Case study

From Strong Controls to a Defensible Program

How a ~150-employee regional CPA firm turned solid IT into a documented, defensible, sustainable compliance program, with Dynamic Quest.

INDUSTRY

CPA & Accounting

SIZE

~150 employees

ENGAGEMENT

WISP & compliance posture review

FRAMEWORKS

IRS Pub. 4557 · FTC Safeguards · CIS Controls v8 · Cyber Liability

feature case studies Regional CPA Firm

Overview

A regional CPA firm with roughly 150 employees engaged Dynamic Quest to review its Written Information Security Plan (WISP), cybersecurity policies, and overall compliance posture. The firm had strong technical controls in place, but leadership recognized growing pressure from IRS Publication 4557, the FTC Safeguards Rule, and client expectations around data protection. They wanted documentation, processes, and controls that were not just compliant but defensible and sustainable.

The challenge

The firm believed it was "in good shape," but had concerns in three areas: whether the existing WISP and policies truly aligned with current regulatory requirements; the gaps between what IT was actually doing and what was formally documented; and its confidence in responding to client questionnaires, regulatory scrutiny, or a potential incident.

img s4 Regional CPA Firm Challenge
ic quote

"We had pieces of almost everything, but not a cohesive, defensible program. 
We needed to know where we really stood."

Executive Operations Partner

The Approach

ic number 01

Discovery & CurrentState Review

Reviewed the existing WISP, policies, and procedures, then interviewed leadership to understand how the firm runs and mapped current controls to CIS v8, IRS 4557, and the FTC Safeguards Rule.

ic number 02

Gap Analysis

Identified gaps between documented policy and actual practice, separating findings into "required for compliance" and "recommended for best practice."

ic number 03

Policy & WISP Alignment

Rewrote and consolidated policies to reflect how the firm runs, aligned to the frameworks while staying practical and usable.

ic number 04

Roadmap & Ongoing Structure

Delivered a prioritized remediation roadmap and a plan for maintaining compliance over time, not just achieving it once.

The Experience

Both leaders called the process detailed but highly practical, focused on real implementation rather than theory.

 
ic quote

"We've always had strong controls in place, but this connected everything. It tied what we were doing in IT directly to what's required for compliance, and made it understandable for the business."

Chief Information Officer

ic quote

"This wasn't just about documents. It gave us a clear, defensible position. I now feel confident in how we'd respond to a client request or a regulatory review."

Executive Operations Partner

The Results

ic s8 Clear Compliance Alignment

Clear Compliance Alignment

A WISP and policy set aligned to IRS 4557, the FTC Safeguards Rule, CIS Controls v8, and cyber-liability requirements.

ic s8 IT and Compliance

IT and Compliance, Connected

Closed the gaps between technical controls and documentation. What's done, what's left, what's documented, and what you can demonstrate now line up.

ic s8 A Defensible Position

A Defensible 
Position

Ready to confidently respond to client security questionnaires, regulatory inquiries, and audit or duediligence requests.

ic s8 A Sustainable Framework

A Sustainable Framework

A structured approach to maintaining compliance, clear ownership and accountability, 
and a roadmap for ongoing improvement.

The Takeaway

"It's rare to find a team that understands both the technical side and the compliance side at this level. This gave us a framework we can actually maintain." For CPA firms, strong security controls alone aren't enough. True compliance requires alignment across technology, documentation, and operations. 
This engagement delivered more than compliance: clarity, confidence, and a long-term framework 
for managing risk.

Know where you stand. Start with
a free Compliance Risk Diagnostic