List of UK Wealth Management companies that are not secure by default

By Stephen Kellett
15 December, 2017

This is one of several posts of the topic of security of websites. Inspired by my initial post on the security of UK banks.

The reason for splitting this data into multiple posts is to make it more manageable. So that data on one institution is not mixed with data on another type of institution.

This is an updated version of an earlier post. We have added 15 companies since the first version.

The following key is used for the secure status:

YesThe site is secure, loaded via https
InvalidThe site loads via https, but the security certificate is invalid and thus the site is insecure.
PartialThe site loads via https, but loads some parts of the page without https. The site is insecure.
NoThe site is loaded via http, not via https.
FixedThe site is loaded via https, but at the time of first writing it was loaded via http.
??We could not find a website to evaluate.

We tested 68 wealth management companies. We found 18 wealth management companies that did not have a secure home page (not https or did have https with an invalid security certificate). That is 27% of UK wealth management companies have security vulnerabilities

Wealth Management CompanySecureHome Page
Aberdeen Asset ManagementNo
Aberdeen Asset Management Trust CentreNo
Allianz Global InvestorsYes
Artemis Investment Management LLPYes
Baillie GiffordYes
Barclays WealthYes
Brewin DolphinYes
Cantab Asset ManagementYes
Capital InternationalYes
CBRE Global InvestorsNo
Charles StanleyYes
City Asset Management PlcNo
Clifton asset managementYes
Close Brothers Asset ManagementYes
Equester Capital ManagementYes
Fidelity Worldwide InvestmentYes
Franklin TempletonNo
Hargreaves LansdowneNo
Hawksmoor investment managementNo
Heartwood investment managementNo
Henderson Global InvestorsYes
Hermes Investment ManagementYes
Interactive InvestorNo
Investec BankYes
Invesco PerpetualYes
Kleinwort HambrosYes
Lion TrustNo
London and CapitalYes
M&G Securities LtdNo
Mattioli WoodsYes
Mayfair CapitalYes
Money FarmYes
Morning StarNo
Newton Investment ManagementYes
Nova FinancialYes
Old Mutual WealthYes
Prospect Wealth ManagementYes
Psigma investment maangementNo
Quilter CheviotYes
Sanlam Life and Pensions UK LimitedYes
Saranac PartnersYes
Scalable CapitalYes
St. Jame’s PlaceYes
Standard Life InvestmentsYes
State Street Global AdvisorsYes
SVM Asset ManagementNo
T Rowe PriceYes
Threadneedle Asset ManagementYes
Tilney GroupYes
Troy Asset ManagementNo
UBS Global Asset ManagementYes
Unicorn Asset ManagementYes
Vanguard Asset ManagementYes
Wealth HorizonNo


It is interesting that you cannot trust a name or a brand to be secure. For example, Aberdeen Asset Management is probably the one name that is most known in the UK. They are regularly featured on the early morning BBC Radio 4 Today Programme to provide their expert opinion. Unfortunately, their website is not secure.

A number of these companies have names that sound old and established, or strong and reliable. They are names, just that. The reliability is in their behaviour. A key part in that is “are they secure”?


I shouldn’t need to point this out, but i will, all the same, just to be clear.

The data provided on this page should taken at face value. If you’re not sure about something, please verify it yourself. Nothing reported here should be regarded as a criticism or an endorsement or recommendation of an organisations security effectiveness. I am simply passing comment on whether the home page (whatever that may be) is provided as https on not. Other security concerns are a separate matter.

If your organisation is listed here and is not marked as secure, your best course of action is to fix that, not to complain that someone is reporting a fact anyone with a web browser can discover. The security status of your home page is public information, albeit information that many people don’t understand.

Fully functional, free for 30 days