Mercer Advisors Security Measures

Your Trust Comes First

At Mercer Advisors, our most valuable asset is the relationship we maintain with our clients.

Protecting your personal and financial information is a top priority for Mercer Advisors, and a shared responsibility. We have implemented a number of safeguards to help protect your data, and together we can reinforce them in ways that align with your preferences and comfort level.

Safeguards Inside Mercer Advisors

Compliance and cybersecurity policies
Mercer Advisors has created and implemented compliance and cybersecurity policies and procedures based on the National Institute of Standards and Technology (NIST) frameworks.

Extra login security
Mercer Advisors employees utilize multifactor authentication (MFA) tokens when logging in to company systems. Our Client Portal also uses MFA. MFA provides an additional layer of account security by requiring more than one verification method to log in to an account.

Wire transfer verification
If you request a wire transfer by email, we will always verify your identity by calling you to confirm before initiating the transfer.

Systems surveillance
We utilize a 24/7 Security Operations Center to monitor our network and infrastructure.

Encryption on all endpoint devices
Mercer Advisors utilizes a Unified Endpoint Management system to encrypt all endpoint devices (laptops, phones, etc.), monitor for malware threats or jailbroken devices, and implement safeguards such as remote lock, device wipe or customizable device quarantine controls where appropriate.

Anti-virus software
Mercer Advisors utilizes anti-virus software and a leading endpoint detection and response solution to help identify and prevent unauthorized activity.

Firewalls
We have implemented firewalls designed to prevent unauthorized access into our networks and computer systems.

Physical security at our offices
Our security measures extend to our physical locations as well. We monitor all work areas to help prevent theft or scrutiny of documents containing sensitive information. In addition, authorized personnel are permitted to enter work areas
only through the use of a security badge, key, or mobile device.

Restricted access to data
We limit access to systems containing client information to only those employees who need it to conduct business.

Protecting Your Online Visits

Username and password requirements
We require you to create a unique username and password when you first access your account. As a best practice, you should use a password that is long and employs a mix of numbers, upper-
and lower-case letters, and special characters. We also recommend that clients utilize a password management system so you do not need to remember several complex passwords. You should also avoid using passwords across multiple sites and platforms or reusing passwords.

Encrypted website
Mercer Advisors provides an encrypted website connection to MercerAdvisors.com and the Client Portal. Information transmitted over an HTTPS connection is encrypted in transit.

Email security
You can send our advisors encrypted email messages. Additionally, we will never ask you to provide your account numbers, username, or passwords over email.

Protecting Your Phone and Video Interactions

Encrypted communication
Mercer Advisors utilizes an encrypted telephone and videoconference system designed to prevent interception of your communications.

Ready to learn more?