Managed IT and Managed Security · Leesburg, VA

Accounting and CPA Firms

Managed IT and Security for Accounting and CPA Firms.

We understand security and regulated businesses. Tax returns, Social Security numbers, banking details and confidential records are what an accounting firm holds. We run the IT and the security program that protects them, and the documentation that proves it.

CPA firms, tax preparers, accountants and bookkeepers, and the professional service firms like them.

What the FTC Safeguards Rule asks an accounting firm forOn the left, a locked folder of what a firm holds: tax returns, Social Security numbers and banking details. On the right, the six things the updated rule asks for: a written information security plan, a designated Qualified Individual, regular assessments, staff training, encryption and multi-factor authentication, and an incident response plan.CLIENT DATATax returnsSSNsBanking detailsSAFEGUARDS RULE ASKS FORWritten security planA Qualified IndividualRegular assessmentsStaff trainingEncryption and MFAIncident response plan

What an Accounting Firm Needs From an MSP

Do We Need a WISP?

Yes. Under the updated FTC Safeguards Rule, a firm that handles client financial information needs a Written Information Security Plan (WISP) describing the administrative, technical and physical safeguards in place. For qualified CPA firms, we write the WISP with you as part of the security program, so it describes what we actually run rather than a template.

What Does the FTC Safeguards Rule Ask For?

A written information security plan, a designated Qualified Individual to oversee it, regular assessments and employee training, technical safeguards including encryption and multi-factor authentication, and an incident response plan. Our managed IT and security deliver the technical parts; formal compliance engagements are delivered by our Compliance Division, Capital Cyber Compliance.

The FTC Safeguards Rule, Explained

How Do You Protect Logins and Microsoft 365?

Multi-factor authentication on every email account and business application, individual accounts for everyone, and no daily work from administrator accounts. We administer Microsoft 365 and its security settings, including email filtering and anti-spoofing, so the tenant is set up securely and stays that way.

Microsoft 365 and Email Security

How Do You Stop Phishing and Business Email Compromise?

Phishing aimed at financial practices is the attack accounting firms see most, and business email compromise is how a convincing email becomes a wire transfer. We layer filtering, multi-factor authentication, account monitoring, staff training with phishing simulations, and a written procedure to verify any change of payment details.

Security Awareness Training

What About Ransomware and Tax Season?

Endpoint detection and response and application allow-listing on every device, encrypted off-site backups that are tested, and an incident response plan, so ransomware during the busiest weeks of the year is an incident and not the end of the season.

Backup and Ransomware Recovery

Can You Help With Our Cyber Insurance Application?

Yes. We read your insurer's questions against your environment, verify controls such as multi-factor authentication and training are in place, and prepare the documentation, so each answer on the application is true and backed by evidence.

Cyber Insurance Readiness

How We Cover It

6 SERVICES

WISP and Safeguards Program

A written plan that matches the controls we run.

MFA and Identity

Multi-factor authentication and individual accounts everywhere.

Microsoft 365 Security

Tenant administration, email filtering and anti-spoofing.

Endpoint Protection

EDR and application allow-listing on every device.

Backups and Incident Response

Tested off-site backups and a written response plan.

Testing

Penetration testing and vulnerability assessment, with a retest.

Compliance

Formal Compliance Work Is Delivered by Our Compliance Division.

The security program runs here. Formal compliance engagements are delivered by our Compliance Division, Capital Cyber Compliance. Firms that want independent proof of their program can also look at CyberCert SMB1001 certification.

FTC Safeguards Rule Requirements · Start With Capital Cyber Compliance · CyberCert SMB1001 Certification

On the Record

CASE STUDY

John E. Geantasio CPA LLC

A 30-year accounting practice that engaged us after a third-party penetration test showed gaps it could not see from the inside.

As published on capital-cyber.com, August 31, 2021

Frequently Asked Questions

5 QUESTIONS
Does the FTC Safeguards Rule apply to CPA firms?

The FTC treats firms that handle consumer financial information, including many tax preparers and accounting firms, as covered. If you prepare returns or handle client financial data, assume it applies and confirm with your own counsel.

Who should be our Qualified Individual?

The rule requires one person designated to oversee the information security program. It can be someone at the firm or a service provider. How that is set up for your firm is part of the compliance scope.

Do you support tax and practice management software?

We support the computers, accounts, network and security your practice management and tax software run on, and work with the vendor's support when the problem is on their side.

Is this priced per user?

Managed IT and security are a fixed monthly cost scoped to your firm. We give you the number on the call.

Have you worked with CPA firms before?

Yes. A New Jersey and New York CPA practice engaged us after a third-party penetration test, as published in the case study below.

Services for This Industry

Microsoft 365 and Email Security

Microsoft 365 set up, secured and run, with email protection against phishing and spoofing.

MFA and Endpoint Protection (EDR)

Multi-factor authentication, endpoint detection and response, and application control on every device.

Security Awareness Training

Training and phishing simulations that turn staff into a line of defense.

Backup and Ransomware Recovery

Encrypted, off-site backups that are tested, and a plan to restore the business after an attack.

Cyber Insurance Readiness

Know what your insurer requires, prove the controls are in place, and have the documents ready.

Talk Through Your Firm's Security.

Pick a time, ideally before tax season. Tell us how many people and what software you run.

Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

Book a 30-Minute Call