DIGITAL MARKETING
Evara's integrated system combining revenue strategy, marketing operations, and data infrastructure to produce compounding, measurable growth.
Perspectives on growth strategy, revenue operations, technology and AI – for Financial Services and FinTech leaders.
0%
read so far
Data governance is one of those topics that sounds abstract until something makes it suddenly, uncomfortably concrete. For us, that something arrived in an inbox on an otherwise unremarkable Tuesday morning.
About week ago, an email landed in my inbox. The sender was none other than our CEO Sheila Mitham, or so they claimed.

The message was three lines long: a generic "Hi anita," a request to send a direct message to a private WhatsApp number "regarding the tasks that need to be completed," and a formal sign-off.
The platform flagged it with a screaming red banner telling me “this message might be dangerous.”
The irony is that the attacker got the name and the job title exactly right, but everything around them went haywire:
Nobody at Evara is ever going to message a stranger's WhatsApp number on the strength of three sentences from a free email account signed with the right name. That's not the story worth telling.
Getting the CEO's name and title correct cost the attacker nothing. Sheila Mitham's name and role at Evara are a matter of public record - searchable for free on the UK's Companies House register director names from public view. This was no breach of Evara platforms, and none of our data protection practices failed. In the world of manual research, finding this information would have taken 30 seconds. In the world of AI and MCPs, it probably takes an hour to find thousands of companies and their CEOs.
What we should look at is not phishing attempts, but data governance. It's the same story whether the attempt lands with three lines from a Gmail account or with a meticulously personalised wire-transfer request that clears a bank's own fraud checks.
While banks would tell you to watch out for email handles and account names, for spelling mistakes and false information, data governance experts will tell you to be aware of what you’re sharing. Not how the scammers are contacting you.
Financial services firms operating in the EU are now bound by the Digital Operational Resilience Act (DORA), which treats ICT and data-handling failures as operational risk, not just IT risk, with penalties running up to 2% of annual global turnover. UK and EU firms already carry GDPR obligations that apply just as much to a CRM record as to a bank account. None of this is written with marketing or growth teams in mind, but none of it exempts them either.
Here's what makes this interesting for anyone running a growth function, not just a security team: the tools that made Sheila's name discoverable in thirty seconds are the same tools growth teams use every day. ZoomInfo, Sales Navigator, enrichment tools, the entire category of software built to find a prospect's name, title, and company in seconds exists because data is public, structured, and cheap to pull. We know this because it's our job. We build these pipelines for clients.
That's not an argument against enrichment. It's an argument for treating the data your own growth stack touches with the same discipline a bank treats its fraud systems. The asymmetry runs both ways. If Evara can pull a CEO's name and title from Companies House in seconds to build an ICP, so can anyone building a scam. The difference is what happens to the data once it's inside your systems, not the tools themselves.
What we need to consider when working with data is:
All of these are not phishing questions but the same governance questions banks have been forced to answer under DORA and GDPR. We just applied them to the growth systems most fintechs still treat as Marketing's problem, not Compliance's.
Here's the problem with "is this tool safe" as a question: most people answer it by checking whether the vendor has a badge on their homepage. That's not nothing, but it's not the whole answer either. Some of these badges mean a lot. Some mean almost nothing without the report behind them. It's worth knowing the difference before you plug another tool into your stack.
|
Certification |
Description |
|
Not a certification, technically. It's an attestation report from a licensed auditor, built around five criteria: security, availability, processing integrity, confidentiality, and privacy. Type II matters more than Type I, because Type I checks whether controls exist on one day; Type II checks whether they actually held up over a period of months. The report itself is confidential; you have to request it and sign an NDA to read it. |
|
|
A real, publicly verifiable certification, issued by an accredited body, covering the vendor's entire information security management system rather than a single product. Recognised in over 160 countries, which is why it tends to matter more for vendors selling into the EU or UK than SOC 2 does on its own. |
|
|
It's the first international standard for AI management systems specifically, published in December 2023 and now showing up in roughly 40% of enterprise AI vendor RFPs in the EU. If a tool uses AI to enrich, score, or act on your data, this is the certification that says someone is actually governing that AI system, not just the infrastructure underneath it. Most vendors don't have it yet. That's useful information too. |
|
|
A DPA sets out who's the controller, who's the processor, what happens to sub-processors, and what happens to your data when the contract ends. |
Evara holds ISO 9001 and ISO 27001 certification, the two internationally recognised standards our fintech and financial services clients most often ask about when evaluating a growth partner who will handle sensitive customer and prospect data.
ISO 9001 is the international standard for quality management systems. Certification means Evara's delivery processes, from ICP development through lead scoring and smart lead generation, are documented, consistently applied, and independently audited on an ongoing basis, rather than depending on any one person's way of working. For clients, that translates into predictable delivery quality and a paper trail for how decisions and outputs are reached, not just what they are.
ISO 27001 is the international standard for information security management systems (ISMS), covering how an organisation identifies, manages, and reduces risk to the data it handles. Certification means Evara's approach to client and prospect data, access controls, data handling procedures, incident response, and ongoing risk assessment, has been independently audited against a recognised global standard, not just described in an internal policy document. This sits at the centre of how we build lead scoring models, ICP frameworks, and intent-signal pipelines for clients operating under GDPR, DORA, and equivalent regulatory regimes.
If a tool now lets an AI agent act on your behalf (e.g.: querying your CRM, enriching a list, pulling records through an MCP connection) the old SaaS security checklist isn't enough on its own. The Model Context Protocol's own security specification, formalised in the November 2025 spec, sets out what a safe implementation actually requires:
None of this is theoretical caution. The first malicious MCP package was found in the wild in 2025, stealthily exfiltrating email data via BCC for two weeks before anyone noticed. If a vendor can't tell you plainly how their AI features handle authorization, that's the question to ask before the badge.
So, what do certificates mean? A certificate tells you someone audited the vendor once. A DPA tells you what happens to your data contractually. Neither tells you whether the specific AI feature you're about to switch on was built with the same care as the rest of the platform. Ask about that part directly.
We build lead-scoring models, ICP frameworks, and intent-signal pipelines for financial services companies. Every one of those systems touches the same category of data that made Sheila's email possible – names, titles, companies, contact details, often enriched from the exact same public sources an attacker would use.
The governance question isn't whether to use that data. It's whether the systems built around it can withstand the same scrutiny a bank applies to its own fraud infrastructure: documented access, clear retention rules, and an audit trail that survives contact with a regulator.
That's the standard we build to. It's worth asking whether your current stack does too.
WRITTEN BY
Related Thinking
DIGITAL MARKETING
From the death of keyword dependence to the rise of PR in SEO, BrightonSEO experts revealed the technicalities, research, data,
Anita Jordan
The financial world moves fast. Customers expect instant answers, regulators expect spotless compliance, and competitors expect
Sheila Mitham
DIGITAL MARKETING
HubSpot's annual Inbound conference has gone digital this year due to the coronavirus, but that hasn't stopped it being a huge
Rowland Marsh
GET IN TOUCH
Every growth challenge is different. Tell us where you are today and we will share a clear perspective on what is possible. No obligation. Just a focused conversation with someone who understands Financial Services.
No obligation. Response within 1 business day.