Skip to content
Tidebreak Advisory

Industry-Specific Insights

One Security Gap, Four Different Obligations

A managed service provider with standing administrative access is one technical fact, and it reads as a distinct professional obligation in a law firm, a CPA practice, a medical group, and a registered investment adviser.

A managed service provider holding standing administrative access to a firm's file system is one technical fact. I have seen it in nearly every environment I have assessed, and on its own it is neither good nor bad. It is a configuration. What changes is what that configuration means once you read it against the professional standard the firm actually answers to.

That is the part most security work skips. A vulnerability scanner reports the access as a control state. A questionnaire records it as a yes or a no. Neither of them tells the managing partner what she is on the hook for. The obligation does not live in the security framework. It lives in the rules that govern her profession, and those rules read the same fact four different ways depending on whose office you are sitting in.

I want to walk through the same gap, standing administrative access by an outside MSP, across the four verticals Tidebreak serves. Then I want to explain why we map every finding twice, and what that second mapping is doing that the first one cannot.

The same fact, four readings

In a law firm, the MSP engineer with that access is a nonlawyer assistant. ABA Model Rule 5.3 (ABA Model Rules of Professional Conduct, as updated through 2023) makes the firm responsible for supervising the conduct of nonlawyer assistants, and the engineer's hands on the document system put him squarely inside that rule. The obligation is not that the access is forbidden. It is that the firm must be able to show a documented basis for the supervision that is happening. A named contact, a defined escalation path, a periodic review of what the MSP did against what it was asked to do. If the firm cannot produce that record, Rule 5.3 is being met in practice and not in writing, and the people who ask for the writing are auditors and carriers.

In a CPA practice, the same access reads through the AICPA Code of Professional Conduct (as updated through 2025) and, more pointedly, through SQMS No. 1 (effective December 15, 2025). SQMS No. 1 asks the firm to design and operate a system of quality management, and a service provider that can reach client tax files and workpapers is a resource inside that system. The firm has to consider whether that resource is appropriate and whether the risks it introduces are addressed. Layer the IRS tax-practice overlay on top, IRS section 7216 and IRS Publication 4557, and the same engineer is now also a person with access to taxpayer information that the practice is obligated to safeguard. The access did not change. The number of standards reading it went up.

In a medical group, the MSP is a business associate, and the access is governed by the HIPAA Security Rule and Breach Notification Rule (45 CFR Part 164 Subparts C and D). The practice owes a risk analysis under section 164.308(a)(1), and the technical safeguards at section 164.312 expect access to be controlled and accounted for. Standing administrative access that nobody reviews is not a violation by itself. It is an input to a risk analysis that, in too many practices, was never performed in a way that would survive a request to see it.

In a registered investment adviser or other financial-services firm, the same access sits under the FTC Safeguards Rule (16 CFR Part 314, as amended 2023), SEC Regulation S-P (2024 amendments), and, for New York-connected firms, NYDFS 23 NYCRR Part 500 (Second Amendment). The Safeguards Rule's written risk assessment under section 314.4(b) is signed by the firm's qualified individual. That signature is supposed to rest on independent work. An outside party with administrative reach into systems holding customer information is exactly the kind of fact the qualified individual is signing about. The access is a line item in someone's accountability.

One configuration. Four professions. Four readings, and not one of them is interchangeable with another.

Why the security framework alone is not enough

Here is the trap. A security framework will tell you the access exists and whether it is governed by a control. CIS Controls v8.1.2 (2024) has a clean account of it: account management, access control management, the safeguards that expect privileged access to be inventoried, justified, and reviewed. NIST CSF 2.0 (2024) places the same concern under Protect and Govern. Both are right, and both are necessary. I map every finding to CIS Controls v8.1.2 first and NIST CSF 2.0 second because that is the language an MSP and an IT team can act on without translation.

But a managing partner does not lose sleep over a CIS safeguard number. She loses sleep over Rule 5.3. A CPA firm's quality leader does not answer to a NIST function. He answers to SQMS No. 1. The security framework tells the technician what to fix. The professional standard tells the principal why it is hers to answer for. A finding that names only the first half is a finding the buyer cannot carry into the room where the decision gets made.

This is the whole reason Tidebreak maps findings twice. The dual framework mapping pairs a security-framework reference, CIS Controls v8.1.2 as the primary and NIST CSF 2.0 as the governance-tier secondary, with the professional-standard reference for the firm's vertical. The security side makes the finding fixable. The professional-standard side makes it the principal's problem, in the principal's own vocabulary. Neither side is decoration. The pair is the point.

The discipline of the second mapping

I will be plain about the limit, because it is easy to abuse this. Forced dual mapping dilutes. If I have to stretch to connect a finding to a professional standard, I have a finding with one honest mapping, not two, and I would rather state the one than manufacture the second. An untested backup, for instance, is a sharp CIS Controls v8.1.2 finding on its own. When it sits in a medical group, it also bears on the contingency expectations behind the HIPAA Security Rule, and that second mapping is real. When the second mapping is real, it goes in. When it is not, the single mapping stands, and the finding is stronger for the honesty.

That restraint is what separates an assessment from a sales motion. A free assessment from a provider that wants to sell you something downstream has every reason to over-map, because more obligations cited reads as more urgency. Tidebreak's compensation is not tied to what the assessment finds, so the mapping can be exactly as wide as the fact supports and no wider.

What this means for the buyer

If you run a firm in one of these four verticals, the test is simple. When your IT provider hands you a report, or when a scanner produces a finding, ask whether anyone has read it against the standard that governs your profession. Not the security framework. The standard with your name on it: the Model Rule, the AICPA Code and SQMS No. 1, the HIPAA citation, the Safeguards Rule section.

Most of the time, no one has. The provider speaks security, the regulator speaks obligation, and the translation between them is the work that falls to you in the room with your partners. That translation is what an independent assessment is for. We read the environment in the security framework so it can be fixed, and we read it again in your professional standard so you can answer for it. The gap was always one fact. What it costs you depends entirely on whose rules are reading it.