Blog / Reputation and business risk

Reputation and business risk

Agencies and Staffing Firms: The Shared Drive, the SOC 2 Question, and What to Answer Before You Have a Report

Agency and staffing SOC 2 questions arrive with your biggest deal. What client data in shared drives exposes, and the answer that keeps the deal alive.

Sam KhanSam Khan The Cyber ExpertFounder and CEO24 September 2026 · 6 min read

The folder that has been open since 2019

The managing partner of a twenty-eight person agency has just been told her firm is the preferred bidder on the largest piece of work it has ever chased. Two years, a global brand, enough to hire a fourth account team.

Then the client's procurement lead sends a note asking for the firm's most recent SOC 2 Type II report and a completed vendor security questionnaire.

She does not have a SOC 2. She has a shared drive, eleven freelancers, and a habit of moving fast that clients have paid for since 2016. So she opens the drive to see what a reviewer would find, starting with the sharing report.

Sorted by oldest, the first entry is a folder created in March 2019 for a client that left in 2021. Sharing: anyone with the link can view. Inside it, a product launch plan that was under embargo at the time, two rounds of unreleased creative, and a candidate spreadsheet with names, addresses and dates of birth.

She checks who has the link. Nobody knows, which is the nature of the setting. Twelve rows down, a folder shared with a freelancer who left in 2022 and whose personal email has since turned up in a breach notification.

Nothing has leaked, as far as she can tell. She now has to describe all of this to a procurement lead, in writing.

What the heck does this mean

A SOC 2 report is an independent auditor's opinion on how you handle customer data, written against the AICPA Trust Services Criteria: security first, then availability, processing integrity, confidentiality and privacy, depending on which ones you include.

A Type I looks at whether the controls were designed properly on a single date. A Type II looks at whether they actually operated over a period of months. Buyers want the second one, because the first proves you wrote the policy and not that you followed it.

Jargon translated. Trust Services Criteria: the checklist the auditor scores you against. Scope: which systems and which criteria the report covers, which is how a report can be real and still useless to the client reading it. Evidence: the export, the screenshot, the ticket that turns a yes into a fact.

For agencies and staffing firms, the exposure is rarely a server. It is the drive. Client material under embargo, campaign data, candidate records with national identifiers, freelancer contracts, all in folders created quickly by people whose job is speed. Where twenty US state privacy laws were in force in 2026, candidate and consumer records in those folders carry obligations of their own, on top of whatever the client's contract says. Our professional services page covers the wider picture.

The numbers that matter

Credential theft was behind 31% of breaches in professional services in the Verizon 2026 Data Breach Investigations Report. One freelancer's reused password is the whole attack.

Third parties were involved in 48% of breaches in that same Verizon 2026 report, up 60% year on year. Read that from the client's chair: they are not being difficult, they are being taught.

And a number that is now on questionnaires. In the Verizon 2026 report, 45% of employees used AI tools on work devices, 67% of them through personal accounts rather than a company one. Agency work is exactly where client material gets pasted into a consumer AI chatbot at eleven at night.

What to do this week

  1. Run the sharing report on your drive, sort by oldest, and turn off every link set to anyone with the link. Do it before you answer the questionnaire, because that is the row you will otherwise answer optimistically. (CIS 3 Data Protection)
  2. List every external person with access to anything: freelancers, former contractors, the client's own staff, the agency you subcontracted one project to in 2023. Remove everyone who is not on live work this month. (CIS 5 Account Management)
  3. Give client work a home with a rule instead of a habit. One folder per client, access granted by role, a written close-out step when an engagement ends, and a retention decision on what you keep afterwards. Say that decision out loud to the client; most will thank you. (CIS 3 Data Protection)
  4. Write the AI answer before you are asked. Which tools your team may use for client material, which accounts they must use, and what never gets pasted anywhere. The questionnaire row exists now, and "we have not thought about it" is a poor look next to a two-year contract. (CIS 3 Data Protection)
  5. List your own subcontractors and the software holding client data, with what each one touches. The client's question about your vendors is the same question they are asking you, one step down the chain. (CIS 15 Service Provider Management)
  6. Turn on multi-factor authentication for every account including freelancers, and check that nobody is signing in with a personal account that also holds their side projects. (CIS 6 Access Control Management)

Where AccuSights fits

Our assessment reads your environment the way the client's reviewer will: what is shared with whom, which accounts still work, where client and candidate data actually sits, and which questionnaire answers are true today. You get the evidence folder and a dated plan for the rest, which is what wins the deal while a Type II period is still running. The scoping tool tells you in a few minutes what a SOC 2 would actually cover in a firm your shape, before you commit to an audit.

We map the assessment to your regulators and to the questionnaire itself, and the read-only compliance agent gives you continuous insight into your cloud and infrastructure so you can see what is in place, what has slipped, and what to prioritise. We have no access and we do not remediate. You or your IT partner fix it, and we show you where.

Questions people ask

We do not have a SOC 2 report. What do we tell the enterprise client? Tell them the truth with a date on it. Something like: we do not hold a SOC 2 report today, we have completed an independent assessment against the same criteria, here are the results, here are the four items still open and the month each closes, and here is our decision on a Type I engagement. Procurement teams read hundreds of workbooks a year and can spot a wish list instantly. A dated plan beats an unsupported yes, and it survives the conversation that happens after an incident.

SOC 2 Type I or Type II: which one do buyers actually want? Type II, almost always. A Type I says the controls were designed properly on a given date. A Type II says an auditor watched them operate over a period, commonly three to twelve months. Both report against the AICPA Trust Services Criteria. A Type I is a reasonable first step because it forces the design work and gives procurement something concrete, but expect the buyer to ask when the Type II period starts.

Is a shared drive link really a security issue? It is the most common one we find in agencies and staffing firms. Link sharing set to anyone with the link means the file has no gate at all: it travels through forwarded emails, old proposals and former contractors' bookmarks, and it keeps working for years after the project ends. Run the sharing report on your drive this week and sort by oldest. The results are usually a short, unpleasant education.

The folder you opened in 2019 is still open, and the only question is whether you find it this month or your biggest client's reviewer finds it next month.

Questions people ask

We do not have a SOC 2 report. What do we tell the enterprise client?

Tell them the truth with a date on it. Something like: we do not hold a SOC 2 report today, we have completed an independent assessment against the same criteria, here are the results, here are the four items still open and the month each closes, and here is our decision on a Type I engagement. Procurement teams read hundreds of workbooks a year and can spot a wish list instantly. A dated plan beats an unsupported yes, and it survives the conversation that happens after an incident.

SOC 2 Type I or Type II: which one do buyers actually want?

Type II, almost always. A Type I says the controls were designed properly on a given date. A Type II says an auditor watched them operate over a period, commonly three to twelve months. Both report against the AICPA Trust Services Criteria. A Type I is a reasonable first step because it forces the design work and gives procurement something concrete, but expect the buyer to ask when the Type II period starts.

Is a shared drive link really a security issue?

It is the most common one we find in agencies and staffing firms. Link sharing set to anyone with the link means the file has no gate at all: it travels through forwarded emails, old proposals and former contractors' bookmarks, and it keeps working for years after the project ends. Run the sharing report on your drive this week and sort by oldest. The results are usually a short, unpleasant education.

Controls this post maps to

CIS 3 Data ProtectionCIS 5 Account ManagementCIS 15 Service Provider Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with your Risk Assessor draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.