Case study

SOC 2 compliance for a Southern California accounting firm

An accounting firm with more than 200 professionals across Los Angeles and Orange County needed SOC 2 compliance and a security program that could grow with it. We built the program, then stayed on as its vCISO.

  • A SOC 2 compliant environment
  • Immutable backups against ransomware
  • Ongoing vCISO guidance on policy and risk
Two colleagues reviewing financial reports

The challenge

Sensitive client data and a growing footprint

The firm is long established and offers tax planning and consulting, audit and assurance, and advisory services. Its team of more than 200 professionals, with offices in Los Angeles and Orange County, serves privately held businesses, nonprofit organizations and high-net-worth individuals, and handles sensitive financial data and personally identifiable information (PII) every day.

As the firm added clients and new technology, it needed security that could scale with its infrastructure, a program that met SOC 2 requirements, and continuing guidance as threats and expectations changed.

  • Sensitive client financial data and PII
  • A growing client base and technology footprint
  • SOC 2 compliance required
  • A need for continuing security guidance
Team reviewing findings around a conference table
Security advisor speaking on a video call

What we did

A tailored program mapped to SOC 2

We designed and implemented a cybersecurity program mapped to the firm’s path to SOC 2 compliance, so it could meet requirements without slowing down its work. As operations grew, we added capacity to the program and continued as the firm’s virtual CISO.

As vCISO, we guide decisions on cybersecurity policy, risk management and compliance, and help the firm identify and acquire the security tools that fit its needs.

  • Discovery and assessment of existing infrastructure and security
  • Multi-factor authentication for critical applications with PII
  • Segmentation of PII behind 24/7 SOC services
  • An immutable backup solution for business continuity
  • vCISO consulting and security tool recommendations

Results

What the firm gained

  • A SOC 2 compliant environment that protects client data
  • Visibility into blind spots, so threats can be triaged and investigated
  • Immutable backups that keep ransomware from disrupting the business
  • Security infrastructure that scales as the firm grows
  • Continuing vCISO guidance on policy, risk and compliance
  • The ability to show clients how their data is protected

Talk to a compliance expert

Plan your path to SOC 2

Tell us about your firm and your compliance deadline. An advisor will reply by email to talk through readiness and a security program that fits.

  • A mapped path to SOC 2 compliance
  • vCISO support after you get there

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message