Engagements  /  PSY-AUD-0356

Essential hygiene, prioritised into one quarter’s work

A thirty-person accounting practice wanted to be secure without becoming a security company. IG1 was the right size of question.

Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.

Sector
Professional services
Engagement
CIS Controls v8.1 audit
Frameworks
CIS Controls v8.1 Implementation Group 1, NIST CSF 2.0
Duration
3 weeks

An accounting practice.

The practice held tax records, payroll files and bank details for over a thousand clients. Its cyber insurer had raised premiums and asked for MFA, backups and an incident response plan as conditions of renewal.

The managing partner wanted to know what else they should be doing, in priority order, without a hundred-page report.

What we did

The smallest set of controls that matters most.

Assess against IG1

The CIS Controls v8.1 define Implementation Group 1 as essential cyber hygiene for every organisation. We assessed each of its safeguards with evidence, not interviews alone.

Prioritise by attack, not by number

Gaps were ordered by how real attacks on accounting firms start — phishing, invoice fraud, ransomware through remote access — rather than by control number.

Fit it to one quarter

The roadmap fitted into twelve weeks, so the work was done before the insurance renewal date rather than planned around it.

What we found

What insurance asked for, and what it did not.

SeverityFindingMaps toStatus at retest
HighRemote desktop exposed to the internet on the practice-management server.CIS 4.4 · 6.4Closed
HighBackups stored on the same network share they were protecting.CIS 11.4Closed
HighNo MFA on the cloud accounting platform used for client books.CIS 6.3 / 6.5Closed
MediumNo inventory of laptops; two unaccounted for.CIS 1.1Closed
MediumWire-transfer changes confirmed by email reply only.CSF PR.AT · CIS 14.2Closed

What changed.

Every IG1 gap rated high was closed within the quarter, and the insurer accepted the renewal with evidence drawn directly from the audit.

A callback rule for bank-detail changes is now in place, which on its own addresses one of the most common ways firms like this lose money.

Next engagement

Want this for your application?

Tell us what you ship and who is asking for proof. We will come back with a scope and a range.