Asset Management
Protect the trust you manage
Investors trust you with their capital and their data, and regulators trust that your controls work as described. DarkGuard gives asset managers and fund businesses one accountable partner for cybersecurity, IT operations, and governance, so your leadership team can show it is in control and keep its focus on performance and clients.
The challenge
Technology decisions are now board decisions
Your technology sits at the centre of everything the firm does: investment decisions, fund administration, valuation, investor reporting, and client data. When something in that chain fails, the conversation quickly moves from IT to investor protection, regulatory standing, and the board's oversight. Four pressures in particular now reach the leadership team.
Regulators expect proof
Supervisors expect firms to show that their controls work, that recovery has been tested, and that material incidents are reported on time. Auditors check this against records and samples.
Insurers and clients ask for evidence
Cyber insurers ask detailed questions about your controls before they renew cover. Institutional clients and counterparties increasingly ask for security commitments in their contracts.
Outsourcing does not transfer accountability
Fund administrators, custodians, cloud platforms, and IT providers now sit inside most of your processes. The work can be outsourced, but your board remains accountable for it.
Leadership time is finite
Every hour your COO spends chasing suppliers after an outage, or your CFO spends pulling together answers for an auditor or insurer, is an hour away from investment performance and clients.
How we support you
Cybersecurity, IT, and governance from one partner
Firms your size often work with several suppliers at once: an IT provider, a security specialist, a compliance consultant, and an incident response firm on call. Each may do its part well, but someone in your leadership team ends up coordinating between them, and that is usually where gaps appear. We bring this work together in one engagement, delivered by senior people, with one point of accountability to you.
Virtual CISO (vCISO)
Security leadership at board level, without a full-time hire.
- — Fractional CISO leadership: a named senior security leader, typically two to four days a month
- — Board & executive cyber reporting: quarterly board reporting in plain English, covering risk appetite, key metrics, and compliance status
- — Regulator & external engagement: support in your conversations with regulators and auditors
- — Security strategy & roadmap development: a multi-year plan your leadership team can track and fund
- — Security programme governance: clear oversight of security priorities, spend, and delivery
Governance, risk & compliance
Policies, risk management, and evidence that stand up to your regulator's review.
- — Compliance & policy framework: policies aligned to the rules you answer to, with evidence packs ready for audits
- — ICT risk management & governance: a defined risk appetite, a living risk register, and board-level reporting
- — Third-party & supply chain risk management: due diligence and monitoring of key suppliers such as fund administrators, custodians, cloud, and IT providers
- — Security awareness & training: role-based training and phishing simulations for every team
ICT services
Reliable IT, run to a defined standard with clear accountability and documented procedures.
- — Cloud infrastructure & migration: cloud environments designed, migrated, and managed
- — Network & connectivity: office and remote connectivity, managed and monitored
- — End-user computing & workspace: Microsoft 365, devices, and onboarding and offboarding of staff
- — Managed service desk: a single point of contact for your staff, with defined service levels
- — IT infrastructure & systems management: servers, storage, backups, and patching
Managed detection & response
Continuous monitoring, so unusual activity is spotted and handled early.
- — MDR & XDR services (24/7 managed detection & response): monitoring and response across devices, identities, network, and cloud, around the clock
- — SIEM engineering & operations: log data from your critical systems collected and reviewed in one place
- — Threat intelligence & detection engineering: detection tuned to the threats that target financial services firms
Incident response & forensics
An experienced response team on call, working to a plan agreed with you in advance.
- — Security incident response: fast triage and containment, organised around your regulatory reporting deadlines
- — Digital forensics & containment: evidence collected and preserved with a clear chain of custody
- — Regulatory incident reporting & playbooks: thresholds, timelines, and notification templates ready before they are needed
- — Crisis communication & stakeholder management: coordinated communication with clients, staff, and regulators
Operational resilience
Confidence that your firm can keep running and recover when something fails.
- — Operational resilience & important business services: your critical services identified, with recovery targets and tolerances agreed
- — Recovery planning & business continuity: continuity and disaster recovery plans for the services that matter most
- — Business continuity & cyber resilience testing: tabletop exercises for the board and crisis team, and technical recovery tests
- — Critical data & records management: critical data classified and protected, with backup and recovery procedures that are tested
Every service runs to the NIST Cybersecurity Framework (CSF) 2.0. You can take all six as a managed service or start with the areas where your gaps are largest.
How we engage
How we work with you
Assess
A fixed-scope review of where you stand against what your regulator expects. You receive a summary for the board and a prioritised plan.
Build
We close the priority gaps in governance, controls, and recovery. Every finding gets an owner and a remediation date.
Run
We look after your IT and security day to day and meet with you every quarter to review progress against your risk appetite.
Additional services
Specialist services when you need them
Attack surface management
Asset discovery & inventory, vulnerability management & assessment, penetration testing & adversary simulation, and configuration & hardening reviews. Every finding is tracked until it is fixed.
Identity & data protection
Data security & privacy protection, identity & access management, and encryption & key management, so the right people have access to the right systems and client data stays protected.
AI enablement
AI adoption is moving faster than AI governance at most regulated firms. From an AI readiness assessment to AI governance, risk & policy and LLM & generative AI security testing, we help make AI in research, portfolio, and client processes defensible to your board and regulator.
Specialised services
Digital security for partners, principals, senior executives, high-net-worth individuals (HNWI), and family offices, scaled to each person's exposure.
Regulatory fluency
Fluent in the rules you answer to
Whichever regulator supervises your firm, the expectations follow the same themes. We work with your compliance function and your technology team in the same conversation, and where your group operates in more than one jurisdiction, we set up one control environment that covers all of them.
Governance and accountability
Clear ownership of ICT and cyber risk, a defined risk appetite, and regular reporting to the board.
Outsourcing and third parties
Due diligence, contracts, ongoing monitoring, and exit plans for the providers your firm depends on.
Critical data and continuity
Critical data identified and protected, and recovery tested against realistic scenarios.
Incident reporting
Material incidents classified and reported within the deadlines your regulator sets, with a clear record of each decision.
Evidence
Policies, tests, and remediation records kept current, so audits and supervisory reviews start from documents that already exist.
White paper · Switzerland
Beyond generic IT
Written for FINMA-regulated fund managers. It covers what an IT and cybersecurity partner has to deliver and closes with 10 questions for the board to ask before renewing an IT contract.
PDF · 34 pages · September 2026
Talk to us about where your firm stands today and what to prioritise first.
Speak with our team