Cybersecurity Audit for Actuarial Consulting Firm
- Cybersecurity
- Confidential
- Jan. 2017 - Ongoing
- Quality
- 5.0
- Schedule
- 5.0
- Cost
- 4.0
- Willing to Refer
- 5.0
"They’ve been there every step of the way and done everything as we agreed."
- Financial services
- Minneapolis, Minnesota
- 11-50 Employees
- Phone Interview
- Verified
FRSecure is conducting a SOC 2 audit to ensure data security. The process involves remote and on-site examination of both digital assets and physical conditions.
FRSecure identified several points of weakness and suggested concrete resolutions. Testing is thorough and communication consistent regardless of circumstances.
A Clutch analyst personally interviewed this client over the phone. Below is an edited transcript.
BACKGROUND
Introduce your business and what you do there.
We’re a small actuarial consulting firm with 11 employees.
OPPORTUNITY / CHALLENGE
What challenges were you trying to address with FRSecure?
We had a client that was worried about their data, so we were basically required to do a SOC 2 (Service Organization Controls) audit if we wanted to keep them as a client. This was the first time we interacted with a cybersecurity company in this way.
SOLUTION
What was the scope of their involvement?
Everything’s been related to a SOC 2 audit. We’ve done two to three different engagements with them related to that. A lot of firms are requiring their partners and vendors to go through a SOC 2 audit. It basically makes sure we have the processes and procedures to minimize risks of a cybersecurity breach. We hold a lot of their data, and they want to ensure we’re secure. That’s where FRSecure came in.
A SOC 2 audit entails getting all your systems up to snuff, and then an auditor comes in to confirm we’re done it right. We’re at the stage right now where FRSecure is helping us get ready for this audit. We’ll have the auditor come in very soon, and we’re hoping we pass. We’re setting up lots and lots of policies. For example, if you have a new employee come in, we have a policy that defines the steps IT needs to take.
They look at our server to make sure it has all the up-to-date stuff, so the client can’t get hit. We have to make sure we lock our file rooms and don’t leave stuff at our desks, all the various things that would increase the chances of Social Security numbers being released to the wrong people. It’s the whole process; setting up all the policies, and then other processes, and working with our internal IT guy to make sure we’re doing the most up-to-date stuff.
We had one on-site meeting, but otherwise, it’s all done remotely. It’s nice to have that option. FRSecure delivers reports and action items as they go along. They’ve given us samples to work with, so we start with those and modify them to meet our firm’s specifics. They’ve been very knowledgeable, and they’ve had a lot of good tools that allow us to work with what they’ve given us and to update.
How did you come to work with FRSecure?
I looked up local auditors who do SOC 2 audits, and they’re the ones who actually referred us to FRSecure. The auditors had worked with them many times and said it’s gone well. They’re a smaller company close to us, so it just made a lot of sense. They were the only company we interviewed.
What is the status of this engagement?
We’ve been working together for almost a year. It’s been taking us a long time, and I’m still not done. That’s not due to anything FRSecure has done, we’re just busy at work. I have to update a few more policies and get that ready for the auditor.
RESULTS & FEEDBACK
Could you share any evidence that would demonstrate the productivity, quality of work, or the impact of the engagement?
We’ve made a lot of changes. We’ve set up all these policies, and now we’ve been having regular IT meetings internally. We’ve had meetings with employees to talk about security. We’ve locked our server room so no one can just walk in and do what they want. We’ve changed configurations on the server based on what FRSecure has told us. We’ve changed how we’re sending data back and forth with clients. Basically, we’ve changed most everything in the overall data process.
We’ve hired them to do penetration testing. They try to attack our server to see if there are any holes in it. They do those monthly. There have been a few things we’ve changed due to these tests, which has been good. They’ve also given us some ideas on disaster recovery and business continuity. We’re still in the process of working on that right now, but they’ve definitely given us some good tools to update that.
How did FRSecure perform from a project management standpoint?
A lot of our communication is by email, but we also have scheduled meetings. We all get on and do a live webcast so they can see what we’re doing. We’re showing them everything we’re setting up, asking questions, and getting ready for this audit. That’s really what we hired them to do, get us ready to pass the audit. If I could spend a couple hours working on this stuff, I think we’ll be ready for the audit. I’ve met with the auditor once, and there were a couple things we still had to do, so we’re very close.
What did you find most impressive about FRSecure?
I didn’t know what to expect. Trying to change all your processes is not fun and not our business. It’s kind of been a pain, but not because of them. We’re realizing that we’re so far behind the times. It’s been good to talk with them, and they’re helping us get into the 21st century and be more prepared.
Are there any areas FRSecure could improve?
I can’t think of anything. They’ve done what we asked them to do. They’ve been there every step of the way and done everything as we agreed.
Do you have any tips for potential clients?
I would tell them that’s it’s going to take longer than they think, and it’s much more involved than they think. They’re going to have to devote someone to spend a lot of time. I’m not sure I would tell them to react any differently regarding FRSecure. I would just warn them as to what’s really involved. For a small business, it takes a lot of time away from doing your real business.
RATINGS
-
Quality
5.0Service & Deliverables
-
Schedule
5.0On time / deadlines
-
Cost
4.0Value / within estimates
"<p>They’re not cheap, but I see the value in it.</p> "
-
Willing to Refer
5.0NPS