The Big Cybersecurity Threats Facing Accountants and How to Protect Yourself

by By Anthony Mongeluzo, PCS - October 3, 2022
cybersecurity_login_phone_laptop_iStock-876819100 (002)

Accountants often ask me what the most current cybersecurity threats are that might disrupt their practice. While these are generally of an IT nature, which this article will outline, my initial response startles most accountants: Focus on your staff as your first line of defense.

No Staff Surprises

Surprisingly, accounting practices, regardless of size, seldom have a meeting to discuss in-house rules for protecting their data. The threat comes from social engineering, a fancy term IT people use, which is nothing more than tricking recipients through impersonation. Hackers pretend to be someone else to fool targets into acting in the attacker's favor, usually by sending money. The best defense is education and training. Have your in-house IT security expert (or outside consultant) go over a detailed approach about what rules to follow to ensure that staff doesn't fall prey to creative scammers. Ensure that new employees also receive training when they join the firm.

Other security threats include the following:

  • Ransomware: I describe it as expensive, unpredictable and terrifying. Ransomware simply means that an outside actor has taken control of your IT system and will not return control to you until you pay a ransom. Think: IT kidnapping. It can occur simply by opening an attachment that appears to be an invoice, and in doing so, you've launched the malware that allows the attacker to take over your computer. A 2017 IBM Research report said that this approach, called phishing, was responsible for 59 percent of ransomware attacks. Just because it looks legitimate doesn't mean that it is. You can prevent ransomware by using tested monitoring applications, backing up frequently, installing the latest anti-malware protection and, yes, training your staff.
  • Deficient Post-Attack Procedures: If you’re a victim of a cybersecurity attack, don't relax thinking you're safe. You're not. You must patch any holes in your system immediately after the attack. A survey of 1,263 IT professionals by Cybereason found that 80 percent of victims who submitted a ransom payment said they experienced another attack soon after. The survey also found that "60 percent of cyber attacks could have been prevented if an available patch had been applied, and 39 percent of organizations say they were aware they were vulnerable before the cyber attack occurred."

Two Defense Options 

  • 2 Factor(2F) or Multifactor Authentication (MFA): These are not threats but rather the gold standard for protecting your data. There is a difference, however, between the two. 2F authentication requires precisely two steps. The most common version is when the site you wish to enter will send a code to your cellphone. Upon receiving and entering the code, you gain access to the site. Accountants should consider this the minimum-security barrier. MFA requires two or more methods of verifying your identity. Every 2F is an MFA, but the reverse is not necessarily true. Think of MFA as an extra door lock that creates an additional barrier more likely to dissuade an intruder. You might have the login and password as your first line of defense, but you might also add a retina scan or a fingerprint with an MFA. Employing MFA adds a substantial extra layer of protection, and accountants should note that the cost is modest. Utilizing an MFA security system might add an extra moment to implement or require you to remember which type of MFA a site demands. Still, this slightly added irritant is worth the considerable increase in security.
  • Next-Generation Antivirus (NGAV): NGAV is the latest in antivirus protection using artificial intelligence. If you created a digital recipe that combines artificial intelligence, behavioral detecting and machine learning algorithms and exploits mitigation techniques, you would have NGAV. To explain it more simply, "NGAV is the next step in endpoint protection, using a signature-less approach to deliver more complete and effective security possible with legacy AV [antivirus]," according to Crowd Strike. This is an accurate description because NGAV is cloud-based, immediately deployable and removes updating barriers across the network, such as updating software or maintaining infrastructure.

It might be a cliché but invest in prevention now or pay much more in the future after a cyber attack.

CPACharge was developed specifically for CPAs, enrolled agents and accountants, providing a simple, affordable online payment solution that allows you to securely accept credit, debit, and eCheck/ACH payments from anywhere. 
On-Site Training

NJCPA on-site training programs offer the same outstanding content and expert instruction as our seminars but are led at your location.

Accounting Today
Save 20 percent on an Accounting Today subscription and stay up to date on the latest issues affecting the profession.
Join the Accounting Educators Community

Connect and share with other accounting educators about curriculum, trends and the profession. Learn about NJCPA initiatives that are valuable for your students including information on obtaining the CPA designation, student membership, scholarships, volunteer opportunities and events.

Earn an AICPA Robotic Process Automation Certificate
Recognize what RPA is and its business value, with specific focus on accounting and finance functions. Understand how RPA provides a significant competitive advantage.
Guaranteed Rate/Marc Demetriou
Marc Demetriou of Guaranteed Rate is offering NJCPA members a “no lender fee mortgage” ($1,440 lender fee credit), competitive low rates and a dedicated team to deliver world class service.
Join the Women's Leadership Forum

Join our online forum that enables female CPAs at all career levels and industries to make meaningful connections with each other and discuss career goals.

Earn an AICPA Single Audit Certificate
Learn how to plan, perform and evaluate single audits in accordance with the latest requirements of the new Uniform Guidance.
Wolters Kluwer
NJCPA members save 25 percent on CCH CPELink subscriptions, live webinars and on-demand self-study (mobile friendly) CPE courses.

SMI has negotiated special discounts for the NJCPA members with all the major technology carriers and providers.

Join the Business & Industry Professionals Interest Group

Stay connected to your peers and share knowledge on corporate finance topics.

Wolters Kluwer CCH
Save on COVID Tax Resources
NJCPA members save 25 percent on Wolters Kluwer's new book, COVID and Taxpayer Certainty Acts of 2020: Law, Explanation & Analysis.
Shop the NJCPA store
Are you NJCPA proud? Purchase NJCPA merch to show your pride and help support our scholarship program.
Real Estate Classified Ads
View classified ad postings for office space for sale or rent.
Mergers & Acquisitions Classified Ads
View classified ad postings from CPA firms looking to be acquired and those looking to acquire or merge with other firms.
Professional Services Classified Ads
View classified ad postings from companies providing services to CPAs.
Join the Cannabis Interest Group
New Jerseyans have voted to legalize cannabis. Join the NJCPA's Cannabis Interest Group to gain information, insights and best practices for serving clients in this promising new industry.
Zoom Backgrounds
Download our virtual backgrounds for Zoom meetings.
Earn an AICPA Certificate
When you’re ready to show your competencies, expand your career opportunities or enter new areas of practice, start by earning an AICPA certificate. Choose a certificate that matches your next career goal.
Earn the AICPA Blockchain Fundamentals Certificate
Build a foundation toward becoming a strategic business partner within your organization and with your clients. Learn how to anticipate potential benefits and risks of the technology, structure and functionality, and to translate them into relevant business application and value.