4 Ways to Protect Your Clients' Data

By Hannah Bruno, CPACharge, CPA, Accountants Advisory Group, LLC – November 6, 2024
4 Ways to Protect Your Clients

                                                                                                                                                  SPONSORED CONTENT

Today’s accounting professionals know that data security is a more urgent concern than ever. CPAs are in possession of their clients’ most sensitive personal and financial details, so it’s no surprise they’ve become prime hacking targets.

The IRS has advised CPAs to review all aspects of their data security strategies, including administrative practices, building protection, computer security, staff and information systems. But does this mean you have to immediately become an internet security expert if you want to avoid becoming the next headline or cautionary tale? Abso­lutely not. Protecting sensitive data can be simple. The following steps will help ensure better data protection in your practice.

1. Identify Your Cyber Assets

The path to a more secure firm starts with creating a simple document detailing your practice’s IT assets. List all the technology you use at your firm to the best of your knowledge, including:


  • Networking infrastructure: Do you have wired (LAN) and Wi-Fi networks? What is connected to each? Is there a guest network? Who has access? Take an inventory of all of the PCs, laptops, mobile devices, file servers and network-attached storage (NAS) that are present in the practice. 
  • Systems and other hardware: Take an inventory of all of the PCs, laptops, mobile devices, file servers and network-attached storage (NAS) that are present in the practice.

  • Applications and data: Common software for accounting professionals includes practice management suites, billing and payments solutions, and document management tools.

  • Users: Make a comprehensive list of any and all users with accounts on your systems, including the privileges and capabilities these users have.

2. Strengthen Your Passwords

Everything in your office, from your network itself to your personal computer, is only as secure as the password you’ve created for it. What steps can you take to strengthen passwords?

  • Use a password manager. A password manager provides a secure way to store and find all of your passwords.
  • Create a strong passphrase. Ensure that your passphrase: 

          *Contains both uppercase and lowercase letters

          *Has digits and punctuation symbols as well as letters

          *Contains at least 12 letters, numbers or symbols 

          *Is not a word in any language, slang, dialect or jargon

          *Is not based on any personal information

 
  • Enable multi-factor authentication. This requires both a password and a code to access an account.

3. Fortify Your Physical and Digital Office

Securing both the physical and digital office environments is crucial, particularly with Wi-Fi networks serving as the back­bone of connectivity. While convenient, they pose significant security risks if not properly configured. Start by securing administrative access to your wireless router with a strong, unique password through the router’s configuration website, ensuring default passwords are changed.

4. Ensure Data Security and PCI Compliance

Every business that accepts credit or debit card payments must comply with the Payment Card Industry Data Security Standard (PCI DSS). To become compliant, businesses must complete a self-assessment questionnaire (SAQ) on an annual basis. The SAQs are based on the six standard groups outlined by the PCI DSS (and their sub-requirements), which are:

 

  • Build and maintain a secure network. Ensure that your systems have firewalls installed and are regularly updated.
  • Protect cardholder data no matter what. The best online payment solutions store and protect sensitive cardholder data for you.
  • Maintain a vulnerability manage­ment program. This simply means using antivirus and anti-malware software and keeping it up to date. 
  • Implement strong access-control measures. This involves limiting access to sensitive cardholder data to only those with a business need to access it. 
  • Regularly monitor and test networks. This involves documenting who can access what and ensuring these practices are working correctly.
  • Maintain an information security policy. Draft a security policy that out­lines how your business uses technology and handles sensitive data.

For more tips on how to increase your firm’s security, access the comprehensive guide, Cybersecurity: Best Practices for Accounting Firms, at cpacharge.com/resources/e-books-and-guides/cybersecurity-guide-for-accounting-firms/.

CPACharge, an NJCPA Member Benefit Provider, provides online payment solutions for CPA firms to enable them to streamline their billing processes and increase cash flow, safely and securely. Learn more at cpacharge.com/njcpa.


Hannah Bruno

Hannah Bruno is a senior content writer at CPACharge. She can be reached at cpachargesales@cpacharge.com.

This article appeared in the Fall 2024 issue of New Jersey CPA magazine. Read the full issue.

 

 

Related events

January 16, 2025Paramus
January 17, 2025Red Bank & Live Webcast
January 17, 2025Webcast Replay
January 22, 2025Live Webcast
January 23, 2025Webcast Replay
January 23, 2025Live Webcast
January 23, 2025Live Webcast
January 31, 2025Webcast Replay
February 5, 2025Linwood
Atlantic/Cape May Chapter
Federal & State Tax Update
February 6, 2025Paramus
Bergen Chapter
Special Topics
February 6, 2025Haddonfield
Southwest Jersey Chapter
Technology Update
February 12, 2025Live Webcast
February 19, 2025Live Webcast
February 24, 2025Webcast Replay
February 25, 2025Live Webcast
March 4, 2025Webcast Replay
March 19, 2025Live Webcast
March 20, 2025Live Webcast
March 27, 2025Live Webcast
April 16, 2025Live Webcast
April 21, 2025Live Webcast
April 22, 2025Clark
April 25, 2025Roseland
April 25, 2025Live Webcast
April 29, 2025Webcast Replay
May 1, 2025Webcast Replay
May 6, 2025Live Webcast
May 7, 2025Northfield
Atlantic/Cape May Chapter
Estate Planning
May 8, 2025Haddonfield
Southwest Jersey Chapter
Nonprofit Update
May 9, 2025Live Webcast
May 16, 2025Webcast Replay
May 20, 2025E. Brunswick
Middlesex/Somerset Chapter
New Jersey Law and Ethics
May 21, 2025Live Webcast
June 3 - 6, 2025Atlantic City
June 25, 2025Live Webcast
July 23, 2025Live Webcast
August 5, 2025Live Webcast
August 13, 2025Live Webcast
August 18 - 20, 2025Atlantic City
August 26, 2025Live Webcast
September 17, 2025Live Webcast
October 22, 2025Live Webcast
October 29, 2025Live Webcast
November 4, 2025Live Webcast
November 13, 2025Live Webcast
November 19, 2025Live Webcast
November 19, 2025Live Webcast
December 3, 2025Live Webcast
December 11, 2025Live Webcast
December 17, 2025Live Webcast
January 6, 2026Live Webcast
February 4, 2026Live Webcast
March 8, 2026Live Webcast