....
AIProfessional Services AI in professional services: what actually works_ Find out the best AI use cases for professional services and how to get measurable outcomes – not just hype....