What UK Financial Services Firms Are Actually Doing About Cyber Risk: 3 Approaches Compared
Bridgewater Associates rebuilt its entire security architecture around Zero Trust in early 2020, before NIST had even published the framework. Copp Clark scoped a proportionate DORA assessment. ICONOMI built a compliance track specific to crypto. None of the three is the right model to copy wholesale, the point is matching your own exposure to the right one.
Key Takeaways
- Three very differently sized financial-services-adjacent companies, Bridgewater Associates (a giant hedge fund), Copp Clark (a small Canadian data vendor) and ICONOMI (a crypto investment platform), have taken three genuinely different approaches to cyber and operational risk, and the differences track company type and regulatory exposure closely, not one company simply doing more than the others.
- Bridgewater’s Zero Trust rollout, rebuilding security around Microsoft 365 and identity-based access instead of a corporate firewall, is described in a case study that references COVID-19 as a live event and a Davos trip “this year,” dating it to roughly January to March 2020, before NIST had even published its formal Zero Trust Architecture framework. Genuinely early. Also, by 2026, Zero Trust has moved from differentiator to baseline expectation across financial services, with Gartner putting global, cross-industry adoption at around 63% and financial services among the leading adopter sectors.
- Igor Tsyganskiy, quoted in that case study as Bridgewater’s CTO, later became Microsoft’s global Chief Information Security Officer in January 2024, succeeding a 14-year incumbent, then moved into an EVP role at Microsoft Research by March 2026, a genuinely notable trajectory worth knowing when reading his 2020 quote.
- DORA and rising FCA scrutiny explain why a small vendor like Copp Clark and a crypto platform like ICONOMI are now investing in structured compliance work regardless of size: DORA became enforceable across the EU in January 2025, and the FCA reports over 40% of cyber incidents reported to it in 2025 involved a third party, exactly the exposure a company like Copp Clark represents to its financial-institution customers.
- None of the three approaches is more “correct” than the others. A board’s actual task isn’t picking the best model off this list; it’s matching its own regulatory exposure and company size to the approach that fits, rather than assuming a giant asset manager’s playbook scales down, or a small vendor’s proportionate fix scales up.
Put a hedge fund, a reference-data vendor and a crypto platform in the same room and they’ll describe completely different security priorities, and all three will be right. Bridgewater Associates, Copp Clark and ICONOMI sit at genuinely different points on the financial-services risk spectrum, by size, by regulatory exposure, by what an attacker or a regulator actually cares about in each case, and comparing what each one actually did is a more useful exercise for a UK C-suite than treating any single approach as the model to copy.
Bridgewater: a genuinely early Zero Trust move, worth dating precisely
Bridgewater Associates, at the time one of the world’s largest hedge funds managing roughly $150 billion, had built its security around a traditional perimeter that made remote and mobile access difficult and limited how far cloud collaboration could go. “We developed a vision to improve productivity and collaboration and deliver comprehensive mobile access, but to achieve this goal, we needed to overhaul our technology,” said Anthony Golia, Head of Productivity and Endpoint Engineering at Bridgewater Associates. Xantrion, working alongside Microsoft, rebuilt Bridgewater’s security model around Zero Trust principles using Microsoft 365, replacing reliance on the corporate firewall with granular, identity-based access controls. “Since implementing a Zero Trust strategy using Microsoft 365 technologies, our employees can fulfill their company duties from anywhere in the world while maintaining tight control over core security needs. This has been extremely valuable now that all of our company is working from home due to COVID-19. Everyone is working from an insecure environment today, and with our Zero Trust strategy in place, we are confident we can keep our data safe,” said Igor Tsyganskiy, Chief Technology Officer at Bridgewater Associates. “Because we collaborated with Microsoft to improve our security controls, I can access my files on OneDrive as if I was in the office. When we went to the World Economic Forum meetings at Davos this year, I accessed my files from my iPad just like I would in the office, so my team could continue to adjust the presentations throughout the conference. In the past, we wouldn’t have allowed this kind of access from a public location, making that collaboration more difficult,” said Greg Jensen, co-Chief Investment Officer at Bridgewater Associates.
Two details worth being precise about. First, the timing: a case study referencing COVID-19 as a live disruption and a Davos trip “this year” places this rollout roughly in the first quarter of 2020, Davos 2020 ran 21 to 24 January that year, meaning Bridgewater had rebuilt its access model around Zero Trust principles before NIST published its own formal Zero Trust Architecture framework, SP 800-207, in August 2020. That’s a genuinely early move by a large financial institution, not a follow-the-herd decision. Second, worth knowing when reading Tsyganskiy’s quote: he later left Bridgewater, joined Microsoft as chief strategy officer for security in September 2023, and was named Microsoft’s global Chief Information Security Officer effective January 2024, succeeding a CISO who’d held the role for 14 years, before moving into an EVP role at Microsoft Research by March 2026. The person describing this Zero Trust rollout went on to run security for one of the world’s largest technology companies, a detail that adds real weight to the quote without needing embellishment. On scale, it’s also worth noting Bridgewater’s assets under management have since fallen from roughly $150 billion to around $92 billion as of the end of September 2025, a deliberate downsizing toward investment agility rather than a distress signal, but the two figures describe different points in time and shouldn’t be conflated.
Copp Clark and ICONOMI: proportionate compliance, not the Bridgewater playbook scaled down
Copp Clark, a small Canadian company supplying financial institutions with global public holiday, trading hour and close-day data, took a completely different route: not a wholesale security architecture rebuild, but a scoped DORA gap assessment and Digital Operational Resilience Testing, deliberately calibrated to avoid “compliance activities that went beyond what its actual role required,” in the case study’s own words. That’s the right instinct for a company of its size and role, DORA became enforceable across the EU in January 2025, and the FCA has reported that more than 40% of cyber incidents reported to it in 2025 involved a third party, exactly the exposure a small data vendor represents to the financial institutions that rely on it. ICONOMI took a third route again: an onboarding and functional testing pass alongside its FCA cryptoasset AML registration, a compliance track specific to crypto platforms rather than to financial-services vendors generally. Neither company needed, or attempted, a Bridgewater-scale Zero Trust rebuild, and that’s the correct call, not a lesser one; a reference-data vendor and a crypto onboarding flow carry a genuinely different risk profile than a global asset manager’s entire remote workforce.
What actually explains the difference
The pattern across all three isn’t effort or sophistication, it’s exposure. Financial services was the second most-targeted industry globally in the first half of 2025, roughly 19% of observed attacks, and 65% of financial firms reported being hit by ransomware in the prior year, with average breach costs in the sector running around $6 million. Regulatory pressure has risen to match: DORA’s enforcement, the FCA’s own reporting on third-party-linked incidents, and industry estimates suggesting only around half of EU financial institutions were fully DORA-compliant even a year into enforcement, all point toward a landscape where every company touching financial data, regardless of size, now has a specific compliance obligation attached to its specific role. Zero Trust has followed a similar arc inside large institutions: Gartner’s most recent research puts global, cross-industry Zero Trust adoption at around 63%, with financial services among the leading adopter sectors, meaning what Bridgewater did as a genuine early move in 2020 is, by 2026, closer to a baseline expectation for an organisation its size than a differentiator.
What a UK C-suite should actually take from this
The temptation with a comparison like this is to rank the three companies by how impressive their security story sounds. That’s the wrong exercise. Bridgewater needed, and built, a comprehensive architectural rebuild because it is a global asset manager with a large, distributed workforce handling extraordinarily sensitive data, and it did so early enough that the engineer who led it went on to run security at Microsoft. Copp Clark needed, and got, a proportionate compliance assessment scoped to its actual role as a third-party data vendor, not more than that. ICONOMI needed a compliance track specific to being a regulated crypto platform. The right question for a board isn’t “which of these should we copy.” It’s “which of these three profiles, by size, by data sensitivity, by regulatory category, actually matches our own position,” and then building the proportionate version of that answer, rather than either underbuilding against real exposure or over-engineering a Zero Trust programme a company’s actual risk profile doesn’t yet justify.

