
In an era where generative AI and deepfake technology have revolutionized the precision of social engineering, the risk profile for professional service firms has shifted dramatically. Financial practitioners are no longer just defending against generic "spam"; they are now targets of highly coordinated attacks designed to exploit the specific trust and authority inherent in the CPA-client relationship. This course breaks down the anatomy of a modern breach—from ransomware extortion to sophisticated supply chain vulnerabilities—and provides a practical roadmap for securing a small-to-mid-sized firm without an enterprise-level IT budget. Moving beyond simple firewall conversations, participants will explore the transition to a "Zero Trust" environment and the implementation of high-security protocols like passkeys and FIDO2 authentication. We will examine the increased regulatory scrutiny from frameworks like GLBA, GDPR, and the FTC Safeguards Rule, emphasizing how these requirements translate into daily firm operations. Attendees will walk away with a concrete incident response plan for the critical first 24 hours of a suspected breach, ensuring they have the tools to mitigate damage, protect client confidentiality, and maintain the integrity of their practice.
CPAs and firm owners managing security for small-to-mid-sized professional practices.
This is a basic level course designed for CPAs and firm owners who manage their own security. You don't need a computer science degree to follow along, as we focus on practical management and daily operations.
Yes, we look at how to meet the evolving requirements of the FTC Safeguards Rule, GLBA, and GDPR. We focus specifically on how these rules change the way you handle client data and authentication.
No advanced preparation or software purchases are required for this session. We focus on strategies and protocols like Zero Trust and passkeys that you can often implement with existing tools.
It does. We analyze how attackers use generative AI and deepfakes to create highly convincing social engineering attacks that target the CPA-client relationship.
We focus on the critical first 24 hours after you suspect a breach. You will learn how to design a plan that mitigates immediate damage and protects your client's most sensitive information.
I wrote this because I've watched the threat landscape shift from clumsy spam to precision strikes that use AI to mimic the partners we trust. Small firms often feel like they're bringing a knife to a gunfight, so I built this to help you secure your practice without needing a massive IT department. My goal is to give you a clear, defensive roadmap that actually works in a busy office.
Reach out for more information or to bring this training to your organization.
Interested in bringing this training to your team, or want more information? Send a note and we’ll get back to you.