Having IT Support Is Not the Same as Proving Client Data Is Protected

Robot finger touching digital lock

A 90-person CPA and CAS firm can look well covered from the outside.

It has an IT provider. It has security tools. It has Microsoft 365 controls. It has backups. It may even have someone internal who knows the systems, the vendors, the tax software, the portals, the remote access setup, and the seasonal staff workflow.

Then a client asks a simple question:

“Can you show how our confidential data is protected?”

Or cyber insurance asks for evidence. Or a partner asks why IT always feels reactive. Or a compliance project starts using words like NIST, written information security plan, access control, monitoring, and risk assessment.

That is when the uncomfortable part appears.

The firm may have activity everywhere — tickets, alerts, tools, vendors, dashboards, policies, and people — but no clean executive view of whether client-data protection is actually working.

This is not always negligence. It is often something more common: an evidence gap.

security tools, vendors, IT staff, and tickets surrounding a central gap labeled executive evidence.

The evidence gap often appears between IT activity and executive confidence

The issue is no longer just whether your firm has IT support. The issue is whether leadership can validate that critical controls are working, produce evidence when asked, review exceptions on a cadence, and make clear decisions when something is missing.

That is a different standard than “we have an IT company.”

The gap hides inside normal operations

Most firms do not discover this gap during a calm week.

They discover it when timing is bad.

A client sends a security questionnaire before approving a larger advisory engagement. A cyber insurance renewal asks about MFA, endpoint protection, backups, privileged access, and incident response. A WISP project requires someone to explain which safeguards are actually operating. A partner asks whether former employees still have access to client files. A CAS team starts using a new document workflow, and no one is entirely sure how permissions, retention, and sharing are being governed.

In a typical firm, the answers live in different places.

Some information is in Microsoft 365. Some is in the backup portal. Some is in the endpoint security console. Some is in the ticketing system. Some is known by the IT person. Some is known by the MSP. Some is assumed because “we set that up last year.”

That may be enough for day-to-day troubleshooting.

It is not enough for leadership governance.

NIST’s Cybersecurity Framework 2.0 gives governance a central role in cybersecurity risk management, alongside identify, protect, detect, respond, and recover. The FTC Safeguards Rule also points firms toward a written information security program built around administrative, technical, and physical safeguards. Tax professionals also have IRS guidance focused on safeguarding taxpayer data. (IRS Publication 4557)

The pattern is clear: regulators, clients, insurers, and larger buyers are not merely asking whether a firm bought security tools. They increasingly expect a firm to know how its safeguards are managed.

NIST Cybersecurity Framework 2.0

Protection is not proof

  • A security tool being installed is not the same as a control working.
  • A backup job running is not the same as recoverability being understood.
  • A policy existing is not the same as exceptions being reviewed.
  • An IT provider closing tickets is not the same as leadership knowing what risk remains.

The difference matters because CPA and CAS firms handle data that clients consider highly sensitive: tax records, payroll information, financial statements, business plans, transaction documents, ownership information, and advisory workpapers. If that data is exposed, the damage is not limited to IT cleanup. It can affect client trust, partner confidence, referral relationships, and the firm’s reputation.

The dangerous assumption is this:

“If something important were wrong, someone would tell us.”

That sounds reasonable. It is also how risk drifts.

Tools may alert. IT may respond. Vendors may send reports. But unless there is a defined cadence to review control posture, evidence, exceptions, and ownership, leadership may never see the difference between “handled,” “partially handled,” and “not actually verified.”

Table comparing installed tools, working controls, evidence records, and leadership governance

Protection becomes defensible only when it is validated, evidenced, reviewed, and owned

 

A practical example: client files and broad access

Consider a familiar situation.

A firm uses Microsoft 365, SharePoint, Teams, a client portal, tax applications, and several line-of-business tools. During busy season, access gets expanded so staff can move faster. A seasonal preparer needs a folder. A partner wants easier access from a personal device. A client sends documents through email instead of the portal. A CAS team creates a shortcut workflow because the standard process is too slow.

None of these decisions may look reckless in isolation.

But after six months, leadership may not be able to answer basic questions clearly:

  • Who has access to sensitive client folders?
  • Which exceptions were approved?
  • Are former employees fully removed?
  • Are privileged accounts reviewed?
  • Is MFA enforced across the right users and applications?
  • Are backups monitored, and is there recent evidence that recovery would work?

If the answer is, “We would need IT to check,” the firm may not have a technology problem yet. But it does have a governance problem.

The better question

Instead of asking, “Do we have cybersecurity?” ask:

“Could we produce credible evidence within 48 hours that our most important client-data controls are working?”

That question changes the conversation.

It separates activity from accountability. It forces clarity on where evidence lives. It reveals whether the firm has a current user and asset denominator. It exposes whether exceptions are tracked or merely tolerated. It helps leadership see whether IT risk is being governed or just reacted to.

This is the idea behind Cyber Defensibility.

Cyber Defensibility is not a certification. It is not a guarantee that a breach, outage, or data loss can never happen. It is not a one-time checklist that lets leadership declare victory.

It is a structured way to validate key controls, collect evidence, identify gaps, track exceptions, and review decisions on a defined cadence. The purpose is to help firm leadership know where it stands before a client, insurer, auditor, deadline-season failure, or security incident forces the issue.

Cyber Defensibility process showing how IT Assure validates IT controls, evaluates evidence, identifies top IT risks and exceptions, and turns findings into leadership decisions.

Cyber Defensibility turns IT control evidence into leadership-ready risk decisions.

 

A simple self-diagnostic

Ask your leadership and IT team these questions:

  • If a top client asked tomorrow, could we show evidence that access to their data is controlled?
  • Could we prove which users and devices are covered by endpoint protection?
  • Could we show recent backup monitoring results and explain recovery expectations?
  • Could we identify known exceptions and who accepted them?
  • Could we show when leadership last reviewed IT risk, not just IT tickets?

If those answers are clear, current, and documented, your firm is in a stronger position.

If the answers require scrambling across tools, vendors, inboxes, and memory, that is the gap to address.

The natural first step is not to buy another tool. It is to determine whether your firm has a control gap, an evidence gap, or an ownership gap.

Start with the Client Data Protection Quick Self Check.

If the results suggest the issue is bigger than a quick self-review, the next step is a Cyber Defensibility Review (see what happen in a review) — a structured conversation about what controls are in place, what evidence exists, what exceptions are known, and what leadership needs to decide.

The goal is not to create fear. The goal is to replace assumptions with evidence.

Professional service firms run on trust. The firms that manage this well will not merely say client data is protected. They will be able to show how they know.