How Glacier Protects Client Data and Investment Accounts


Glacier by Sanlam says it protects client information through restricted internal access, encrypted digital communications, security testing, and verification checks for sensitive account changes.

These controls aim to reduce two major risks facing financial services companies: criminals gaining access from outside the organisation and unauthorised employees viewing or transferring personal information internally.

Clients also play an important role. Using Glacierโ€™s secure online channels, enabling multi-factor authentication, and carefully checking payment requests can reduce the risk of phishing, account takeovers, and investment fraud.

Glacier limits access to personal information

Glacier by Sanlam says employees only receive access to client data when their roles require it. This access-control approach helps limit unnecessary exposure to financial and personally identifiable information.

The company also monitors the movement of sensitive information. Transfers involving personal data can be tracked and flagged, helping security teams identify activity that may indicate accidental disclosure or deliberate data theft.

These protections matter because security incidents do not always begin with an external hacker. Misaddressed emails, excessive account permissions, compromised employee credentials, and unsafe data transfers can also expose confidential records.

Digital channels use layered security controls

Glacier says the Investment Hub uses security controls approved across the wider Sanlam Group. These cover authentication, authorisation, secure data transmission, and access to services.

Communications between users and the platform are encrypted. Encryption helps prevent third parties from reading information while it travels between a clientโ€™s device and Glacierโ€™s systems.

The company also subjects its digital channels to penetration testing. During these assessments, cybersecurity specialists simulate attack techniques to identify weaknesses before criminals can exploit them.

Security measureHow it protects clients
Role-based accessLimits internal access to employees who need the information for their work.
Data-transfer monitoringFlags suspicious or unauthorised movement of sensitive information.
Encrypted communicationsProtects information transmitted between users and Glacierโ€™s platforms.
Multi-factor authenticationAdds another identity check when a user signs in.
Penetration testingFinds security weaknesses by simulating real attack methods.

Glacier verifies bank account changes

Financial criminals often try to redirect withdrawals or investment proceeds into accounts they control. Glacier says it verifies client identities and submitted information before processing an investment.

The company performs additional checks when important information changes, including bank account details. Its published repurchase requirements also state that money will not be paid into a third partyโ€™s bank account.

Clients should treat unexpected requests to update payment details with caution. A message may look authentic while directing the recipient to a fake login page or a criminal-controlled account.

Secure portals are safer than ordinary email

Glacier recommends using its authenticated portals and applications when sending instructions or personal documents. These channels include security controls that standard email may not provide.

The Glacier website provides access to its client and intermediary services. Users should reach these services through known addresses or saved bookmarks instead of links in unexpected emails or messages.

Clients should also avoid sharing passwords, one-time codes, identity documents, or banking information in response to unsolicited communications. Glacierโ€™s withdrawal documentation reinforces the importance of verified client-owned bank accounts for payments.

How clients can protect their data

No financial platform can remove every security risk. Criminals frequently target users directly because a convincing phishing message may bypass technical protections by persuading someone to reveal information voluntarily.

The US Cybersecurity and Infrastructure Security Agency recommends several basic protections through its Secure Our World programme. These include recognising phishing, updating software, using strong passwords, and enabling multi-factor authentication.

  • Use a long, unique password for every financial account.
  • Store passwords in a reputable password manager instead of reusing them.
  • Enable multi-factor authentication wherever Glacier makes it available.
  • Install security and operating system updates promptly.
  • Check the sender, domain name, and destination of every login link.
  • Do not approve an authentication prompt that you did not initiate.
  • Avoid sending identity documents or banking details through ordinary email.
  • Confirm unusual payment or account-change requests through an official contact channel.

Strong passwords should not require routine changes

Older security advice often told users to create complicated passwords and replace them every few weeks or months. Current guidance focuses on length, uniqueness, password managers, and evidence of compromise.

The latest NIST digital identity guidance says service providers should not force periodic password changes. A password should instead be replaced when there is evidence that it has been exposed or compromised.

Users should also turn on an additional sign-in factor. CISAโ€™s multi-factor authentication guidance explains that a second verification method can prevent access even when a password has been stolen.

How to recognise a phishing attempt

Phishing messages often create urgency. They may claim that an investment account has been suspended, a transaction requires immediate approval, or a user must confirm personal details to avoid losing access.

Common warning signs include spelling mistakes, unexpected attachments, unusual sender addresses, shortened links, requests for passwords, and pressure to act without checking the request independently.

The Secure Our World guidance advises users to recognise and report suspicious messages rather than clicking their links. Clients should open Glacierโ€™s portal separately and contact the company through an official number when a request appears unusual.

  1. Stop before opening the link or attachment.
  2. Check the full sender address rather than the displayed name.
  3. Open the official Glacier portal independently.
  4. Review the account for alerts or pending actions.
  5. Contact Glacier through a verified channel if the request remains unclear.
  6. Report and delete the suspicious message.

Multi-factor authentication adds an important barrier

Multi-factor authentication requires more than a password. Depending on the service, a user may also need an authenticator app, security key, biometric check, or temporary verification code.

CISA recommends phishing-resistant authentication methods where they are available. Its MFA recommendations note that the extra identity check makes unauthorised access more difficult.

Users must still remain cautious. Criminals may send repeated approval requests or impersonate support staff to persuade a victim to disclose a code. Never approve a login request that you did not initiate.

Data security requires shared responsibility

Glacierโ€™s internal controls, encryption, penetration testing, and account-verification procedures create several barriers between client information and potential attackers.

Clients strengthen those barriers by using secure portals, protecting their login details, checking payment changes, and treating unexpected requests with suspicion.

The NIST authentication standard also supports a practical approach: use long and unique passwords, avoid unnecessary scheduled changes, and replace credentials promptly when compromise occurs.

FAQ

How does Glacier protect client data?

Glacier says it uses restricted employee access, data-transfer monitoring, encrypted communications, penetration testing, multi-factor authentication, and verification checks for sensitive account changes.

Does Glacier use multi-factor authentication?

Glacier says its secure client and intermediary channels use login controls and multi-factor authentication to provide additional protection against unauthorised access.

Is it safe to send personal information to Glacier by email?

Glacier recommends using its authenticated portals and applications whenever possible. Secure portals provide more protection than ordinary email when submitting personal or financial information.

How does Glacier verify changes to bank details?

Glacier says it checks client identities and verifies important information again when details such as a bank account change. Its withdrawal documentation states that payments will not go to a third-party account.

Should clients change their passwords regularly?

Clients should change a password when they suspect or confirm that someone has compromised it. Current NIST guidance does not recommend forced password changes on a fixed schedule.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages