Randy and Brian explain why a written information security plan is no longer a compliance document that can sit on a shelf. Accounting firms hold concentrated stores of tax, financial, identity, and sometimes health information, making them attractive targets for phishing, credential theft, ransomware, fraudulent wire instructions, and AI-enhanced attacks.
The Accounting Tech Lab is an ongoing series that explores the intersection of public accounting and technology.
View the video below:
Key Takeaways
- A WISP should be an operating system for security—not shelfware. It needs ownership, periodic review, documented changes, and executive oversight.
- Accounting firms are unusually attractive targets because they aggregate tax, financial, identity, payroll, and other confidential information.
- Credential theft and phishing remain central risks, while AI is making fraudulent messages and attacks more convincing.
- Vendor management belongs inside the security program. Cloud applications, hosting companies, MSPs, AI services, and other third parties expand the firm’s attack surface.
- Incident response must be planned before the incident. The episode stresses knowing your regulatory notification obligations, internal responsibilities, legal resources, and PR response.
- Security has a recurring calendar. Log reviews, backup restores, phishing tests, vulnerability scanning, access reviews, training, patching, and WISP updates need assigned frequencies and owners.
= END =
Sign in to get access to this free resource, and all of our whitepapers and reports.
Download this content today!
Register Now Already registered? Click here to Log In