Client Case Study · Home Office & Enterprise

WestPac Wealth Partners: two sets of requirements, one answer.

A national wealth-management firm and agency of The Guardian Life Insurance Company of America must satisfy cybersecurity regulators and its home office’s cybersecurity policy document. FCI reviews the policy, configures the systems to meet it, and keeps the firm compliant with both — so the firm has nothing to manage but its business.

Case study · Published with the client’s cooperation · September 2026

The short version

The home-office model, working as designed.

Firms in an enterprise’s agency system answer to two authorities at once: the regulators who examine them, and the home office whose cybersecurity policy document sets specific, auditable requirements. WestPac’s answer to both is the same: FCI reads the requirements, adopts and configures the systems to match, enforces them continuously, and produces the evidence — for the examiner and for Guardian.

Client

A national agency firm

WestPac Wealth Partners — founded in 2007, grown into one of the fastest-rising firms in Guardian’s agency system, with hundreds of professionals across the country.

Challenge

Regulation + the policy document

Cybersecurity regulation on one side; Guardian’s cybersecurity policy requirements on the other. Both specific. Both checked.

Outcome

Nothing to manage but the business

FCI configures to the requirements and evidences the result. The firm trusts one partner for both sets of obligations.

The story

From policy document to enforced configuration.

A home office’s cybersecurity policy is not a suggestion — it is a detailed document of required controls, settings, and attestations. Meeting it is a configuration job, not a paperwork job.

1. Two authorities
The regulator examines you. The home office requires of you.

As an agency of Guardian Life, WestPac operates under cybersecurity regulation like every financial services firm — and, on top of it, under Guardian’s own cybersecurity policy document: the enterprise’s specific requirements for how an agency’s devices, users, and data must be protected. The two overlap, but neither substitutes for the other.

The pattern: in an agency system, "compliant" means compliant twice — with the regulation, and with the home office’s policy. Firms that only track one get surprised by the other.
2. The expertise
FCI reads the policy document like an engineer, not a lawyer.

FCI’s work with Guardian’s agency system means the policy document is familiar terrain: what each requirement means in practice, which system setting satisfies it, and what evidence proves it. FCI reviews the requirements, adopts the mandated controls, and configures WestPac’s environment to match — to the letter.

The pattern: a policy requirement only becomes compliance when a system is configured to enforce it. Translation from document to configuration is the actual work — and the part most firms have no one to do.
3. The handoff
The firm’s job became trusting the result.

With FCI configuring and enforcing the controls, WestPac’s obligation stopped being interpretation, implementation, and upkeep — and became oversight of a partner who delivers both compliance outcomes and the documentation behind them. When the home office asks, the answer is ready. When the regulator asks, the same.

The pattern: "Data Secured. Compliance Proven." works in both directions — up to the enterprise, and out to the regulator.
4. The model
This is the Home Office & Enterprise model.

What works for WestPac generalizes to any firm operating under an enterprise’s security requirements — agencies, branch offices, field networks. The home office defines the policy; FCI turns it into configured, enforced, evidenced reality across every firm and every device, without the enterprise or the firm building a security operation.

The pattern: the enterprise gets provable field compliance; the firm gets its time back; every device answers to the same standard.

We strongly recommend FCI to any firm with a desire to get cybersecurity protection and compliance.


Nash Subotic
Nash Subotic Founder & CEO, WestPac Wealth Partners
Agency of The Guardian Life Insurance Company of America

What this means for your firm

Four lessons for firms under a home office.

The same four decisions face every agency, branch network, or field firm operating under an enterprise’s cybersecurity requirements.

The policy document is the spec

Home-office requirements are specific and auditable. Compliance is a configuration state, not a signed attestation.

One partner for both authorities

Regulation and home-office policy overlap heavily. One configured, enforced environment satisfies both — two separate efforts satisfy neither well.

Trust is built on evidence

"Trust FCI" works because the proof is produced continuously — the firm, the home office, and the examiner all see the same record.

The model scales across the system

Every firm in an agency system faces the same document. A partner who has already translated it once delivers it everywhere.

Operating under a home office’s security requirements?

Start with the 16-question assessment, or ask FCI how the Home Office & Enterprise model would meet your policy document — reviewed, configured, enforced, and evidenced.