INDUSTRY
CPA & Accounting
SIZE
~150 employees
ENGAGEMENT
WISP & compliance posture review
FRAMEWORKS
IRS Pub. 4557 · FTC Safeguards · CIS Controls v8 · Cyber Liability
Overview
A regional CPA firm with roughly 150 employees engaged Dynamic Quest to review its Written Information Security Plan (WISP), cybersecurity policies, and overall compliance posture. The firm had strong technical controls in place, but leadership recognized growing pressure from IRS Publication 4557, the FTC Safeguards Rule, and client expectations around data protection. They wanted documentation, processes, and controls that were not just compliant but defensible and sustainable.
The challenge
The firm believed it was "in good shape," but had concerns in three areas: whether the existing WISP and policies truly aligned with current regulatory requirements; the gaps between what IT was actually doing and what was formally documented; and its confidence in responding to client questionnaires, regulatory scrutiny, or a potential incident.
"We had pieces of almost everything, but not a cohesive, defensible program. We needed to know where we really stood."
Executive Operations Partner
The Approach
Discovery & CurrentState Review
Reviewed the existing WISP, policies, and procedures, then interviewed leadership to understand how the firm runs and mapped current controls to CIS v8, IRS 4557, and the FTC Safeguards Rule.
Gap Analysis
Identified gaps between documented policy and actual practice, separating findings into "required for compliance" and "recommended for best practice."
Policy & WISP Alignment
Rewrote and consolidated policies to reflect how the firm runs, aligned to the frameworks while staying practical and usable.
Roadmap & Ongoing Structure
Delivered a prioritized remediation roadmap and a plan for maintaining compliance over time, not just achieving it once.
The Experience
Both leaders called the process detailed but highly practical, focused on real implementation rather than theory.
"We've always had strong controls in place, but this connected everything. It tied what we were doing in IT directly to what's required for compliance, and made it understandable for the business."
Chief Information Officer
"This wasn't just about documents. It gave us a clear, defensible position. I now feel confident in how we'd respond to a client request or a regulatory review."
Executive Operations Partner
The Results
Clear Compliance Alignment
A WISP and policy set aligned to IRS 4557, the FTC Safeguards Rule, CIS Controls v8, and cyber-liability requirements.
IT and Compliance, Connected
Closed the gaps between technical controls and documentation. What's done, what's left, what's documented, and what you can demonstrate now line up.
A Defensible Position
Ready to confidently respond to client security questionnaires, regulatory inquiries, and audit or duediligence requests.
A Sustainable Framework
A structured approach to maintaining compliance, clear ownership and accountability, and a roadmap for ongoing improvement.
The Takeaway
"It's rare to find a team that understands both the technical side and the compliance side at this level. This gave us a framework we can actually maintain." For CPA firms, strong security controls alone aren't enough. True compliance requires alignment across technology, documentation, and operations. This engagement delivered more than compliance: clarity, confidence, and a long-term framework for managing risk.