AccuSights
PartnersBlogAbout
Book my 30-minute demo

Agencies, Staffing & Consultancies · Cybersecurity, compliance and GRC, in plain English

Your clients trust you with their secrets. Prove it.

To your clients you are the third party, and third parties were in 48% of breaches in the 2026 DBIR. One forwarding rule in one mailbox leaks every pitch, contract and invoice for weeks; one open account lets a departing director take the client list. We protect the inboxes, scope client files by engagement, write the AI-use policy and hand you the evidence the next security questionnaire asks for.

Questionnaire-ready evidenceSOC 2 path when a client insistsSee your score immediately

The test is scored against CIS Controls v8.1 IG1 and the CIS Community Defense Model. You see your score immediately, then we talk if you want to.

A story we hear too often

The Thursday an agency’s bank pitch almost left with the invoices

the founder of a 35-person marketing agency

Priya built the agency from a spare bedroom in Wicker Park into 35 people and a client list she still knows by heart. Thursday is pitch day. The team has spent three weeks on a rebrand for a regional bank, and the deck, the pricing and the research sit in a shared drive next to every other client’s.

At 4:10 a client calls to ask why she received an invoice from the agency with a new bank account, and why it came from a domain one letter off. Priya pulls up the mailbox. A rule has been forwarding every message with ‘invoice’ or ‘contract’ in the subject to an outside address for three weeks. The bank pitch went too.

In the version that goes badly, two clients pay the wrong account, the bank’s confidential research is in a competitor’s hands, the security clause in the master services agreement becomes a breach-of-contract letter, and a departing account director takes the client list on the way out because nobody turned off her access.

In Priya’s version, the forwarding rule tripped an alert the day it was created. The engineer removed it, reset the account and found the look-alike domain the same afternoon. The invoice never reached a client. The pitch goes ahead Thursday. Priya wins it.

A rule has been forwarding every message with ‘invoice’ or ‘contract’ in the subject to an outside address for three weeks.

What changes the ending

  1. Mailbox MFA and alerts on forwarding rules, the quiet tool of every invoice fraud (CIS Controls 5 and 9, Account Management and Email Protections)
  2. Client files scoped by engagement, with access ending the day someone leaves (CIS Controls 6 and 3, Access Control and Data Protection)
  3. A named person watching the logs with authority to reset an account at 4:10 on a Thursday (CIS Control 13, Network Monitoring and Defense)
Show me this running for my business

The questions owners are afraid to ask

Ask them anyway. Here are the answers.

What if my best account director walks out with the entire client list and our pricing?

It happens in every services firm that leaves the CRM and the shared drive open to everyone. We scope client folders by engagement, restrict and log exports, and disable accounts the hour notice is given, which is also what makes your non-solicitation clause enforceable.

A client’s security questionnaire asks for SOC 2. Do we need it?

Not always; most mid-market clients accept evidence that the basics run: MFA, endpoint protection, backups, access reviews and a response plan. The assessment produces that evidence, and if an enterprise client insists on SOC 2, the same controls carry you into the readiness package.

Our staff use AI tools for client work. Is that a security problem?

It is when client research, source files or personal data go into consumer accounts with no policy: the latest DBIR found 67% of employees using AI on work devices through non-corporate accounts. We write the policy, set up approved tools and monitor uploads so the work continues and the client data stays yours.

What you hold, and why someone wants it

Your data protection needs, by the data.

Client files, research and unreleased work

The pitch, the campaign, the strategy and the source files a competitor would pay for. Engagement-scoped access and monitoring protect them.

Candidate and placement records

Resumes, Social Security numbers, pay rates and background checks for thousands of people in a staffing firm. Encryption, access limits and retention rules protect them.

The client list, contracts and pricing

The firm’s equity, exportable in one click. Role-based access and export logging protect it.

Invoices, receivables and bank details

The channel invoice fraud hijacks. Mailbox MFA, forwarding-rule alerts and a call-back rule protect it.

Credentials to client systems

Your logins to clients’ ad accounts, CMS, cloud and data. Password management, MFA and offboarding protect them and the client’s trust in you.

Staff use of AI tools

Client data pasted into consumer AI accounts becomes a contract problem. Policy, approved tools and upload monitoring protect it.

$3.05B
lost to business email compromise in 2025; the look-alike invoice from an agency or consultancy domain is the professional-services version
Source: FBI IC3 2025 Internet Crime Report
67%
of employees using AI on work devices did so through non-corporate accounts, and source code and research documents were the most common data uploaded
Source: Verizon 2026 Data Breach Investigations Report
48%
of breaches involved a third party, up 60% in a year; to your clients, you are the third party
Source: Verizon 2026 Data Breach Investigations Report

No regulator at the door, still rules that apply

What you are still on the hook for, in one page.

Client master services agreements and security addenda
Your clients
Confidentiality, breach-notice windows, MFA, endpoint protection and sometimes SOC 2 or ISO 27001 evidence as conditions of the engagement.
State privacy laws
State attorneys general
Processor and contractor duties in twenty comprehensive privacy laws; candidate and consumer data you hold for clients is in scope.
GLBA Safeguards and DFARS 7012, by client
FTC and DoD
Serving a financial institution makes you a service provider under the Safeguards Rule; serving a defense prime flows down DFARS and NIST 800-171.

Verified September 2026 from the regulators' own publications. We map all of it to one control set so evidence is produced once.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

The threat picture

What actually goes wrong, and what we do about it.

  • A forwarding rule in one mailbox that leaks every invoice, contract and pitch for weeks.
  • A departing account lead who exports the client list and pricing because access never ended.
  • Client data in consumer AI accounts, which turns a productivity habit into a breach of the master services agreement.

It happened to businesses like yours

A ransomware attack on a Manpower staffing franchise between December 29, 2024 and January 12, 2025 exposed the personal information of 144,189 people; the RansomHub gang claimed about 500 GB of data.

December 2024 to January 2025 · BleepingComputer

Dentsu’s US agency Merkle detected a cyberattack on October 27, 2025, took systems offline and confirmed that files on clients, suppliers and current and former employees were taken.

October 2025 · Security Affairs

Public incidents, listed to show the pattern, never to shame a victim.

Protect, for a professional services business

We protect your people, every device, the servers and the website. Day and night.

  • We protect every employee’s inbox, where the look-alike invoice and the spoofed founder request arrive.
  • Every laptop and workstation, in the office, at home and at the client site.
  • The server, the shared drive and the cloud storage holding client files and contracts.
  • The website, the client portals and the tools you log into on clients’ behalf.
  • The cloud apps: email, CRM, project management, design and ad platforms, payroll and the applicant tracking system.
  • Day and night, with an AI agent that contains a threat in seconds and a named human engineer watching.

Think of it as a per-employee service, like payroll. Except that this is the one corner that, if you cut it, can empty the account and take the business with it. We have your back.

How Protect works →

Where we start

Cybersecurity and Data Protection Assessment for Professional Services

Built on the CIS Controls v8.1 IG1 and scoped from what a services firm stands to lose: the client’s secrets, the client list and the invoice cycle. It produces the evidence pack your clients’ questionnaires ask for, and the SOC 2 path if one of them insists.

  • Inventory of every laptop, cloud app and client-system login the firm holds, including the accounts you run for clients (CIS Controls 1 and 2)
  • Mailbox security review: MFA, forwarding rules, look-alike domain monitoring, invoice-change controls (CIS Controls 5, 6 and 9)
  • Client-data map: which files are scoped by engagement, who can export, and how access ends at offboarding (CIS Control 3)
  • AI-use policy and approved-tool setup, with monitoring of what leaves for consumer accounts (CIS Control 3)
  • Backup and restore test for the shared drive, the CRM and the applicant tracking or project system (CIS Control 11)
  • Questionnaire-ready evidence pack and a ranked remediation plan, with the SOC 2 path mapped if a client requires it
Start with the 3-minute test

Packages

Built for professional services businesses, with the price on the page.

Cyber and Data Protection Assessment

A complete read on your exposure: every endpoint, server, cloud account and identity inventoried, controls tested against CIS and NIST CSF 2.0, threats mapped to your industry, and a plan ranked by what would actually hurt.

Fixed feescoped in 30 minutes
1 to 3 weeks
Details →

SOC 2 Readiness: Type 1 and Type 2

Enterprise and government buyers ask for SOC 2 before they sign.

Fixed feescoped in 30 minutes
Type 1 readiness: 4 to 8 weeks
Details →

Mock Audit Package: SOC 2, HIPAA or CMMC

We run your audit before your auditor does: the same evidence requests, the same interviews, the same sampling, the same findings language.

Fixed feescoped in 30 minutes
1 to 3 weeks depending on framework and scope
Details →

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions owners ask

Straight answers.

Do marketing agencies and consultancies need SOC 2?
Only when a client’s contract requires it, which is increasingly the case with enterprise and financial clients. Most firms start with the assessment and a questionnaire-ready evidence set, then pursue SOC 2 Type I when a specific client asks; the controls are the same.
How do I protect client data as a consultant or agency?
Scope files by engagement so one login cannot reach every client, put MFA on every mailbox and client-system login, alert on forwarding rules, encrypt the laptops and end access the day someone leaves. That covers most of what a client’s security questionnaire is asking.
Is it safe to use AI tools with client data?
With a policy, approved business-tier tools that do not train on your inputs, and monitoring of what leaves, yes. Without those, it is a breach of most master services agreements waiting to be discovered.

People also search: cybersecurity for marketing agencies near me · IT security for consulting firms in Chicago · for a 35-person agency · for a staffing firm with 200 contractors · cybersecurity for a PR firm in Wicker Park · client questionnaire help for consultancies · for an engineering consultancy with client IP · cybersecurity for a recruiting agency

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes with an engineer.

3-min test