Information security

up arrow
A proactive roadmap to manage risk

RSM’s information security program establishes a secure foundation for sustainable digital growth through strategic, technical and organizational measures that protect the firm’s digital assets.

Our information security mission calls for protecting the confidentiality, integrity and availability of RSM and client data. To support this mission, our leadership team drives continuous improvement through appropriate levels of oversight, active engagement and a risk-based approach to safeguarding protected information. This approach is reinforced through mandatory information security and privacy awareness training upon an employee’s hire and annually thereafter, including ongoing phishing detection training.

We have a dedicated information security team led by our chief information security officer. This team includes the office of the CISO, security operations, cybersecurity incident response, security architecture and engineering, and information security governance. Our information security standards align with the internationally recognized ISO/IEC 27001: 2022 framework. They are further shaped by industry best practices, regulatory requirements and the specific needs of our operating environment.

Information security risk management

Our approach to information security has evolved beyond traditional, reactive technical risk management to encompass a comprehensive strategic framework. We follow a proactive roadmap that anticipates and manages emerging cybersecurity risks, aligns with global trends and adapts to the dynamic threat landscape. RSM embeds security considerations into the sourcing of digital products and services. Any vendor solution that stores or accesses confidential information undergoes a formal security review, and our vendor agreements include appropriate requirements for confidentiality, security, privacy, data integrity and breach response. In addition, contractors and other nonemployees are required to comply with RSM’s acceptable use and information security policies.

Information security incident management

We continuously monitor for threats, vulnerabilities and security events through industry-leading prevention and detection capabilities spanning endpoints, systems and networks. Our incident response plan is supported by a dedicated and experienced incident response task force and is subject to regular testing to ensure timely and effective response.

Collection, use and retention of personal information

We collect, use and retain personal information subject to our publicly available privacy policy. As described in that policy, we process this data for several purposes, including providing services to our clients. This data may be retained for as long as necessary for the purposes described in our privacy policy, to achieve the goals for which the information was collected or as permitted under applicable law. Our privacy program is overseen by a dedicated enterprise privacy office under the leadership of our enterprise privacy leader.

Information security constantly evolves

As the threat landscape continues to evolve, RSM strengthens its capabilities across people, processes and technology to protect the firm and support our clients. Building on more than a century of client service, RSM pairs trusted service delivery with modern, resilient security practices that support clients’ missions today and into the future.

Central to this effort is our people. RSM’s expanding information security team operates across a global footprint, delivering continuous 24/7 monitoring and incident response capabilities. The team has doubled in size over the past decade, improving our ability to respond swiftly, collaborate effectively and apply deep subject matter expertise to emerging challenges.

A recent milestone in our process-driven approach to information security is RSM’s achievement of Cybersecurity Maturity Model Certification Level 2 assessment as an External Service Provider. This designation formally distinguishes RSM as both a managed services provider and a managed security services provider for government contractors handling critical national security information. This accomplishment, in addition to our existing authorization as the largest certified third-party assessment organization within the CyberAB ecosystem, underscores the firm’s unwavering commitment to helping clients meet the U.S. Department of Defense’s stringent cybersecurity requirements and reflects RSM’s longstanding commitment to helping clients navigate change with confidence.

RSM has long incorporated machine learning and AI technology into its capabilities—with active use predating 2020—to strengthen detection and prevention, streamline analysis, and drive continuous improvement. This mature and deliberate application of advanced analytics enables the firm to adapt rapidly to evolving threats and deliver resilient, dependable security outcomes.

Close-up of colorful interconnected spheres representing a molecular or neural network.