Accounting and CPA Firms
Managed IT and Security for Accounting and CPA Firms.
We understand security and regulated businesses. Tax returns, Social Security numbers, banking details and confidential records are what an accounting firm holds. We run the IT and the security program that protects them, and the documentation that proves it.
CPA firms, tax preparers, accountants and bookkeepers, and the professional service firms like them.
What an Accounting Firm Needs From an MSP
Do We Need a WISP?
Yes. Under the updated FTC Safeguards Rule, a firm that handles client financial information needs a Written Information Security Plan (WISP) describing the administrative, technical and physical safeguards in place. For qualified CPA firms, we write the WISP with you as part of the security program, so it describes what we actually run rather than a template.
What Does the FTC Safeguards Rule Ask For?
A written information security plan, a designated Qualified Individual to oversee it, regular assessments and employee training, technical safeguards including encryption and multi-factor authentication, and an incident response plan. Our managed IT and security deliver the technical parts; formal compliance engagements are delivered by our Compliance Division, Capital Cyber Compliance.
How Do You Protect Logins and Microsoft 365?
Multi-factor authentication on every email account and business application, individual accounts for everyone, and no daily work from administrator accounts. We administer Microsoft 365 and its security settings, including email filtering and anti-spoofing, so the tenant is set up securely and stays that way.
How Do You Stop Phishing and Business Email Compromise?
Phishing aimed at financial practices is the attack accounting firms see most, and business email compromise is how a convincing email becomes a wire transfer. We layer filtering, multi-factor authentication, account monitoring, staff training with phishing simulations, and a written procedure to verify any change of payment details.
What About Ransomware and Tax Season?
Endpoint detection and response and application allow-listing on every device, encrypted off-site backups that are tested, and an incident response plan, so ransomware during the busiest weeks of the year is an incident and not the end of the season.
Can You Help With Our Cyber Insurance Application?
Yes. We read your insurer's questions against your environment, verify controls such as multi-factor authentication and training are in place, and prepare the documentation, so each answer on the application is true and backed by evidence.
How We Cover It
6 SERVICESWISP and Safeguards Program
A written plan that matches the controls we run.
MFA and Identity
Multi-factor authentication and individual accounts everywhere.
Microsoft 365 Security
Tenant administration, email filtering and anti-spoofing.
Endpoint Protection
EDR and application allow-listing on every device.
Backups and Incident Response
Tested off-site backups and a written response plan.
Compliance
Formal Compliance Work Is Delivered by Our Compliance Division.
The security program runs here. Formal compliance engagements are delivered by our Compliance Division, Capital Cyber Compliance. Firms that want independent proof of their program can also look at CyberCert SMB1001 certification.
FTC Safeguards Rule Requirements · Start With Capital Cyber Compliance · CyberCert SMB1001 Certification
On the Record
CASE STUDYJohn E. Geantasio CPA LLC
A 30-year accounting practice that engaged us after a third-party penetration test showed gaps it could not see from the inside.
Frequently Asked Questions
5 QUESTIONSDoes the FTC Safeguards Rule apply to CPA firms?
The FTC treats firms that handle consumer financial information, including many tax preparers and accounting firms, as covered. If you prepare returns or handle client financial data, assume it applies and confirm with your own counsel.
Who should be our Qualified Individual?
The rule requires one person designated to oversee the information security program. It can be someone at the firm or a service provider. How that is set up for your firm is part of the compliance scope.
Do you support tax and practice management software?
We support the computers, accounts, network and security your practice management and tax software run on, and work with the vendor's support when the problem is on their side.
Is this priced per user?
Managed IT and security are a fixed monthly cost scoped to your firm. We give you the number on the call.
Have you worked with CPA firms before?
Yes. A New Jersey and New York CPA practice engaged us after a third-party penetration test, as published in the case study below.
Services for This Industry
Microsoft 365 and Email Security
Microsoft 365 set up, secured and run, with email protection against phishing and spoofing.
MFA and Endpoint Protection (EDR)
Multi-factor authentication, endpoint detection and response, and application control on every device.
Security Awareness Training
Training and phishing simulations that turn staff into a line of defense.
Backup and Ransomware Recovery
Encrypted, off-site backups that are tested, and a plan to restore the business after an attack.
Cyber Insurance Readiness
Know what your insurer requires, prove the controls are in place, and have the documents ready.
Talk Through Your Firm's Security.
Pick a time, ideally before tax season. Tell us how many people and what software you run.
Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.
