Can our staff use ChatGPT or other AI tools with client data?
Only with clear rules in place. Free and personal versions of some AI tools can use what people type to improve their models, and the firm has no control over where that data goes. Business versions typically exclude your data from training and give you admin controls, retention settings and audit logs. Decide which tools are approved and which data must never be entered (client, personal and confidential information), write it into an AI use policy, and assess AI providers as you would any other supplier.
Is Microsoft 365 Copilot safe for a regulated firm?
It can be, but it exposes weaknesses in your permissions. Copilot can find and summarise anything a user already has access to, so files that are overshared across SharePoint, Teams and OneDrive become easy to surface. Before switching it on, review who can see what, label confidential data and confirm your retention and logging settings. See our
Microsoft 365 governance guide.
How do we stop fake invoice and payment-change emails?
Treat any email that asks you to change bank details or make an urgent payment as possibly fraudulent, even if it comes from a real supplier or colleague, because their account may have been compromised. Confirm every change by calling a number you already hold, never one in the email. Require two people to approve new payees and large transfers. Protect email with multi-factor authentication, flag messages from external senders, and set up SPF, DKIM and DMARC so others cannot easily send email as your domain.
Could a deepfake of our CEO be used to authorise a payment?
Yes. Voices and video can now be faked convincingly. In a widely reported 2024 case in Hong Kong, an employee transferred about US$25 million after a video call with what appeared to be the company’s senior managers. The defence is process rather than spotting fakes: no payment is approved on the strength of a call, video or message alone, and urgent or confidential requests are always verified through a separate channel you already trust.
What should we do in the first hours after a cyber attack?
Contain it, preserve evidence and note the time. Disconnect affected devices from the network, but do not wipe or switch them off. Call your IT or incident response provider. Change passwords from a clean device and check for unexpected email forwarding rules. Record what happened and when. Then decide whether the incident is material: DIFC firms must report within 72 hours and ADGM firms within 24 hours (see
reporting deadlines). A personal data breach may also need reporting to the data protection regulator.
Should we pay a ransom?
Take advice before making any decision. Paying does not guarantee you will get your data back or that it will not be published, it marks you as willing to pay, and paying a sanctioned group can be unlawful. Involve your senior management, legal adviser, insurer and the police early, and keep to your regulator’s reporting deadlines. The best position is never to have to decide: tested, offline backups let you restore without paying.
How do we know our backups will work when we need them?
Test them. Restore real files regularly and, at least once a year, a whole system, and time how long it takes. Keep at least one copy offline or immutable so ransomware cannot encrypt or delete it, and another copy off site or in a separate cloud account. Record each test with its date and result: that record is exactly the evidence regulators, auditors and insurers ask for.