The client is a $15M annual CPA firm in Austin, Texas. The engagement: an independent, third-party audit of disaster recovery and endpoint security, commissioned to validate the deliverables of the firm's Managed Service Provider (MSP), align IT operational security with the firm's actual risk tolerance, and give the Board of Directors unbiased assurance they could stand behind.
The Challenge: Operational Trust vs. Unmitigated Risk
The firm had already lived through a catastrophic ransomware attack under a previous MSP, one that caused severe productivity loss and compromised data. Since then, it had moved to a new provider that delivered solid day-to-day IT support. But quality support wasn't the same as proof, and the trauma from the prior breach kept firm leadership up at night.
Three friction points stood in the way of real peace of mind:
- Self-Graded Homework: The MSP routinely provided internal reports certifying that backup and disaster recovery efforts were sound. Without an independent layer of validation, leadership had no way to confirm those metrics matched real-world recovery expectations.
- Fear of Recurrence: Operating in the financial sector, the firm faced existential threats from ransomware and sensitive client data exfiltration.
- Hesitancy to Discard Quality Support: The firm valued its relationship with the current MSP and worried that bringing in an outside advisor would create friction or imply a lack of trust.
Chris McGlasson was brought in as a strategic Fractional CIO to bridge the gap between technical execution and executive business risk, ensuring the MSP's services were directly aligned with the firm's overarching goals.
Chris McGlasson's Approach: Collaborative Alignment
Chris established immediate transparency with both firm leadership and the incumbent MSP. Rather than positioning the engagement as adversarial, he framed it as a collaborative alignment exercise: the MSP delivers the technical infrastructure, and he independently verifies that the infrastructure maps to business continuity and board-level risk expectations.
Independent Audit
Technical Execution
Technical Audit & Assessment Scope
Chris executed a comprehensive third-party assessment across two core pillars: disaster recovery and business continuity, and endpoint detection and management.
Disaster Recovery & Business Continuity (DR/BC) Audit
To verify that recovery capabilities matched the firm's operational tolerances, Chris conducted a granular technical review that went well beyond standard backup log checks:
- RPO & RTO alignment: evaluated Recovery Point and Recovery Time Objectives against the firm's actual downtime tolerance during peak tax and audit cycles
- Immutable & air-gapped backups: inspected backup architecture to verify block-level immutability and offline/air-gapped storage, ensuring restore points couldn't be encrypted or deleted by compromised domain admin credentials
- Restoration testing validation: audited historical, fully virtualized boot-test results, spinning up VMs from backup images in isolated sandbox environments, rather than relying on simple file integrity checks
- Retention & GFS schema: verified Grandfather-Father-Son retention rules for compliance with financial record retention mandates and long-term point-in-time recovery
Endpoint Protection & Security Posture Audit
To address exfiltration and lateral movement concerns, Chris assessed the technical efficacy of endpoint defenses:
- Zero Trust acceleration: recommended and guided a more aggressive shift from perimeter-based trust to strict identity verification, explicit access controls, and continuous micro-segmentation
- Behavioral EDR/MDR architecture: confirmed deployment of signatureless Endpoint Detection and Response / Managed Detection and Response agents capable of real-time memory analysis, script-blocking, and automated isolation
- Least privilege & attack surface reduction: audited endpoint policies for LAPS enforcement, application allowlisting, and macro-execution restrictions across end-user workstations
- Data loss prevention & exfiltration controls: evaluated egress filtering, external storage restrictions, and email tenant security configurations to prevent exfiltration of sensitive tax documents
- Patch orchestration & vulnerability scanning: evaluated OS and third-party application patch cadence alongside automated vulnerability scanning routines
Outcomes & Board Presentation
Chris synthesized complex technical architecture into a clear, risk-adjusted reporting package for the firm's executive team and Board of Directors.
- Unbiased assurance: delivered an objective third-party report to the Board confirming the MSP's infrastructure met defined business continuity standards
- Enhanced posture: identified minor architectural gaps in retention policies and endpoint isolation procedures, with actionable remediation steps the MSP successfully implemented
- Preserved MSP synergy: strengthened the relationship between the firm and its MSP by establishing clear, shared definitions of success without disrupting daily IT operations
- Leadership peace of mind: turned hope-based security into verified operational resilience, eliminating executive anxiety over ransomware recurrence
Conclusion
The firm didn't need a new MSP. It needed independent proof that the one it already trusted was actually delivering what it claimed. Chris's Fractional CIO audit turned self-graded homework into verified, board-ready assurance, without a single day of disruption to the firm's daily IT operations.
Stop grading your own homework.
If your board or leadership team needs independent, unbiased assurance that your MSP's backup, disaster recovery, and endpoint security actually hold up, Chris McGlasson is ready to help.