Case Study

Enhancing Cybersecurity Compliance: A Case Study of a Portland Accounting Firm

The Firm's Profile

This accounting firm, with a staff of 30 professionals, specializes in tax and consulting services for individuals and businesses, as well as audit and assurance services. Despite its reputation for excellence in accounting, the firm faced significant cybersecurity challenges that threatened its operations and client trust.

Introduction

In an era where data breaches and cyber threats are increasingly common, safeguarding sensitive client information is not just a legal obligation but a business imperative. The IRS and FTC continue to tighten regulations, notably with IRS Publication 4557 "Safeguarding Taxpayer Data" and the incorporation of the FTC Safeguards Rule, which emphasize the necessity for tax preparers and accounting firms to implement robust security measures. This case study explores how a medium-sized accounting firm in Portland, Oregon, confronted its cybersecurity challenges by partnering with Fixed Fee IT to enhance its security posture, comply with federal regulations, and ultimately strengthen its business operations.

Initial Challenges

  • Lack of a Written Security Program: The firm did not have a formalized security plan, leaving it vulnerable to cyber threats and non-compliant with FTC Safeguards Rule requirements.
  • Aging Infrastructure: An outdated server hosting the practice management software and files was due for replacement, posing reliability and security risks.
  • Cybersecurity Incidents:
    • Email Compromise: A senior staff accountant's mailbox was breached, leading to phishing emails being sent to clients.
    • Payroll Fraud: The HR lead was deceived into altering direct deposit information through a spoofed email, resulting in financial loss.
  • Compliance Uncertainty: The firm was unsure about its adherence to IRS E-File security requirements outlined in IRS Publication 1345.
  • Client Distrust: Following phishing incidents, clients were wary of emails from the firm, causing operational delays as staff had to resort to phone communications.
  • Inadequate IT Support: The existing IT provider offered only basic break-fix and light monitoring services without proactive security measures or consulting.
  • Insurance Obstacles: The firm was unable to secure cyber attack insurance due to non-compliance with underwriters' requirements.

The Turning Point. Recognizing the critical need for a comprehensive cybersecurity strategy, the firm sought external expertise. A new partner, recently joined from another firm, recommended Fixed Fee IT for its specialization in accounting and its consistent SOC 2 Type II audits.

Comprehensive Evaluation

Fixed Fee IT initiated an in-depth evaluation process involving multiple meetings and technical assessments to understand the firm's current state, challenges, and future aspirations. The primary goal was to restore confidence among partners, staff, and clients regarding the security of the firm's systems, data, and processes.

Fixed Fee IT team reviewing an accounting firm's security assessment

Development of a Tailored Security Program

1. Creation of Written Policies

Fixed Fee IT collaborated with the firm to develop a customized set of information security policies, ensuring alignment with the firm's practices and regulatory requirements. These policies covered:

  • Configuration Standards
  • Authentication Standards
  • Device and Network Security Standards
  • Physical Security Measures
  • Access Control Protocols
  • Encryption Standards
  • Data Classification
  • Disaster Recovery Plans
  • Incident Response Procedures

2. Risk Assessment and Management

  • Fixed Fee IT helped the firm conduct a comprehensive risk assessment and business impact analysis to identify critical risks.
  • Formed a risk committee comprising partners, staff, and Fixed Fee IT representatives to oversee ongoing risk management efforts.

Implementation of BHelped for Accounting Services

Fixed Fee IT deployed its BHelped for Accounting suite, a set of managed IT services tailored to the unique needs of accounting firms. Key components included:

  • Advanced Email Threat Protection
  • Patch Management Service
  • Managed Endpoint Detection and Response
  • Managed Detection and Response for Microsoft 365
  • Managed Anti-Virus/Anti-Malware
  • Secure Browsing and Firewall Services
  • Wireless and Network Management
  • Desktop, Laptop, and Mobile Device Support
  • Microsoft 365 Management
  • DNS Management
  • Multi-Factor Authentication
  • Disaster Recovery for Microsoft 365
  • Awareness Training Programs

These services were designed to create a secure, reliable, and easy-to-use environment that met FTC Safeguards and IRS Secure Six compliance standards.

Infrastructure Modernization

Fixed Fee IT assisted the firm in transitioning from its outdated server to a Software-as-a-Service (SaaS) version of its practice management software. This migration included:

  • Implementing Single Sign-On (SSO): Streamlined access for employees while enhancing security through centralized authentication.
  • Access Restrictions: Established according to the new security policies to control data access and permissions.
  • Server Retirement: Eliminated reliance on aging hardware, reducing maintenance costs and potential points of failure.

Employee Training and Culture Shift

Understanding that employees are both the first line of defense and potential vulnerabilities, Fixed Fee IT introduced a comprehensive awareness training program:

  • Monthly Training Assignments: Engaging and accessible modules covering various cybersecurity topics.
  • Simulated Phishing Attacks: Regular testing to assess and improve employees' ability to recognize and respond to phishing attempts.
  • Positive Reinforcement: Celebrating individuals and teams who successfully thwarted phishing simulations, fostering a culture of vigilance.

The results were significant, with the phishing compromise rate dropping from 20% to between 0% and 2% within three months.

Ongoing Monitoring and Reporting

Fixed Fee IT implemented the BSecured Vulnerability Reporting service, providing:

  • Monthly Insights: Detailed reports on current vulnerabilities and remediation efforts.
  • Comprehensive Inventory: Up-to-date records of all systems, software, and devices.
  • Risk Committee Collaboration: Facilitated informed decision-making and prioritization of security initiatives.

Outcomes and Benefits

Enhanced Compliance and Security

  • Regulatory Compliance: The firm achieved full compliance with FTC Safeguards Rule and IRS security requirements, significantly reducing the risk of legal repercussions.
  • Insurance Acquisition: Within 90 days, the firm secured cyber attack insurance, with multiple underwriters offering coverage due to the improved security posture.

Improved Client Trust and Engagement

  • Restored Confidence: Clients regained trust in the firm's communications, streamlining operations and reducing the need for time-consuming follow-ups.
  • Value-Added Services: The firm partnered with Fixed Fee IT to offer webinars on cybersecurity best practices for clients, enhancing client relationships and differentiating the firm in the market.

Operational Efficiency and Cost Savings

  • Infrastructure Reliability: Migrating to SaaS solutions and retiring old servers reduced downtime and maintenance costs.
  • Insurance Savings: Lower risk profiles led to reduced insurance premiums.
  • Staff Productivity: Employees could focus on their core responsibilities without the distraction of security incidents and technical issues.

Strategic Partnership and Ongoing Support

  • Regular Consultations: Monthly meetings between the firm's IT leadership team and Fixed Fee IT ensured alignment on business goals, security updates, and future projects.
  • Risk Committee Effectiveness: The collaborative approach to risk management kept security at the forefront of organizational priorities.

Cultural Transformation

  • Security Awareness: Employees became active participants in maintaining cybersecurity, contributing to a proactive defense strategy.
  • Positive Work Environment: Recognition of security-conscious behavior boosted morale and reinforced the importance of each individual's role in protecting the firm and its clients.

Conclusion

The partnership between the Portland accounting firm and Fixed Fee IT exemplifies how organizations can effectively navigate the complex landscape of cybersecurity compliance. By addressing the technical, administrative, and cultural aspects of security, the firm not only met legal obligations but also enhanced its operational resilience and market competitiveness. The proactive measures taken served to protect client data, restore and strengthen client relationships, and position the firm for sustained success in an increasingly digital and regulated environment.

Fixed Fee IT advisor greeting a client

Key Takeaways

  • Compliance is Non-Negotiable: Adhering to IRS and FTC regulations is essential to avoid legal consequences and maintain business operations.
  • Professional Expertise Matters: Engaging specialists with industry-specific knowledge ensures that security solutions are tailored and effective.
  • Employee Engagement is Crucial: Training and involving staff in security efforts transforms them from potential vulnerabilities into assets.
  • Continuous Improvement: Security is not a one-time project but an ongoing process that requires regular assessment and adaptation.
  • Client Trust is Earned and Maintained: Transparent communication and added value services, like educational webinars, strengthen client relationships.

By embracing a comprehensive and proactive approach to cybersecurity, accounting firms can protect their clients and themselves from the ever-evolving landscape of cyber threats while capitalizing on opportunities to enhance their services and reputation.

Ready to Join Our Happy Clients?

Find out what Protected, Productive and Happy really means for your business.

Let's Talk →