6 Essential Practices to Protect Your Firm from Cyberattacks

By John Graziano, CPA, CFP, PFS, FFP Wealth Management  – January 3, 2023
6 Essential Practices to Protect Your Firm from Cyberattacks

Is your accounting firm taking steps to protect against a cyberattack? If not, you may be putting your firm’s future at risk. On average, cyberattacks cost companies $4.24 million in 2021, up from $3.86 million in 2020. On top of that, an estimated 60 percent of small businesses go out of business within six months of a cyberattack.

The following best practices can help protect your firm from cyberattacks.

1. Know Your Threats

To protect your firm from an attack, you need to know your enemy. While there are many different types of cyberattacks, accounting firms are more likely to be the targets of:

  • Malware and ransomware: Ransom­ware is a type of malware that encrypts files and blocks owner access. To regain access, cybercriminals demand payment, usually via cryptocurrency. Malware can infect an entire system quickly and easily, leaving a firm completely immobilized.
  • Phishing texts and emails: Ransomware and viruses are often delivered to accounting firms through phishing schemes deployed via text or email. Phishing schemes hide malicious files inside seemingly innocent ones (like office documents). Once the attached file is opened, the entire system is infected.

2. Train Your Staff

Reports show that more than 90 percent of cyberattacks are carried out by either stealing credentials or using phishing scams to trick employees into providing access. Proper staff training can help reduce the risk of someone gaining unauthorized access to your system. All staff should be trained how to:

  • Spot phishing attacks. For example, emails asking for their login information or other sensitive data should be viewed as suspicious. Verifying these types of requests in person or over the phone can help prevent a data breach.
  • Protect their credentials. For example, login information should never be written on a piece of paper or typed in a text file.

3. Know the Regulations

Every accounting firm should know and understand the data regulations in their respective states. Some states have more stringent rules than others.

All firms, regardless of location, must protect any client data they collect under the Gramm-Leach-Bliley Act. As part of this Act, the FTC created the Safeguards Rule, which requires businesses to:

  • Designate employees to coordinate a security program.
  • Identify and assess risks, and evaluate the effectiveness of current measures to protect against these risks.
  • Create and implement a safeguards program.
  • Choose service providers that maintain appropriate safeguards.
  • Evaluate and change the program as needed.

In addition, all states have data breach notification laws. Research yours to ensure that you’re prepared to comply and properly notify clients in case of a breach.

4. Design an Approval and Validation System

An accounting firm’s system should create strict control over data access. The right approval and validation system can help prevent fraud and identity theft. For example, staff may verify or validate client requests to ensure that the client is indeed the person making the request.

5. Establish Security Requirements

Accounting firms should have clear security protocols, and all staff should be aware of these requirements. These security requirements may include drive encryption, antivirus and antimalware software, firewalls, two-factor authentication and virtual private networks (VPNs) for remote working.

Additionally, firms should create strict access control systems to ensure that only the right people have access to data.

6. Choose the Right Accounting System

Finally, firms should choose the right accounting system. Ideally, the system should include encryption, data redundancy, automated backups and more to protect data.

Cybersecurity should be a top priority for accounting firms. Failure to comply with regulations or properly protect against data breaches can result not only in fines but also in a lot of stress, headaches and a damaged reputation that can be difficult to recover from.

John E. Graziano

John E. Graziano

John Graziano, CPA, CFP, PFS, is president of FFP Wealth Management, a financial planning and management firm. He is a member of the NJCPA.

More content by John E. Graziano:

This article appeared in the winter 2022/23 issue of New Jersey CPA magazine. Read the full issue.


CPACharge was developed specifically for CPAs, enrolled agents and accountants, providing a simple, affordable online payment solution that allows you to securely accept credit, debit, and eCheck/ACH payments from anywhere. 
On-Site Training

NJCPA on-site training programs offer the same outstanding content and expert instruction as our seminars but are led at your location.

Accounting Today
Save 20 percent on an Accounting Today subscription and stay up to date on the latest issues affecting the profession.
Join the Accounting Educators Community

Connect and share with other accounting educators about curriculum, trends and the profession. Learn about NJCPA initiatives that are valuable for your students including information on obtaining the CPA designation, student membership, scholarships, volunteer opportunities and events.

Earn an AICPA Robotic Process Automation Certificate
Recognize what RPA is and its business value, with specific focus on accounting and finance functions. Understand how RPA provides a significant competitive advantage.
Guaranteed Rate/Marc Demetriou
Marc Demetriou of Guaranteed Rate is offering NJCPA members a “no lender fee mortgage” ($1,440 lender fee credit), competitive low rates and a dedicated team to deliver world class service.
Join the Women's Leadership Forum

Join our online forum that enables female CPAs at all career levels and industries to make meaningful connections with each other and discuss career goals.

Earn an AICPA Single Audit Certificate
Learn how to plan, perform and evaluate single audits in accordance with the latest requirements of the new Uniform Guidance.
Wolters Kluwer
NJCPA members save 25 percent on CCH CPELink subscriptions, live webinars and on-demand self-study (mobile friendly) CPE courses.

SMI has negotiated special discounts for the NJCPA members with all the major technology carriers and providers.

Join the Business & Industry Professionals Interest Group

Stay connected to your peers and share knowledge on corporate finance topics.

Wolters Kluwer CCH
Save on COVID Tax Resources
NJCPA members save 25 percent on Wolters Kluwer's new book, COVID and Taxpayer Certainty Acts of 2020: Law, Explanation & Analysis.
Shop the NJCPA store
Are you NJCPA proud? Purchase NJCPA merch to show your pride and help support our scholarship program.
Real Estate Classified Ads
View classified ad postings for office space for sale or rent.
Mergers & Acquisitions Classified Ads
View classified ad postings from CPA firms looking to be acquired and those looking to acquire or merge with other firms.
Professional Services Classified Ads
View classified ad postings from companies providing services to CPAs.
Join the Cannabis Interest Group
New Jerseyans have voted to legalize cannabis. Join the NJCPA's Cannabis Interest Group to gain information, insights and best practices for serving clients in this promising new industry.
Zoom Backgrounds
Download our virtual backgrounds for Zoom meetings.
Earn an AICPA Certificate
When you’re ready to show your competencies, expand your career opportunities or enter new areas of practice, start by earning an AICPA certificate. Choose a certificate that matches your next career goal.
Earn the AICPA Blockchain Fundamentals Certificate
Build a foundation toward becoming a strategic business partner within your organization and with your clients. Learn how to anticipate potential benefits and risks of the technology, structure and functionality, and to translate them into relevant business application and value.